Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Tuesday, June 06, 2017

BOMBSHELL: Leaked NSA Report Confirms Russian Hack Reached Into Voting Systems

By Karoli Kuns/Crooks and Liars
The Intercept just published a bombshell report based upon a leak of a classified report by the NSA, indicating that Russians had attempted to hack into voter databases using phishing schemes against vendors of software used for electronic polling books.
The Intercept based their reporting on a leaked NSA document created in May, 2017, which was more specific about the methods and targets used by the Russians than anything previously known. There was no doubt in the mind of the analysts that the Russian government was behind the hacks.
The NSA has now learned, however, that Russian government hackers, part of a team with a “cyber espionage mandate specifically directed at U.S. and foreign elections,” focused on parts of the system directly connected to the voter registration process, including a private sector manufacturer of devices that maintain and verify the voter rolls. Some of the company’s devices are advertised as having wireless internet and Bluetooth connectivity, which could have provided an ideal staging point for further malicious actions.
VR Systems, a vendor to several states -- some of which were swing states -- was a specific target.
So on August 24, 2016, the Russian hackers sent spoofed emails purporting to be from Google to employees of an unnamed U.S. election software company, according to the NSA report. Although the document does not directly identify the company in question, it contains references to a product made by VR Systems, a Florida-based vendor of electronic voting services and equipment whose products are used in eight states.
While there's no evidence that any machines were breached, there are still major concerns about the complicated efforts to access the voter database and possibly other systems.
Although the NSA report indicates that VR Systems was targeted only with login-stealing trickery, rather than computer-controlling malware, this isn’t necessarily a reassuring sign. Jake Williams, founder of computer security firm Rendition Infosec and formerly of the NSA’s Tailored Access Operations hacking team, said stolen logins can be even more dangerous than an infected computer. “I’ll take credentials most days over malware,” he said, since an employee’s login information can be used to penetrate “corporate VPNs, email, or cloud services,” allowing access to internal corporate data. The risk is particularly heightened given how common it is to use the same password for multiple services. Phishing, as the name implies, doesn’t require everyone to take the bait in order to be a success — though Williams stressed that hackers “never want just one” set of stolen credentials.

↓ Story continues below ↓
There's much more in the report, which you can read here.
Just after the report was published, the FBI announced they arrested the woman they believe leaked it to The Intercept.
Apparently they found a trail which included email communication from Ms. Winner to The Intercept, which led to an arrest. Via the DOJ release:
Winner is a contractor with Pluribus International Corporation assigned to a U.S. government agency facility in Georgia. She has been employed at the facility since on or about February 13, and has held a Top Secret clearance during that time. On or about May 9, Winner printed and improperly removed classified intelligence reporting, which contained classified national defense information from an intelligence community agency, and unlawfully retained it. Approximately a few days later, Winner unlawfully transmitted by mail the intelligence reporting to an online news outlet.
Once investigative efforts identified Winner as a suspect, the FBI obtained and executed a search warrant at her residence. According to the complaint, Winner agreed to talk with agents during the execution of the warrant. During that conversation, Winner admitted intentionally identifying and printing the classified intelligence reporting at issue despite not having a "need to know," and with knowledge that the intelligence reporting was classified. Winner further admitted removing the classified intelligence reporting from her office space, retaining it, and mailing it from Augusta, Georgia, to the news outlet, which she knew was not authorized to receive or possess the documents.
The arrest confirms the validity of the NSA report. At the same time, it seems strange and bizarre that the leaker of the report is arrested within minutes of the publication of key parts of it in The Intercept, because she emailed them from her work computer.
Still, take this NSA report and combine it with the possibility of collusion between the Trump campaign and Russia. Winner's arrest confirms the report is authentic and true. If the campaign is shown to have been colluding with Russia, there are a lot more folks in need of arrest, trials, and long prison sentences, including the guy who occupies the White House.

Friday, October 04, 2013

Video: Glenn Greenwald Is Grilled on BBC Newsnight, Spews Insults Like a Firehose

