Showing posts with label nsa. Show all posts
Showing posts with label nsa. Show all posts

Friday, October 21, 2016

The Coming Cyber War #19

Cyber Warfare:

The United States had a cyber attack today with a massive DDOS attack on a key company on the internet causing outages mainly on the East Coast.

Is cyber defense the great space race of our generation?

Destructive cyber attacks are coming.

The IoT Botnet Mirai's software has been released to the public.  DHS is warning about this malware specifically.

Hackers are attacking the US voting systems.

NATO states cyberattacks complicate defense.

Nyotron is bringing a cloud based cyber defense to militaries. 

The US has officially stated Russia is responsible for the hacks on the election system Stateside.  The Russians have responded that's part of the 'anti-Russian hysteria.' sweeping the US.  The hacks, some think, are meant to shake trust in American democracy.  The rhetoric against Russia has been stepped up.  The US government has stated it will doing a proportionate response against Russia.  But how?  Supposedly the CIA (really?  CIA?) is preparing to conduct a cyber attack against Russia.

A warning has been sent out Russian hackers might be attempting to attack the US Presidential election.

The US military needs to get cool to attract cyber experts?  Use a cyber ROTC?  Perhaps.  Or perhaps it needs to pay industry rates...

The British have stated they are actively conducting cyberwarfare operations against Daesh.

Russia, cyber coercion and the classic whodunit.

Cyber Security:

3d printing systems have cyber security issues.

Buzzfeed hacked and had false stories released.

Is cyber security best incentivized by a carrot or a stick?

One election system vendor uses developers in Serbia. 

IAEA has stated at least one nuclear power plant was successfully hacked and had its operations disrupted.

IoT might be really, really bad for the internet.

Johnson & Johnson's insulin pumps are hackable.

MITRE is offering a bounty on rogue IOT devices.

Most businesses do not inspect their cloud services for malware.  And the clouds have lots of it.

Sixgill is moving from defense to detection in software.

Spotify users were hacked through malware carrying ads.

Cyber Espionage: 

Apple watches have been banned from British Cabinet meetings due to hacking fears.

Assange promises more secrets to be revealed about Clinton and Google.  Some more were revealed for the Clinton campaign.  Supposedly, a nation state cut off Assange's internet access.  That nation?  Ecuador!  The host embassy he has asylum with.  Ecuador has stated they did so because Assange was interfering with the US election and not because they were being pressured. 

Gufficer dumped Clinton Foundation data again.

An NSA officer was caught stealing secrets.  He stole apparently tens of terabytes of data.

Trump's email servers are hopelessly hackable.

Yahoo had a regular program of scans of user emails for the NSA and denied it.  (Apple, Google, and Microsoft denied they have a similar programs.)  Yahoo's scans were under a surveillance law that is expiring.  Calls are being made to declassify the program the Yahoo email scans were being done under.  The tool being used apparently was a hacking tool, rather than an email filter.  Verizon wants a $1 billion reduction in the price for purchasing Yahoo due to the lack of disclosure on the email scans.  In fact, Verizon is now saying this is a material breach.  In an odd twist, Yahoo is demanding to know who in the government ordered the monitoring.

A Russian spy ship might have tapped internet cables coming out of Syria.

Cyber Crime:

4Chan hackers are claiming to have wiped a Clinton aide's phone remotely.

A new android malware tries to trick users into taking a picture of themselves holding an ID card.

The Clinton Foundation is warning their donors against phishing.

Apparently, darknet users are strongly against animal trafficking.  

DDOS attacks actually have a changing effect.

Hackers who attacked French TV have still not been found.

Hackers have also hit 6,000 online stores looking for credit card #s over an 18 month period.

Another group of hackers is attacking the SWIFT network.

A huge debit car system breach has affected millions in India and over ten banks.

How hackers got into Podesta and Powell's email accounts.

Malware is not a problem on the Wikileaks site according to Julian Assange.

A Republican Senate Committee website has been hacked.

A Russian hacker has been detained in the Czech Republic for possible extradition to the US.  Russia has strongly criticized the US over the arrest and has named the individual.

