Showing posts with label nsa. Show all posts
Showing posts with label nsa. Show all posts

Saturday, February 06, 2016

National Security Agency Plans Major Reorganization

The Washington Post reports National Security Agency plans major reorganization "The National Security Agency, the largest electronic spy agency in the world, is undertaking a major reorganization, merging its offensive and defensive organizations in the hope of making them more adept at facing the digital threats of the 21st century, according to current and former officials."

"In place of the Signals Intelligence and Information Assurance directorates — the organizations that historically have spied on foreign targets and defended classified networks against spying, respectively — the NSA is creating a Directorate of Operations that combines the operational elements of each."

"“When it comes to cyber in particular, the line between collection capabilities and our own vulnerabilities — between the acquisition of signals intelligence and the assurance of our own information — is virtually nonexistent,” said Rep. Adam B. Schiff (Calif.), the ranking Democrat on the House Intelligence Committee. “What is a vulnerability to be patched at home is often a potential collection opportunity abroad and vice versa.”"

Bruce Schneier doesn't think it's a good idea: "I think this will make it even harder to trust the NSA. In my book Data and Goliath, I recommended separating the attack and defense missions of the NSA even further, breaking up the agency. (I also wrote about that idea here.) And missing in their reorg is how US CyberCommmand's offensive and defensive capabilities relate to the NSA's. That seems pretty important, too."

It seems to me that the real problem is that NSA targets use the same systems as we do, and by we I mean our government, industry and civilians. By definition a hole in these systems means we're vulnerable too and fixing that hole removes a spying opportunity. If the offensive unit isn't going to share vulnerabilities then perhaps they should be separate.

Saturday, December 19, 2015

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

Wired reports Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

On Thursday, tech giant Juniper Networks revealed in a startling announcement that it had found ‘unauthorized’ code embedded in an operating system running on some of its firewalls.

The code, which appears to have been in multiple versions of the company’s ScreenOS software going back to at least August 2012, would have allowed attackers to take complete control of Juniper NetScreen firewalls running the affected software. It also would allow attackers, if they had ample resources and skills, to separately decrypt encrypted traffic running through the Virtual Private Network, or VPN, on the firewalls.

“The weakness in the VPN itself that enables passive decryption is only of benefit to a national surveillance agency like the British, the US, the Chinese, or the Israelis,” says Nicholas Weaver, a researcher at the International Computer Science Institute and UC Berkeley. “You need to have wiretaps on the internet for that to be a valuable change to make [in the software].”

But the backdoors are also a concern because one of them—a hardcoded master password left behind in Juniper’s software by the attackers—will now allow anyone else to take command of Juniper firewalls that administrators have not yet patched, once the attackers have figured out the password by examining Juniper’s code.

Thursday, October 15, 2015

How is NSA breaking so much crypto?

How is NSA breaking so much crypto? "Based on the evidence we have, we can’t prove for certain that NSA is doing this. However, our proposed Diffie-Hellman break fits the known technical details about their large-scale decryption capabilities better than any competing explanation."

For the nerds in the audience, here’s what’s wrong: If a client and server are speaking Diffie-Hellman, they first need to agree on a large prime number with a particular form. There seemed to be no reason why everyone couldn’t just use the same prime, and, in fact, many applications tend to use standardized or hard-coded primes. But there was a very important detail that got lost in translation between the mathematicians and the practitioners: an adversary can perform a single enormous computation to ‘crack’ a particular prime, then easily break any individual connection that uses that prime.

Since a handful of primes are so widely reused, the payoff, in terms of connections they could decrypt, would be enormous. Breaking a single, common 1024-bit prime would allow NSA to passively decrypt connections to two-thirds of VPNs and a quarter of all SSH servers globally. Breaking a second 1024-bit prime would allow passive eavesdropping on connections to nearly 20% of the top million HTTPS websites. In other words, a one-time investment in massive computation would make it possible to eavesdrop on trillions of encrypted connections.

Update: Bruce Schneier's comments.