By Charles Johnson/Little Green Footballs:
Today on BBC Newsnight, activist Glenn Greenwald faced an uncomfortable grilling from the host and several guests, including former senior GCHQ officials who openly scoffed at Greenwald’s tales, particularly his claims that the Russians couldn’t possibly have gotten access to Edward Snowden’s stolen NSA files, and his claims that intelligence agencies are not harmed by massive leaks and that terrorists are not aided.
Many of the questions he faced are the same ones we’ve been asking here, about the discrepancies and problems in his stories about Snowden and the NSA. And when the heat was finally turned up, Mr. Greenwald responded with an utter lack of grace, insulting and patronizing everyone on the show. It’s an amazing, thoroughly unpleasant performance, and shows why Greenwald normally only grants interviews to sympathetic hosts, because he comes off as … well, basically a terrible person. As if someone combined the worst qualities of a weaselly cheap lawyer with a narcissistic fame-seeking paparazzi, and added too much nasty sauce to the mix.
Take it away, Glenn.
In the following clip, former chair of the British Joint Intelligence Committee Pauline Neville-Jones says there’s no way the Russians don’t have access to Snowden’s files. Greenwald responds:
The ignorance of those comments is truly astounding to me. First of all you would think that a rational person before making an extremely serious accusation like ‘Russia and China has gotten all of his data’ would have at least a little bit of evidence before saying that? There is NONE. What is the basis for it, some tingly sensation in the stomach?
[…]
She said, they got the data on his laptops. That isn’t how data works, it’s not 1998. Data is stored on thumb drives, and on those thumb drives are very sophisticated means of encryption shells, that as I said before and I know this because I’ve read the documents that I have on this, not even the NSA can break.
The encryption codes are 4,000 characters long
I did a double take when I heard him say that, because in his patronizing lecture to Baroness Neville-Jones (who has spent much of her life involved in national security and intelligence at the highest levels), Greenwald actually got this important detail completely wrong, in a very amateurish kind of way. The type of encryption he’s talking about (XAES) uses a key with a length of 4096 bits, not “4,000 characters.”
The difference between “4,000 characters” and 4096 bits is huge. He’s off by several factors of 2. Oops.

Wednesday, July 03, 2013

How the Professional Left's Blind Obama Hatred Got them Played by a Far-Right Nutjob

by Spandan C/The People's View

Some outlets reported last week that NSA leaker and fugitive Edward Snowden was caught into a bit of hypocrisy: public chat records indicate that back in the ancient times of 2009, he wanted leakers "shot in the balls." Yeah, he said that. But that's not all he said. Oh, no. The Technology site Ars Technica posted extensive public chat logs from Snowden, then using the monkier TheTrueHOOHA, that confirms what I had suspected since finding his campaign contributions to Glenn Greenwald's straight crush Ron Paul. 

So let's talk about this man that has been granted hero status by the Left's loudest prognosticators and provocateurs. The transcripts released by Ars Technica are about a lot more than Snowden's previous contempt for leakers. He hated social security, loved Ron Paul and his ideas, and peddled the NRA's garbage about fighting the government with guns. He suggested punishing both leakers and publications that publish the leaks. All in all, Edward Snowden is a right wing, anti-government nutjob who has managed to become the hero of so many on the reactionary Left.

Ars Technica reports that Ed Snowden is not much more than your typical, teabagging, cookie-cutter right wing nutjob who hates Obama. He complained about everything from the president's appointment to the CIA to gun control to how Social Security has turned old people into lazy moochers.
 Once Obama took office, Snowden groaned about his policies with increasing frequency. Fears that Obama might revive an assault weapons ban didn't sit well with him as a defender of the Second Amendment. Another sticking point was social security. Snowden was an individualist, even when it was unpopular; he saw little need for a safety net.
Here are just some of the choice quotes from the freakout Left's new hero. I have modified the transcripts only to change "TheTrueHOOHA" to "SNOWDEN" (for ease of following), and to highlight through formatting.

Gun-nut:
 User: the restrictions were made to appease the conservatives to get another bill passed. fucking cons.

SNOWDEN: See, that's why I'm goddamned glad for the second amendment. Me and all my lunatic, gun-toting NRA compatriots would be on the steps of Congress before the C-Span feed finished.
Something tells me Edward Snowden is more fit to be a Tea Party candidate for office in the mold of Sharron Angle (of the infamous "Second Amendment remedies") than a liberal icon - if the screaming "progressives" on the Internet were still capable of having a value system other than "we hate Obama," that is.

Choice words for Social Security and the New Deal:
 SNOWDEN: save money? cut this social security bullshit
User11: hahahayes
User18: Yeah! Fuck old people!
User11: social security is bullshit
User11: let's just toss old people out in the street
User18: Old people could move in with [User11].
User11: NOOO
User11: they smell funny
SNOWDEN: Somehow, our society managed to make it hundreds of years without social security just fine
SNOWDEN: you fucking retards
SNOWDEN: Magically the world changed after the new deal, and old people became made of glass
SNOWDEN: yeah, that makes sense
User11: wow
User11: you are just so fucking stupid
SNOWDEN: yeah, [User11]. and you're quite a gem
User19: and magically, life expectancy has doubled in the last 100 years.funny how that works.
SNOWDEN: [User19], you don't think modern medicine has something to do with that? no? it's social security? wow. I guess I missed that.
User11: hurr wait a second, life expectancy has shot up in recent times along with the dissolution of the communal family unit in exchange for the nuclear family
User11: gee i guess we might need to create a safety net for the sudden glut of helpless elderly????
SNOWDEN: they wouldn't be fucking helpless if you weren't sending them fucking checks to sit on their ass and lay in hospitals all day
User11: you are so goddamned stupd*pid
User11: PUT OLD PEOPLE TO WORK IN THE FIELDS
SNOWDEN: my grandmother is eighty fucking three this year, and you know what? she still supports herself working as a goddamned hairdresser
 His grandmother would be so proud, who he also claims doesn't support Social Security.