The StrongPity malware is infecting users via legitimate software installers.

Friday, November 27, 2015

NSA to Stop Bulk Surveillance by Sunday

The U.S. National Security Agency will end its daily vacuuming of millions of Americans' phone records by Sunday and replace the practice with more tightly targeted surveillance methods, the Obama administration said on Friday.

As required by law, the NSA will end its wide-ranging surveillance program by 11:59 p.m. EST Saturday (4:59 a.m. GMT Sunday) and expects to have the new, scaled-back system in place by then, the White House said.

The transition is a long-awaited victory for privacy advocates and tech companies wary of broad government surveillance at a time when national security concerns are heightened in the wake of the Paris attacks earlier this month.

Monday, March 23, 2015

Canadians as Naughty as Americans: the Cyber Activities of Canada's CSEC


Top-secret documents obtained by the CBC show Canada's electronic spy agency has developed a vast arsenal of cyberwarfare tools alongside its U.S. and British counterparts to hack into computers and phones in many parts of the world, including in friendly trade countries like Mexico and hotspots like the Middle East.

The little known Communications Security Establishment wanted to become more aggressive by 2015, the documents also said.

Revelations about the agency's prowess should serve as a "major wakeup call for all Canadians," particularly in the context of the current parliamentary debate over whether to give intelligence officials the power to disrupt national security threats, says Ronald Deibert, director of the Citizen Lab, the respected internet research group at University of Toronto's Munk School of Global Affairs.

"These are awesome powers that should only be granted to the government with enormous trepidation and only with a correspondingly massive investment in equally powerful systems of oversight, review and public accountability," says Deibert.

Details of the CSE’s capabilities are revealed in several top-secret documents analyzed by CBC News in collaboration with The Intercept, a U.S. news website co-founded by Glenn Greenwald, the journalist who obtained the documents from U.S. whistleblower Edward Snowden.


Documents obtained from Edward Snowden reveal the extent of the cyberwarfare techniques used by Canada’s Communications Security Establishment Canada (CSEC) – including the capacity and will to perform ‘false flag’ operations, where responsibility for cyberattacks, counterattacks or other intelligence-related activity is misattributed to individuals, groups or nation states.

The Intercept, in collaboration with the Canadian Broadcasting Corporation (CBC), has published limited details of CSEC’s cyberwarfare capabilities and disposition just as Canada’s C-51 bill – draft anti-terrorism legislation currently under criticism for its potential to silence legitimate protest – is under fierce debate in Canada’s House of Commons.

The ‘deception tactics’ outlined by the documents include ‘false flag’ techniques, carried out in order to ‘create unrest’. In a spectacular display of bureaucratic legerdemain, this process is apparently defined as ‘[altering] adversary perception’.

The new leak also reveals that CSEC uses ‘honeypot’ or ‘watering hole’ techniques in service of generating deceptive cyberactivity; though no greater detail is given on that point, the principle is one of presenting a tempting online target and attempting to gain advantage from the actors attracted to it.

Additionally the leaked information discloses CSEC’s cooperation with the NSA in service of an ‘active computer network access and exploitation on a variety of foreign intelligence targets, including CT [counter terrorism], Middle East, North Africa, Europe, and Mexico’.

Wednesday, February 18, 2015

The Equation Group is America's Cyberwarfare Manhattan Project


“What we really need is a Manhattan Project for cybersecurity.” It’s a sentiment that swells up every few years in the wake of some huge computer intrusion—most recently the Sony and Anthem hacks. The invocation of the legendary program that spawned the atomic bomb is telling. The Manhattan Project is America’s go-to shorthand for our deep conviction that if we gather the smartest scientists together and give them billions of dollars and a sense of urgency, we can achieve what otherwise would be impossible.

A Google search on “cyber Manhattan Project” brings up results from as far back as 1997—it’s second only to “electronic Pearl Harbor” in computer-themed World War II allusions. In a much-circulated post on Medium last month, futurist Marc Goodman sets out what such a project would accomplish. “This Manhattan Project would help generate the associated tools we need to protect ourselves, including more robust, secure, and privacy-enhanced operating systems,” Goodman writes. “Through its research, it would also design and produce software and hardware that were self-healing and vastly more resistant to attack and resilient to failure than anything available today.”