Wednesday, September 30, 2015

Investigation: Secret Service tried to discredit US lawmaker

Investigation: Secret Service tried to discredit US lawmaker

"Scores of U.S. Secret Service employees improperly accessed the decade-old, unsuccessful job application of a congressman who was investigating scandals inside the agency, a new government report said Wednesday. An assistant director suggested leaking embarrassing information to retaliate against Rep. Jason Chaffetz, R-Utah, chairman of the House oversight committee.

The actions by the employees could represent criminal violations under the U.S. Privacy Act, said the report by the Homeland Security Department's inspector general, John Roth. 'It doesn't take a lawyer explaining the nuances of the Privacy Act to know that the conduct that occurred here — by dozens of agents in every part of the agency — was wrong,' the report said."

Monday, September 21, 2015

George W. Bush Made Retroactive N.S.A. ‘Fix’ After Hospital Room Showdown

The New York Times reports George W. Bush Made Retroactive N.S.A. ‘Fix’ After Hospital Room Showdown.

"For example, Mr. Bush’s secret directives to the agency, starting in October 2001, said the N.S.A. could ‘acquire’ phone and email metadata — logs showing who contacted whom, but not what they said — if at least one end was foreign or if a specific message were linked to terrorism. But the agency was apparently gathering purely domestic metadata in bulk, too, the Justice Department found.

Mr. Bush, in response to the discrepancy identified by the Justice Department, declared that the N.S.A. was authorized to systematically collect the metadata of purely domestic communications, too, so long as analysts only looked at records linked to terrorism. He also declared that the agency had been authorized to do that all along."

Thursday, June 11, 2015

Article Dump

Here are a few technical articles that have been in my Instapaper that I've been meaning to blog.

A couple of older pieces from late 2013:

Friday, June 05, 2015

Irate Congressman gives cops easy rule: “just follow the damn Constitution”

Irate Congressman gives cops easy rule: “just follow the damn Constitution”. That would be Rep. Ted Lieu (D-CA), who said to Daniel Conley, the district attorney in Suffolk County, Massachusetts:

It's a fundamental misunderstanding of the problem. Why do you think Apple and Google are doing this? It's because the public is demanding it. People like me: privacy advocates. A public does not want an out-of-control surveillance state. It is the public that is asking for this. Apple and Google didn't do this because they thought they would make less money. This is a private sector response to government overreach.

Then you make another statement that somehow these companies are not credible because they collect private data. Here's the difference: Apple and Google don't have coercive power. District attorneys do, the FBI does, the NSA does, and to me it's very simple to draw a privacy balance when it comes to law enforcement and privacy: just follow the damn Constitution.

And because the NSA didn't do that and other law enforcement agencies didn't do that, you're seeing a vast public reaction to this. Because the NSA, your colleagues, have essentially violated the Fourth Amendment rights of every American citizen for years by seizing all of our phone records, by collecting our Internet traffic, that is now spilling over to other aspects of law enforcement. And if you want to get this fixed, I suggest you write to NSA: the FBI should tell the NSA, stop violating our rights. And then maybe you might have much more of the public on the side of supporting what law enforcement is asking for.

Then let me just conclude by saying I do agree with law enforcement that we live in a dangerous world. And that's why our founders put in the Constitution of the United States—that's why they put in the Fourth Amendment. Because they understand that an Orwellian overreaching federal government is one of the most dangerous things that this world can have. I yield back.

Thursday, May 07, 2015

NSA's Bulk Collection of Phone Records Is Illegal, Appeals Court Says

The Intercept reports NSA's Bulk Collection of Phone Records Is Illegal, Appeals Court Says "A federal appeals court panel ruled on Thursday that the NSA’s bulk collection of metadata of phone calls to and from Americans is not authorized by Section 215 of the USA Patriot Act, throwing out the government’s legal justification for the surveillance program exposed by NSA whistleblower Edward Snowden nearly two years ago."

The government has pointed to no affirmative evidence, whether “clear and convincing” or “fairly discernible,” that suggests that Congress intended to preclude judicial review. Indeed, the government’s argument from secrecy suggests that Congress did not contemplate a situation in which targets of § 215 orders would become aware of those orders on anything resembling the scale that they now have. That revelation, of course, came to pass only because of an unprecedented leak of classified information.