And his opinion on the racist, wingbat Ron Paul? "Dreamy."

But but but, I can already hear the screamers, you're distracting from the point! It's about government secrecy! I wonder how Snowden felt about that? In January 2009, less than two weeks before Obama took office, the New York Times reported on a leak that President Bush had rejected Israel's request for bunker-busters to hit Iran's nuclear facility. Pointing to that story, Snowden not only advocated for the leakers to be "shot in the balls," but also for the reporting organization (in this case the NY Times) to go out of business.
 SNOWDEN: HOLY SHIT
http://www.nytimes.com/2009/01/11/washington/11iran.html?_r=1&hp
SNOWDEN: WTF NYTIMES
SNOWDEN: Are they TRYING to start a war?
Jesus christ
they're like wikileaks
User19: they're just reporting, dude.
SNOWDEN: They're reporting classified shit
User19: shrugs
SNOWDEN:
User19: meh
SNOWDEN: moreover, who the fuck are the anonymous sources telling them this?
SNOWDEN: those people should be shot in the balls.
Rather lovely sentiments, don't you think? I wonder when Snowden and Wikileaks will explain why he doesn't think he deserves the same punishment he himself prescribed for leakers. That's not all, of course. He lashed out at the New York Times for "blowing" the illegal Bush administration program to warrantlessly wiretap Americans, referring to the Times reporting on the matter in 2006.
 SNOWDEN: these are the same people who blew the whole "we could listen to osama's cell phone" thing the same people who screwed us on wiretapping over and over and over again [sic] Thank god they're going out of business.
User19: the NYT?
SNOWDEN: Hopefully they'll finally go bankrupt this year.
yeah.
So Snowden was a man all for illegally spying on Americans when Bush was in office, but suddenly when Obama takes office and brings the programs under legal cover and gets a court involved, Saint Snowden can stand it no more. Shocked, shocked I tell you to hear there's gambling in Casa Blanca.

Come to think of it, the Professional Left unites with Edward Snowden on that point exactly - the blind, likely racist, pure demonization of this president. After all, this really isn't about privacy or security, is it? If it were, we would be seeing mobilizations and hearing calls to change the law rather than screams of 'scandals' about a program which even the toughest critic admits is perfectly legal under the law as it stands today. We would be seeing a laser focus not on obtaining the freedom of a criminal but on a vigorous debate about the merits of the law itself. Yet, rarely do we hear those calls on "liberal" sites like Daily Kos or on "liberal" shows coughing up a spleen defending Ed Snowden (I'm talking to you, Chris Hayes). What we hear far more often is the lashing out, the "free Snowden" cheerleading, and the unadulterated contempt for the president as well as rule of law. No, it's not about concerns about privacy. This is about concern-trolling about privacy.

Edward Snowden is a pathetic excuse for a hero or a whistleblower. He is a lunatic libertarian far-right nutjob that compromised national security for his personal fame. He has no values, no ethics, no moral core. He is a right wing blowhard that is playing the Professional Left for everything they are worth (which, thankfully, is not much). He is using their Blind hatred of a black president named Barack Obama to make them do the bidding of his own agenda which has nothing to do with transparency nor democracy. And the Professional Left is running right along, singing the praises of this ring-wing nutjob, licking this traitor's boots.