These arguments have so far not swayed a sitting American president. Sure, President Obama mentioned cybersecurity at the State of the Union, but his proposal not only doesn’t boost security research and development, it potentially criminalizes it. At the White House’s cybersecurity summit last week, Obama told Silicon Valley bigwigs that he understood the hacking problem well—“We all know what we need to do. We have to build stronger defenses and disrupt more attacks”—but his prescription this time was a tepid executive order aimed at improving information sharing between the government and industry. Those hoping for something more Rooseveltian must have been disappointed.

On Monday, we finally learned the truth of it. America already has a computer security Manhattan Project. We’ve had it since at least 2001. Like the original, it has been highly classified, spawned huge technological advances in secret, and drawn some of the best minds in the country. We didn’t recognize it before because the project is not aimed at defense, as advocates hoped. Instead, like the original, America’s cyber Manhattan Project is purely offensive.


All your internet are belong to us.  

Monday, February 16, 2015

The Equation Group: Your Hard Drive is Watching you

The U.S. National Security Agency has figured out how to hide spying software deep within hard drives made by Western Digital, Seagate, Toshiba and other top manufacturers, giving the agency the means to eavesdrop on the majority of the world's computers, according to cyber researchers and former operatives.

That long-sought and closely guarded ability was part of a cluster of spying programs discovered by Kaspersky Lab, the Moscow-based security software maker that has exposed a series of Western cyberespionage operations.

Kaspersky said it found personal computers in 30 countries infected with one or more of the spying programs, with the most infections seen in Iran, followed by Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria. The targets included government and military institutions, telecommunication companies, banks, energy companies, nuclear researchers, media, and Islamic activists, Kaspersky said.

The firm declined to publicly name the country behind the spying campaign, but said it was closely linked to Stuxnet, the NSA-led cyberweapon that was used to attack Iran's uranium enrichment facility. The NSA is the agency responsible for gathering electronic intelligence on behalf of the United States.

A former NSA employee told Reuters that Kaspersky's analysis was correct, and that people still in the intelligence agency valued these spying programs as highly as Stuxnet. Another former intelligence operative confirmed that the NSA had developed the prized technique of concealing spyware in hard drives, but said he did not know which spy efforts relied on it.

NSA spokeswoman Vanee Vines declined to comment.

link.

There's a lot more to this than just the hard drives.

Thursday, January 01, 2015

The NSA Eats VPNs for Breakfast

The National Security Agency’s Office of Target Pursuit (OTP) maintains a team of engineers dedicated to cracking the encrypted traffic of virtual private networks (VPNs) and has developed tools that could potentially uncloak the traffic in the majority of VPNs used to secure traffic passing over the Internet today, according to documents published this week by the German news magazine Der Speigel. A slide deck from a presentation by a member of OTP’s VPN Exploitation Team, dated September 13, 2010, details the process the NSA used at that time to attack VPNs—including tools with names drawn from Star Trek and other bits of popular culture.

OTP’s VPN exploit team had members assigned to branches focused on specific regional teams, as well as a “Cross-Target Support Branch” and a custom development team for building specialized VPN exploits. At the regional level, the VPN team representatives acted as liaisons to analysts, providing information on new VPN attacks and gathering requirements for specific targets to be used in developing new ones.

While some VPN technologies—specifically, those based on the Point-to-Point Protocol (PPTP)—have previously been identified as being vulnerable because of the way they exchange keys at the beginning of a VPN session, others have generally been assumed to be safer from scrutiny. But in 2010, the NSA had already developed tools to attack the most commonly used VPN encryption schemes: Secure Shell (SSH), Internet Protocol Security (IPSec), and Secure Socket Layer (SSL) encryption.

Wednesday, August 13, 2014

The NSA has Weaponized Bro and Called it MonsterMind

Edward Snowden has made us painfully aware of the government’s sweeping surveillance programs over the last year. But a new program, currently being developed at the NSA, suggests that surveillance may fuel the government’s cyber defense capabilities, too.