This is a big deal. Good job by the ACLU in bringing the case. Now the government can't hide behind secrecy claims or ridiculous arguments like it's just metadata or it's not a human just a machine looking. A Patriot Act reauthorization is coming up June 1st, hopefully some Congresspeople start talking loudly about this and we now have presidential candidates who should be asked about it. And the media should be getting Obama's opinion on this and ask when he's going to cancel this and similar programs or get authorization from Congress for some replacement. IMHO Obama's biggest failing (ok, one of them) has been in allowing the US to become a secret surveillance state.

Here's the 97 page pdf opinion.

Wednesday, May 06, 2015

How the NSA Converts Spoken Words Into Searchable Text

Tuesday The Intercept explained How the NSA Converts Spoken Words Into Searchable Text "Top-secret documents from the archive of former NSA contractor Edward Snowden show the National Security Agency can now automatically recognize the content within phone calls by creating rough transcripts and phonetic representations that can be easily searched and stored. The documents show NSA analysts celebrating the development of what they called “Google for Voice” nearly a decade ago."

So it's probably ok (at least to us) that they do this for foreign phone calls. It's debatable if it's between a US citizen and a foreigner but we know under current guidelines the NSA would say that's fair game. The problem is, they're doing this not just for traditional phone calls but also for voice over the Internet, for example, Skype and probably most other popular VOIP systems. So once you accept that they do that (which makes sense because traditional phone use is declining) I'm sure they start to argue that it's difficult to intercept voice communication knowing that it's not purely domestic, so they collect it all and only scan what they need. Or maybe they have a computer scan everything and only report calls that have at least one foreign endpoint, unless they're really suspicious or something. So now you have to assume they're collecting every "voice call on the Internet". Are you ok with that? Are you okay with that program being authorized in secret, with no serious oversight?

Monday, April 06, 2015

John Oliver: Convincing People to Care About the Snowden Revelations

John Oliver last night did an extra long show. It turns out it was because he went to Russia and interviewed Edward Snowden. He starts talking about the Patriot Act and then talks about the Snowden releases. He interviews people in the street and they either don't know who Snowden is or mistake him for something to do with Wikileaks. He ends his interview with a very NSFW (language only) way to deliver the message so that people care. The whole thing is a half hour and very funny and worthwhile.

Thursday, July 31, 2014

The NSA's Patents, in One Searchable Database

The NSA's Patents, in One Searchable Database "Foreign Policy obtained the NSA's list of patents from the U.S. Patent and Trademark Office. You can download the entire list here or browse the patents by the dates they were filed. We've linked each one to the underlying documents, which include plain-language descriptions, the name of the particular inventor, and in some cases diagrams of the device."

Matt Novak describes 7 NSA Patents: Cyber Manholes, Super-Shredders and More.

Sunday, July 06, 2014

In NSA-intercepted data, those not targeted far outnumber the foreigners who are

The Washington Post reports In NSA-intercepted data, those not targeted far outnumber the foreigners who are

"Ordinary Internet users, American and non-American alike, far outnumber legally targeted foreigners in the communications intercepted by the National Security Agency from U.S. digital networks, according to a four-month investigation by The Washington Post.

Nine of 10 account holders found in a large cache of intercepted conversations, which former NSA contractor Edward Snowden provided in full to The Post, were not the intended surveillance targets but were caught in a net the agency had cast for somebody else.

Many of them were Americans. Nearly half of the surveillance files, a strikingly high proportion, contained names, e-mail addresses or other details that the NSA marked as belonging to U.S. citizens or residents. NSA analysts masked, or ‘minimized,’ more than 65,000 such references to protect Americans’ privacy, but The Post found nearly 900 additional e-mail addresses, unmasked in the files, that could be strongly linked to U.S. citizens or U.S.residents."