Wednesday, June 26, 2013

The Errors of Edward Snowden and His Global Hypocrisy Tour

by Kurt Eichenwald/Vanity Fair

My tolerance for Edward Snowden has run out.
The former contractor with the National Security Agency who divulged classified secrets about domestic surveillance programs has undertaken what can only be depicted as the global hypocrisy tour. A man outraged by American surveillance and who advocates free expression toodles happily to Hong Kong, a special administrative region of China? Then off to Moscow? Then tries for Ecuador (and, in some accounts, Cuba)?
And along the way, Eddie decided to toss out classified information about foreign-intelligence surveillance by the United States in other countries. For the Chinese, he was quite a spigot of secretsHe revealed documents showing that the N.S.A. had obtained text messages from the Chinese by hacking into some of the country’s telecommunications networks, engaged in computer espionage activities at Tsinghua University, and hacked into systems of Pacnet, an Asian provider of global telecommunications service.
Now, before I get into the specifics of Snowden’s China leaks, I want to stop for a minute. I know that, from the time he disclosed classified documents about the mass collection of Americans’ telecommunications data, there have been plenty of debates about whether Snowden is a whistle-blower or a traitor. And I can understand that disagreement when it comes to the data-mining program that slurps up e-mail and phone data of American citizens. But what, exactly, is Snowden attempting to prove with his China revelations? That countries engage in espionage? That the United States listens in on communications of countries with which it maintains often tense and occasionally volatile relations?
The existence of electronic espionage seems to be his beef. In an interview with the South China Morning Post—in which he admitted that he took a job as a systems administrator with an N.S.A. consultant, Booz Allen Hamilton, for the purpose of stealing classified documents—Snowden laid out his bizarre and egomaniacal philosophy: he would decide what information to pass on in countries around the world.
“If I have time to go through this information, I would like to make it available to journalists in each country to make their own assessment, independent of my bias, as to whether or not the knowledge of US network operations against their people should be published.”
I’ll have to assume that Snowden is on this fit of self-righteous arrogance because he thinks there is something wrong with what he’s seen of United States surveillance in other countries. But to decide that standard espionage activities are improper is a foolish, ahistorical belief.
N.S.A. surveillance has been beneficial repeatedly in American foreign policy. Although most instances remain secret, we already know that the N.S.A. listened to Soviet pilots during the 1983 shooting down of a South Korean airliner; used intercepted diplomatic messages to track a 1986 Berlin disco bombing to Libya; and used the cell phones’ SIM cards to track terrorist suspects after the 9/11 attacks.
But let’s take a more important example. In 1937—at a time when the United States was declaring neutrality in the emerging global tensions that fueled World War II—the Japanese government created a cipher for its military messages using a device called the “97-shiki O-bun In-ji-ki.” The Americans code-named it “Purple.”
The United States military was able to intercept Japanese communications (the very reason that Tokyo needed a code) but couldn’t decrypt the information sent through the Purple machine. William Friedman, the first American cryptography expert who tried to break the code, made some progress before suffering a nervous breakdown. Using that initial information, others managed to break more of the code. Once cracked, the United States could track Japanese naval-troop movements and even intercepted communications containing plans for the Pearl Harbor attack—information that was not properly used.
Would Snowden have been outraged that the United States was intercepting Japanese data at a time when the countries were not at war? It took years to crack the Purple code—would Snowden think the United States should have waited until after Pearl Harbor to tap into Japanese communication lines, and only then begin the arduous effort to break the code? And if not, then what is his point in turning over these kinds of secrets to the Chinese? All I have to say is, thank God Snowden was not around in 1937, four years before the United States joined the war—Lord knows how many Americans would have died if he had acted with whatever arrogance, or self-righteousness, or narcissism, or pure treasonous beliefs that drove him to his espionage on behalf of the Chinese.
Now for a closer look at the specific details Snowden turned over. In trying to understand this, I reached out to an individual I know who spent much of a lifetime in the intelligence world, including some related to parts of Asia. While he specifically stated that nothing he discussed would be based on classified information, he was able to offer a number of educated explanations why the United States would be involved in the activities in China that Snowden revealed.
Take the actions involving Tsinghua University. There are many reasons the N.S.A. would be interested in communications and computer activities at this Beijing-based school. For example, beginning in the past decade or so, university programs on arms control have played an important role in the Chinese government’s efforts to administer export controls on sensitive items. (For those wishing to know more, this is well detailed in a book published by the Rand Corporation called Chasing the Dragon: Assessing China’s System of Export Controls for WMD-Related Goods and Technologies.) Now, perhaps the most prominent university program in China on arms control is at—you guessed it—Tsinghua University. So, do you think there might be a reason why the N.S.A. would want to know about any communications on arms control that might take place between the Chinese government and Tsinghua?
The importance of China in global arms-control issues is hard to understate, even in American negotiations with Russia over proposals on nuclear-arms reduction. As Richard Weitz, a senior fellow and director of the Center for Political-Military Affairs at Hudson Institute, wrote last year:
China’s continued absence from strategic nuclear arms control negotiations is already impeding U.S.-Russian progress in this area. Beijing has traditionally resisted participating in formal nuclear arms control agreements. . . . Whereas U.S. officials want the next major nuclear arms reduction agreement to include only Russia and the United States, Russian negotiators want China and other nuclear weapons states to participate. In particular, Russian representatives insist they cannot reduce their major holdings of nonstrategic, or tactical, nuclear weapons without considering China’s growing military potential. Involving China in certain U.S.-Russian arms control processes could facilitate progress between Moscow and Washington in these areas and yield ancillary benefits for related issues.