The NSA whistleblower says the agency is developing a cyber defense system that would instantly and autonomously neutralize foreign cyberattacks against the US, and could be used to launch retaliatory strikes as well. The program, called MonsterMind, raises fresh concerns about privacy and the government’s policies around offensive digital attacks.

Although details of the program are scant, Snowden tells WIRED in an extensive interview with James Bamford that algorithms would scour massive repositories of metadata and analyze it to differentiate normal network traffic from anomalous or malicious traffic. Armed with this knowledge, the NSA could instantly and autonomously identify, and block, a foreign threat.


This sounds like they weaponized bro and gave it teeth.

Friday, May 23, 2014

The Robopocalypse is Coming for the Intelligence Community...Soon

The intelligence community is on the verge of “revolutionary” technical advances. Spy satellites and other systems will be able to watch a place or a person for long periods of time and warn intelligence analysts and operatives when target changes its behavior. Satellites and their sensors could be redirected automatically to ensure nothing is missed.

Monday, March 31, 2014

The Real Cost of Snowden has yet to be Paid

Regardless of how you feel about Edward Snowden’s domestic surveillance program revelations, it’s time to get real about the cost we are paying for Snowden’s leaks about America’s signals intelligence programs. In a conversation a few months ago with a very senior former US intelligence official, I was struck by their apocalyptic assessment of the damage Snowden’s leaks had caused America’s intelligence capabilities. While he naturally considered the domestic concerns overblown, he was even more upset at Snowden undoing of decades of groundbreaking American work securing our own communications and spying on foreign governments.

Success in signals intelligence relies almost entirely on the opponent not knowing where and how he is being spied upon. As soon as your methods are discovered, your opponent can evade your espionage or, even worse, spoof you with false intelligence. Be detailing the methods that the US uses to spy on other countries, Snowden’s revelations immediately and directly limited the NSA’s capabilities. We are just now beginning to see the fruit of that.

Thursday, March 13, 2014

NSA's Cyber Warfare Tactics Being Outed by Snowden

Top-secret documents reveal that the National Security Agency is dramatically expanding its ability to covertly hack into computers on a mass scale by using automated systems that reduce the level of human oversight in the process.

The classified files – provided previously by NSA whistleblower Edward Snowden – contain new details about groundbreaking surveillance technology the agency has developed to infect potentially millions of computers worldwide with malware “implants.” The clandestine initiative enables the NSA to break into targeted computers and to siphon out data from foreign Internet and phone networks.

The covert infrastructure that supports the hacking efforts operates from the agency’s headquarters in Fort Meade, Maryland, and from eavesdropping bases in the United Kingdom and Japan. GCHQ, the British intelligence agency, appears to have played an integral role in helping to develop the implants tactic.

Friday, February 28, 2014

If Government or Other American Networks are Destroyed, This is an Act of War

On the day that China’s president took personal charge of his country’s new cyber body, pledging to make the People’s Republic of China a “cyber power,” the outgoing head of America’s Cyber Command laid out a clear red line that, if crossed, could lead to war.

“If it destroys government or other networks, I think it would cross that line,” Army Gen. Keith Alexander, head of both Cyber Command and the National Security Agency, told the Senate Armed Services Committee today when asked what level of cyber “attack” would potentially cause America to go to war.

Tuesday, February 18, 2014

Snowden Starts Looking More Like a Spy

Three people at the National Security Agency have been implicated in Edward Snowden's efforts to copy classified material, including a civilian employee who resigned last month after acknowledging he allowed Snowden to use his computer ID, according to an NSA memo sent to Congress.

The other two were an active-duty member of the military and a civilian contractor. The memo does not describe their conduct, but says they were barred from the NSA and its systems in August.

The memo from the director of the NSA's legislative affairs office, Ethan L. Bauman, to the House Judiciary Committee staff does not identify the three or say whether they all worked with Snowden at an NSA post in Hawaii last year. But it offers a glimpse into the internal investigation of what intelligence officials have called the largest theft of classified material in U.S. history.