Monday, June 30, 2014

Court gave NSA broad leeway in surveillance, documents show

I don't find today's Washington Post story, Court gave NSA broad leeway in surveillance, documents show, at all surprising. As a spy organization I'd expect the NSA to spy on other countries, potentially all of them. As far as intercepting things (even from US citizens) that refer to some address or thing of interest in another country, there have long been "joke" email tools (like Emacs' spook) that add random words at the of messages to flood the NSA. I've found the other revelations much more interesting.

Friday, June 20, 2014

The House just overwhelmingly voted to rein in the NSA

Vox wrote The House just overwhelmingly voted to rein in the NSA

"One example is what's known as a backdoor search. In this technique, the NSA engages in wide surveillance of communications that involve both Americans and foreigners. So long as the foreigners are the official 'target,' this is permitted under the FAA. The NSA sometimes stores the information it has collected in a giant database. And the agency has taken the position that it can search this database for information about Americans without running afoul of the no-targeting-Americans rule."

Congress is considering a bill to fund the military for the 2015 fiscal year, and that includes funding for the National Security Agency. The amendment offered by Sensenbrenner and his colleagues and Lofgren prohibits the NSA from using any funds provided in the bill to 'query a collection of foreign intelligence information' acquired under the FAA 'using a United States person identifier...The legislation also effectively bars the NSA or the Central Intelligence Agency from forcing device manufacturers to install technical "backdoors" in their products."

"By itself, the amendment falls short of the kind of sweeping NSA reforms some civil liberties groups support. But the vote represents the first time a house of Congress has voted to curtail the controversial practices revealed by Ed Snowden last year. It will give NSA critics renewed political momentum and may force President Obama to make further concessions to critics of the NSA."

Spencer Ackerman has a little more in The Guardian House of Representatives moves to ban NSA's 'backdoor search' provision.

Bruce Schneier points out, More Details on NSA Tapping the Internet Backbone. "It's a measure of the popular interest in this issue that the German/Danish story isn't being reported by the US press, and I had to search to find the Congressional vote on the New York Times and Washington Post sites. Only the Guardian had it as a home page headline. No one is reporting today's renewal of the telephone metadata program."

Thursday, June 19, 2014

How Secret Partners Expand NSA’s Surveillance Dragnet

The Intercept reports How Secret Partners Expand NSA’s Surveillance Dragnet .

"Huge volumes of private emails, phone calls, and internet chats are being intercepted by the National Security Agency with the secret cooperation of more foreign governments than previously known, according to newly disclosed documents from whistleblower Edward Snowden.

The classified files, revealed today by the Danish newspaper Dagbladet Information in a reporting collaboration with The Intercept, shed light on how the NSA’s surveillance of global communications has expanded under a clandestine program, known as RAMPART-A, that depends on the participation of a growing network of intelligence agencies."

Thursday, May 29, 2014

Brian Williams Interviews Edward Snowden

Brian Williams interviewed Edward Snowden. Here's their official page with the interview in six parts and with lots of text and short clips interspersed. Inside the Mind of Edward Snowden.

Here's what I think is a single youtube video of the whole thing collected.

Thursday, May 22, 2014

Secrets, Lies and Snowden's Email: Why I Was Forced to Shut Down Lavabit

Ladar Levison explains Why I Was Forced to Shut Down Lavabit. Lavabit was an encrypted email company and Edward Snowden was one of their customers.

"In the first two weeks, I was served legal papers a total of seven times and was in contact with the FBI every other day. (This was the period a prosecutor would later characterize as my 'period of silence'.) It took a week for me to identify an attorney who could adequately represent me, given the complex technological and legal issues involved – and we were in contact for less than a day when agents served me with a summons ordering me to appear in a Virginia courtroom, over 1,000 miles from my home. Two days later, I was served the first subpoena for the encryption keys.