Is this the reason for the N.S.A.’s activities at Tsinghua? My intel friend held it out as a good, educated guess, but then made a broader point. Contrary to the depictions in moviesthe N.S.A. does not engage in foreign surveillance as part of some James Bond–ian plot to take over the world. Decisions are based on the national-security needs of the United States. Actions at Tsinghua are not arbitrary; there is a national-security reason they are being done, whether about arms-control policies in China, something else altogether, or both.
As for the N.S.A. gaining access to Pacnet, the best answer is: no kidding. Snowden has expressed seeming outrage both at this and at the fact that Britain, through the Government Communications Headquarters, had tapped into undersea fiber-optic cables. Pacnet operatesEAC-C2C—the leading fiber-optic submarine cable network in Asia, connecting Hong Kong, China, Korea, Taiwan, Japan, the Philippines, and Singapore. In other words, international communications between Asian nations have a good chance of going through the Pacnet cables.
And, what apparently shocks Snowden but what any fool has known for years, the advent of fiber-optic technology has required the N.S.A. and other allied intelligence services to get into the business of cable-tapping. They had the choice: either tap cables or, in some fit of childish, Snowden-like horror at the demands of international security operations, surrender access to intelligence that the West has depended on for decades.
This problem was discussed in a top-secret, hush-hush, “no one can ever see it” public report by the Congressional Research Service on—get ready—January 16, 2001. This 12-year-old document explains not only the reason for expanded international surveillance, but also the need to tap cables:
In the past decade, two important trends have combined to change the nature of electronic surveillance efforts. The end of the Cold War meant policymakers and military officials had a wider range of countries that they were concerned with and placed much greater emphasis on “non-state actors”—terrorist groups and narcotics smuggling organizations that have come to be seen as genuine national security threats. These links are not necessarily easy targets given the great expansion in international telephone service that has grown by approximately 18% annually since 1992. Intelligence agencies are faced with profound “needle-in-a-haystack” challenges; it being estimated that in 1997 there were some 82 billion minutes of telephone service worldwide. The technologies used in civilian communications circuits have also changed; in the past decade reliance on microwave transmissions (which can be intercepted with relative efficiency) has been increasingly displaced by fiber optic cables. Fiber optics can carry far more circuits with greater clarity and through longer distances and provides the greater bandwidth necessary for transmitting the enormous quantities of data commonplace in the Internet age. Inevitably, fiber optic transmissions present major challenges to electronic surveillance efforts as their contents cannot be readily intercepted, at least without direct access to the cables themselves.
Please note, this document is pre-9/11, from a government analytical group outside of the intelligence agencies, discussing the need to tap cables for the purpose of aiding in the surveillance of terrorist groups and narcotics smugglers. (Asia, anyone?) This is not some excuse for what was done in the aftermath of the al-Qaeda attacks in New York and Washington.
But the most important sentence in this report is this: Intelligence agencies are faced with profound “needle-in-a-haystack” challenges. And that is the point of all of this Snowden-esque controversy. In the past, it was comparatively easy to snap up national-security intel—set up a microwave interception system targeting Soviet officials and agents, or some such. America could identify those who posed the national-security threat. Now, not so much.
To hunt for needles, the N.S.A. needs a global haystack that can be used for data mining. That is what the data collection is all about; no one has any interest in listening in on innocuous calls or reading pointless e-mails. This is all about using computers—massive, massive computers—and using complex models and algorithms to find the needles, rather than hoping to guess how to keep Americans safe, just in case the Ed Snowdens of the world might get upset with more intelligent approaches.
Which brings us back to Snowden’s global hypocrisy tour. I think nothing has more thoroughly damaged Snowden’s “whistle-blower” persona than his bizarre—and, I would say, cowardly—decision to rely on some of the countries with the greatest history of oppression to help keep him out of the Americans’ hands. (Usually, when people engage in civil disobedience for a cause—which Snowden seems to want people to believe he is doing—they accept the punishment that will accompany their decision. Snowden, instead, has acted like a spy, fleeing to countries with deeply strained relationships with the United States.
The irony of someone purportedly dedicated to privacy and human rights aiding the Chinese government grew even starker while Snowden was in Hong Kong. Last week, Human Rights Watch issued a report condemning a massive surveillance campaign undertaken by the Chinese government in Tibetan villages, which results in political re-education of those who may question the Communist regime and the establishment of partisan security units. “These tactics discriminate against those perceived as potentially disloyal, and restrict their freedom of religion and opinion,” Human Rights Watch wrote.
But hey, that’s just real life, not the Internet privacy that concerns Snowden. And, of course, the level of the Chinese government’s surveillance and control of their citizens’ use of the Internet is almost an art form. Just six months agoChina’s legislative body, the Standing Committee of the National People’s Congress, adopted the “Decision to Strengthen the Protection of Online Information.” The new rules, which Human Rights Watch says “threaten security and privacy of internet users,” require telecommunications providers to collect reams of personal information about customers who sign up for Internet, landline, or cell-phone service. The law also requires for the providers to insure they have the ability to immediately identify the real names of people who post comments under pseudonyms. Guess why? “In the days following the decision,’’ Human Rights Watch reported, “several well-known online activists found that theirweibo micro-blogging accounts had been shut down.’’
As for Russia, the crackdown on public activism has intensified in recent months, which, again, has led to Human Rights Watch issuing a report just a few weeks before Snowden landed in Moscow. “The crackdown is threatening civil society,” said Hugh Williamson, Europe and Central Asia director at Human Rights Watch. “The EU has spoken out strongly in recent months, but now is the time to directly call on Russia’s leadership to revise restrictive laws and stop the harassment of independent groups.” Primarily, the Russians are going after hundreds of rights groups and related activist organizations as part of a massive campaign to force them to register as foreign agents. “The authorities are seeking to define ‘political’ so broadly as to make any involvement in public life that is not controlled by the government off-limits,” Williamson said. “They are also trying to tarnish groups with the ‘foreign agents’ label, which in Russia can only mean ‘spy.’”