The NSA employee who resigned did not know that Snowden, an agency contractor employed by the consulting firm Booz Allen Hamilton, planned to reveal classified NSA operations and systems to the media. But the employee admitted to the FBI in June that he had used his Public Key Infrastructure certificate, a special digital ID, to give Snowden access to material he was not authorized to see on an internal network called NSA Net.

The employee used his password to sign onto the network and Snowden secretly captured the password without the employee's knowledge, Bauman wrote, and later used it to download additional material.

The employee had his security clearance revoked in November and resigned on Jan. 10, according to the memo. Bauman's memo was first reported Thursday by NBC News.

An NSA spokeswoman declined to comment Friday.

Snowden, who is living in Moscow, has denied that he stole colleagues' passwords to gain access to classified documents. U.S. officials have confirmed reports that he used so-called Web crawler software to automatically troll the spy agency's networks and secretly access up to 1.7 million documents without being detected. It's still unclear how many he copied. News organizations have published a few dozen at most so far.

U.S. officials say Snowden mostly took documents that explained how NSA surveillance programs work, rather than fruits of eavesdropping and code-breaking operations. The officials say he was walled off from many NSA secrets, including recordings of private calls or conversations by world leaders.

But he appears to have accessed documents that could compromise military communications systems, satellite orbits and even the names of clandestine agents, officials say. Mitigating the damage, they say, will take years and cost billions of dollars.

link.

Friday, January 31, 2014

Someone Else Also not Surprised the NSA is Pursuing Quantum Computers in Project "Penetrating Hard Targets"

In this month's issue of Physics World, Jon Cartwright explains how the revelation that the US National Security Agency (NSA) is developing quantum computers has renewed interest and sparked debate on just how far ahead they are of the world's major labs looking to develop the same technology.

In 2006 the NSA openly announced a partnership with two US institutions to develop quantum computers. However, according to documents leaked by whistle-blower Edward Snowden, and published last month by the Washington Post, the NSA also wishes to develop the technology so that it is capable of breaking modern Internet security.

The $79.7m project, dubbed "Penetrating Hard Targets", could be made possible by the extraordinary potential of quantum computers to factorize large numbers in a short space of time, quickly deciphering encryption keys that are used to protect sensitive information.

For the NSA, this could mean deciphering banking transactions, private messages and government files; however, many physicists are not surprised and believe this is exactly the type of technology that the NSA is expected to develop.

Speaking to Physics World, Raymond Laflamme, a leading quantum information theorist at the University of Waterloo in Canada, said "If you put my level of surprise on a scale from zero to 10, where 10 is very, very surprised, my answer would be zero."

Tuesday, January 21, 2014

Was the Army Intelligence Officer Really Threatening Snowden's Life or Blowing off Frustrated Steam?

Edward Snowden needs better security after a news report quoted unnamed U.S. intelligence officials saying they wanted the former spy agency contractor dead and discussing ways to kill him, his Russian lawyer said on Tuesday.

Snowden was granted asylum in Russia last summer after fleeing the United States, where he is wanted on espionage charges for leaking information about government surveillance practices.

The American's revelations caused an uproar in the United States over privacy rights and angered many U.S. allies. Russia's decision to shelter him damaged already strained ties between Moscow and Washington.

"We are concerned about potential hidden threats that we have heard often recently. In these statements ... they openly call for physical reprisal against Edward Snowden," lawyer Anatoly Kucherena said on state-run Rossiya-24 television.

Without naming any media outlet, he referred to comments reported by the website BuzzFeed, which quoted a Pentagon official as saying he would love to shoot Snowden in the head.

BuzzFeed quoted a U.S. Army intelligence officer as saying the former National Security Agency contractor could be killed Cold War-style, poked with a poisoned needle while returning home from the grocery store.

Monday, January 20, 2014

Was Snowden Really a Whistleblower? Or a Spy?

U.S. House Intelligence Committee Chairman Mike Rogers (R-Mich.) believes National Security Agency leaker Edward Snowden may have had help from Russia.

[...]