With such short notice, my first attorney was unable to appear alongside me in court. Because the whole case was under seal, I couldn't even admit to anyone who wasn't an attorney that I needed a lawyer, let alone why. In the days before my appearance, I would spend hours repeating the facts of the case to a dozen attorneys, as I sought someone else that was qualified to represent me. I also discovered that as a third party in a federal criminal indictment, I had no right to counsel. After all, only my property was in jeopardy – not my liberty. Finally, I was forced to choose between appearing alone or facing a bench warrant for my arrest. "

He concludes, "If my experience serves any purpose, it is to illustrate what most already know: courts must not be allowed to consider matters of great importance under the shroud of secrecy, lest we find ourselves summarily deprived of meaningful due process. If we allow our government to continue operating in secret, it is only a matter of time before you or a loved one find yourself in a position like I did – standing in a secret courtroom, alone, and without any of the meaningful protections that were always supposed to be the people's defense against an abuse of the state's power."

Monday, May 19, 2014

The NSA Is Recording Every Cell Phone Call in the Bahamas

The Intercept reports Data Pirates of the Caribbean: The NSA Is Recording Every Cell Phone Call in the Bahamas

"The National Security Agency is secretly intercepting, recording, and archiving the audio of virtually every cell phone conversation on the island nation of the Bahamas.

According to documents provided by NSA whistleblower Edward Snowden, the surveillance is part of a top-secret system – code-named SOMALGET – that was implemented without the knowledge or consent of the Bahamian government. Instead, the agency appears to have used access legally obtained in cooperation with the U.S. Drug Enforcement Administration to open a backdoor to the country’s cellular telephone network, enabling it to covertly record and store the ‘full-take audio’ of every mobile call made to, from and within the Bahamas – and to replay those calls for up to a month.

SOMALGET is part of a broader NSA program called MYSTIC, which The Intercept has learned is being used to secretly monitor the telecommunications systems of the Bahamas and several other countries, including Mexico, the Philippines, and Kenya. But while MYSTIC scrapes mobile networks for so-called ‘metadata’ – information that reveals the time, source, and destination of calls – SOMALGET is a cutting-edge tool that enables the NSA to vacuum up and store the actual content of every conversation in an entire country."

"So: Beyond a desire to bust island pot dealers, why would the NSA choose to apply a powerful collection tool such as SOMALGET against the Bahamas, which poses virtually no threat to the United States? The answer may lie in a document that characterizes the Bahamas operation as a “test bed for system deployments, capabilities, and improvements” to SOMALGET. The country’s small population – fewer than 400,000 residents – provides a manageable sample to try out the surveillance system’s features. Since SOMALGET is also operational in one other country, the Bahamas may be used as a sort of guinea pig to beta-test improvements and alterations without impacting the system’s operations elsewhere."

Monday, March 31, 2014

NSA infiltrated RSA security more deeply than thought

Reuters reports Exclusive: NSA infiltrated RSA security more deeply than thought "Security industry pioneer RSA adopted not just one but two encryption tools developed by the U.S. National Security Agency, greatly increasing the spy agency's ability to eavesdrop on some Internet communications, according to a team of academic researchers."

Saturday, March 22, 2014

Revelations of N.S.A. Spying Cost U.S. Tech Companies

The New York TImes writes Revelations of N.S.A. Spying Cost U.S. Tech Companies

The business effect of the disclosures about the N.S.A. is felt most in the daily conversations between tech companies with products to pitch and their wary customers. The topic of surveillance, which rarely came up before, is now ‘the new normal’ in these conversations, as one tech company executive described it.

“We’re hearing from customers, especially global enterprise customers, that they care more than ever about where their content is stored and how it is used and secured,” said John E. Frank, deputy general counsel at Microsoft, which has been publicizing that it allows customers to store their data in Microsoft data centers in certain countries.

A few points:

People blaming Snowden for this are blaming the messenger. The problem is the extent of the NSA's operations.

I think companies looking for tech companies out of the US are doing exactly the wrong thing. The NSA is prohibited from spying on the US and most of the things we've learned about them spying on US companies like Google and Yahoo is that they use these companies' foreign connections to spy on the data. They're looking at Google data because Google is huge and their targets probably use them but they're not getting the data from the US, they're getting it when Google sends data between data centers in different countries. There's nothing stopping the NSA from doing anything to a company that has no US footprint.

Finally if you really care about the location of your data, then cloud services are probably not for you regardless of where they are.