And what about Ecuador? Why, just two weeks ago, this country that is apparently on Snowden’s list of possible future homes passed new rules that impede free expression. The statute, called the Communications Law, prohibits anyone from disseminating information through the media that might undermine the prestige or credibility of a person or institution (you know, like revealing a government-sponsored surveillance program). The law also places burdens on journalists, making them subject to civil or criminal penalties for publishing information that serves to undermine the security of the state (you know, like revealing a government-sponsored surveillance program).
The takeaway from all of this is perplexing. Perhaps Snowden is so impaired by his tunnel vision about America’s espionage techniques that he doesn’t understand he has made himself an international fool by cozying up to some of the world’s less-admirable regimes on issues of human rights. And there is another thing to bear in mind: Since Snowden seems keen on turning over secret American information to repressive governments, will he be, in the end, acting to aid that repression? Will whatever information he yields be the missing thread that these authoritarian governments need to oppress their citizens more?
I don’t know. Neither do you. And, in the most horrible reality of all, neither does Edward Snowden.

Tuesday, June 18, 2013

Hannity Proffers Laughable Defense For Surveillance Hypocrisy

From the June 17 edition of Fox News' Hannity: 
 
 
 
 
 
00:00
 
00:00
 
 
 
 
 
 

Friday, June 14, 2013

Through a PRISM Darkly: Is There Less Here Than Meets the Eye?