“There's some clear evidence there that something else was going on," Rogers continued. "This wasn't a random smash and grab, run down the road, end up in China, the bastion of Internet freedom, and then Russia, of course, the bastion of Internet freedom. And because of the nature of the information that was stolen [had] nothing to do with Americans' privacy [and] a lot to do with our operations overseas."

Rogers implied Snowden was not skilled enough to pull off the leak alone. "Some of the things he did were beyond his technical capabilities," Rogers said. "[That] raises more questions. How he arranged travel before he left. How he was ready to go -- he had a go bag, if you will."

Sen. Diane Feinstein (D-Calif.), Chairman of the Select Committee on Intelligence, was also asked on "Meet The Press" if she felt Snowden had help from the Russians.

"He may well have," she said. "We don't know at this stage."

On CBS, Mike Morell, a former deputy CIA director, agreed with Rogers' assessment.

“I don't have any particular evidence," Morell said, "but one of the things that I point to when I talk about this is that the disclosures that have been coming recently are very sophisticated in their content and sophisticated in their timing, almost too sophisticated for Mr. Snowden to be deciding on his own. And seems to me, he might be getting some help."


So that's what its like to be ahead of the curve. ;)

Tuesday, January 07, 2014

OMG! Snowden Reveals ALL on NSA Developing Quantum Computers!!!

In room-size metal boxes ­secure against electromagnetic leaks, the National Security Agency is racing to build a computer that could break nearly every kind of encryption used to protect banking, medical, business and government records around the world.

According to documents provided by former NSA contractor Edward Snowden, the effort to build “a cryptologically useful quantum computer” — a machine exponentially faster than classical computers — is part of a $79.7 million research program titled “Penetrating Hard Targets.” Much of the work is hosted under classified contracts at a laboratory in College Park, Md.

[...]

“It seems improbable that the NSA could be that far ahead of the open world without anybody knowing it,” said Scott Aaronson, an associate professor of electrical engineering and computer science at the Massachusetts Institute of Technology.




Actually, this is about as UNSURPRISING as anything Snowden has revealed.  The NSA, if they are doing their jobs the way they ought, really should be pursuing a quantum computer.  Likewise, they ought to be pursuing quantum cryptography (other side of their job is PROTECTION of American communications).  We know LANL produced a star config quantum encrypted network.  So, why in the world are we shocked the NSA is pursuing a quantum computer???  gah.

Likewise, given the prior knowledge of the Carnivore and ECHELON programs, why are we shocked the NSA has developed more capable skills?!  Naive or more likely false outrage is stupid.  Yes, false outrage.  Everyone spies on everyone and this is the world which spawned STUXNET, the "cyber superpower" which created it ought to be able to get into almost anything.  Thinking otherwise is disingenuous at best.

(PS no clemency.  The turkey, if he were a whistleblower, ought to have just revealed (with evidence) the actions of the NSA against US citizens.  He has revealed more than Manning did and Manning got 35 years)


Monday, December 16, 2013

Three Cheers for Judge Leon


America’s founding fathers would be “aghast” at the NSA’s bulk telephone metadata spying, a federal judge today said, finding that the program violates the Fourth Amendment and the legal argument justifying it is “the stuff of science fiction.”

U.S. District Judge Richard Leon, in Washington D.C., called the NSA program “almost-Orwellian,” and ordered the NSA to stop collecting or analyzing the metadata of the two men who sued. But citing national security, Leon stayed his order pending resolution in the appellate courts.

It was the first time a district court judge has ever sided against the NSA program, and several other lawsuits across the nation are pending.

Tuesday, December 10, 2013

Communications Security Establishment Canada (CSEC) is a Full Partner of the American NSA

A top secret document retrieved by American whistleblower Edward Snowden reveals Canada has set up covert spying posts around the world and conducted espionage against trading partners at the request of the U.S. National Security Agency.

The leaked NSA document being reported exclusively by CBC News reveals Canada is involved with the huge American intelligence agency in clandestine surveillance activities in “approximately 20 high-priority countries."

Much of the document contains hyper-sensitive operational details which CBC News has chosen not to make public.