by: /The Big Slice

light spectrum
What do you get when you combine a cheesy PowerPoint presentation, an IT geek with delusions of grandeur, an Obama-hating narcissist who fancies himself the blogosphere’s champion of civil liberties, and a punditocracy whose members make their living on the Internet but can’t explain the difference between Dropbox and Gmail? Behold PRISM.
The existence of PRISM was the subject of the second in a series of blockbuster stories detailing the activities of the National Security Agency, its revelation the product of a “crisis of conscience” on the part of NSA spywhistleblower defector(?) Edward Snowden, a 29-year-old high school dropoutturned NSA security guard turned CIA techie turned employee for NSA contractor Booz Allen Hamilton in Honolulu. Snowden apparently used his position as a computer security consultant toabscond with four Booz Allen laptops copy a bunch of files he wasn’t supposed to copy (despite his “top secret” security clearance) onto a thumb drive and then leave his girlfriend and his $200,000$122,000-a-year job to hop a flight to Hong Kong.
Once in Hong Kong, Snowden provided classified NSA files to activist/pundit/journalist Glenn Greenwald, formerly of Salon.com and now with the UK’s Guardian newspaper, and the Washington Post’s Barton Gellman.
The Guardian broke the first story based on Snowden’s purloined NSA files on June 5, posting a copy of an order marked “top secret” from the Foreign Intelligence Surveillance Court requiring Verizon Business Network Services – a Verizon subsidiary providing phone service to business customers – to turn over “telephony metadata” for calls within the United States and between the U.S. and foreign numbers. The information subject to the order includes phone numbers, IMEI numbers and call durations. The order did not cover the contents of calls or subscribers’ names or addresses. Most in the media assumed – and no one has denied – that the court has issued similar orders to other U.S. phone companies.
As an aside, it is useful to know that the creation of the Foreign Intelligence Surveillance Court, or FISA Court, dates back to the passage of the Foreign Intelligence Surveillance Act in 1978.  The law was passed in response to revelations about the Nixon administration’s use of federal agencies to spy on political opponents and activists and requires the government, before it commences certain kinds of intelligence gathering operations within the United States, to obtain a judicial warrant similar to that required in criminal investigations. The court consists of 11 life-tenured U.S. District Court judges (the same sort of judges who hear civil and criminal matters at the trial level in federal courts throughout the United States) selected by the Chief Justice of the Supreme Court to serve for seven-year stints. They travel from their home districts to Washington, D.C. to hear FISA warrant applications on a rotating basis. At least one of the judges must be a member of the U.S. District Court for the District of Columbia.  Because of its subject matter, the FISA Court’s proceedings are secret, as are its orders.
Although the FISA Court prohibited Verizon from disclosing the existence of the order obtained by the Guardian, Sen. Diane Feinstein (D-CA), chair of Senate Intelligence Committee, and Sen. Saxby Chambliss (R-GA), the committee’s ranking Republican, confirmed the NSA program’s existence on June 6, noting that the order published by the Guardian appeared to represent a routine three-month renewal of a program authorized under Section 215 of the Patriot Act that had been going on since 2007 and was subject to both congressional and judicial oversight. Indeed, prior to 2007 the Bush administration had conducted a nearly identical program, but without court approval. USA Today did a story about the program in 2006 that you can still find online. The only thing new in the Guardian’s story was the existence of the court order.
A day after the Guardian’s story broke, on June 7, Director of National Intelligence James Clapper declassified details about the NSA’s collection and storage of telephone metadata. According to Clapper, the NSA is prohibited by the FISC from “indiscriminately sifting” through the metadata. He said individual records can only be reviewed “when there is a reasonable suspicion, based on specific facts, that the particular basis for the query is associated with a foreign terrorist organization.” That would seem to rule out scrutiny of your phone calls to your pot dealer or to phone sex lines (though keep in mind that the DEA and local cops were seizing phone records and tapping phone lines long before the Patriot Act was even a twinkle in Dick Cheney’s eye).
Clapper also said that only counterterrorism personnel trained in the program may access the records, though this statement somehow seems less reassuring when you consider that the IT guy at the branch office in Hawaii managed to get his hands on the “top secret” court order.
NSA computers can reportedly analyze the metadata for patterns, spot unusual behavior and identify networks of callers in contact with suspicious phone numbers overseas. If the NSA (or the FBI, in the case of a subject inside the United States) wants to actually listen to calls, it needs to go back to court for a wiretap warrant.
So, that’s the telephone metadata story. Not much new, though thanks to the country’s short attention span and the media’s collective amnesia, it caused a fair amount of excitement, and deservedly so. Do we want the government indiscriminately collecting and storing information about our phone calls (even if it doesn’t listen to the calls themselves)? Keeping in mind Benjamin Franklin’s adage that “they who can give up essential liberty to obtain a little temporary security deserve neither liberty nor safety,” we have to ask ourselves whether the program makes us safer and, if so, whether that increase in safety is worth the erosion of our privacy. It’s a debate we should have had years ago. Still, better late than never.
The telephone records story generated a lot of heat (though both support for the program andcriticism were bipartisan, the hypocrisy and faux outrage from the likes of Rush Limbaugh and SeanHannity, supporters of the “surveillance state” under Bush, were predictably hilarious), but there were few outright denials. The media, politicians and even civil libertarians seem to generally agree about what is going on, even if they differ strongly on its merits. But that’s not the case with the second “blockbuster” story to come from Snowden’s thumb drive.
On June 6, both the Guardian and the Washington Post published articles based on several slides from a PowerPoint presentation about “PRISM.”  As Gellman at the Post breathlessly described this program:
The National Security Agency and the FBI are tapping directly into the central servers of nine leading U.S. Internet companies, extracting audio, video, photographs, e-mails, documents and connection logs that enable analysts to track a person’s movements and contacts over time.
The Post added that the NSA is “reaching deep inside the machinery of American companies that host hundreds of millions of American-held accounts on American soil.”  The story identified the companies involved as Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube and Apple. Dropbox was said to be joining the program soon.  According to the PowerPoint slides, the program began in 2007 (under Bush) and was expanded over the years as more Internet companies joined.
The Guardian’s Greenwald likewise reported that the NSA had obtained “direct access” to the Internet companies’ servers and implied that the agency’s spies could retrieve emails, Internet searches, photos – whatever – unilaterally and at will:
The Prism program allows the NSA, the world’s largest surveillance organisation, to obtain targeted communications without having to request them from the service providers and without having to obtain individual court orders. With this program, the NSA is able to reach directly into the servers of the participating companies and obtain both stored communications as well as perform real-time collection on targeted users.
Both the Post and the Guardian based these sweeping conclusions on a line in the PowerPoint slides referring to “collection directly from the servers” of the listed U.S. service providers. However, it appears neither the Post nor the Guardian made much of an effort to determine what this admittedly inartful wording meant. The PowerPoint slides themselves appear rather amateurish, and given their “top secret” nature it seems likely that they were not meant for distribution outside the NSA. Reporters at the Post and the Guardian seem to have used their imaginations to fill in the blanks.
Within hours of the stories’ publication, most of the companies named were strenuously denying the assertions that they had provided the NSA with direct access, or a “backdoor,” to their servers or that the agency was unilaterally downloading users’ information. Although critics of the NSA were calling the denials “carefully parsed,” they were, in fact, pretty unequivocal. Google co-founder Larry Page wrote:
First, we have not joined any program that would give the U.S. government – or any other government – direct access to our servers. Indeed, the U.S. government does not have direct access or a “back door” to the information stored in our data centers. We had not heard of a program called PRISM until yesterday.
Second, we provide user data to governments only in accordance with the law. Our legal team reviews each and every request, and frequently pushes back when requests are overly broad or don’t follow the correct process. Press reports that suggest that Google is providing open-ended access to our users’ data are false, period. Until this week’s reports, we had never heard of the broad type of order that Verizon received – an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false.
On June 7, the day after the PRISM story broke in the Post and the Guardian, the New York Timesreported that rather than direct, unfettered access to the companies’ central servers, what really happens at those companies that have made arrangements with the NSA is that data the companies are required by law to produce pursuant to a warrant or other court order is placed in a separate “secure portal.” The Times further described this “portal” as being similar to “a digital version of the secure physical rooms that have long existed for classified information, in some instances on company servers.”
On June 11, Google confirmed to the Wall Street Journal that the process for turning over data to the government is even less “high tech” than the Times piece had made it sound. According to Google spokesman Chris Gaither, when the company receives a court order to turn over information, it usually does so using a secure FTP, or “file transfer protocol,” server. The current specification for FTP dates to 1985. Gaither said Google occasionally even hands the data over to the NSA or law enforcement in person.
So basically, it appears that the process by which the NSA obtains data from Google and other companies is more akin to accessing a shared file on Dropbox than it is to tapping into or intercepting Internet traffic in real time. When you send someone a link to a shared file or folder on Dropbox, you are not giving that person access to your entire hard drive or a window into your Internet activity. Rather, your computer uploads the specific folder or files to be shared to the “cloud,” and the person you’re sharing it with then downloads it to her computer. In the case of PRISM, “Direct access” may mean access to a dedicated FTP server at Google, but it does not appear to mean access to Google’s “central servers.”
The Post began backing off some of its claims the day after its June 6 story, wiping a statement from the article that the Internet companies had “participated knowingly” in PRISM. Without running a correction or acknowledging any error on its part, the Post substituted the following phrase:
It is possible that the conflict between the PRISM slides and the company spokesmen is the result of imprecision on the part of the NSA author. In another classified report obtained by The Post, the arrangement is described as allowing “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers.
Of course, it is more than a little weasely for the Post to refer to the “conflict between the PRISM slides and the company spokesmen,” since the slides were never meant to describe or explain PRISM to the Post or anyone else outside the NSA, and the PowerPoint’s authors can hardly be held responsible for assumptions made by reporters.
The Guardian’s Greenwald, a longtime proponent of the “Obama is worse than Bush” school of civil libertarians, has been even more reluctant to concede his own fallibility.  In an interview with MSNBC’s Chris Hayes on June 12, Greenwald steadfastly refused to admit any error in his reporting:
Our story was the following: we have documents, a document, from the NSA that very clearly claims that they are collecting directly from the servers of these Internet giants. That’s the exact language that this document used. We went to those Internet companies before publishing and asked them, and they denied it, and we put into the story very prominently that they denied it. Our story is that there is a discrepancy between the relationship that these, that the private sector and the government has, in terms of what the NSA claims and what the technology companies claim.
There’s a “discrepancy” all right, but it’s not between the PowerPoint slides and the statements of the Internet companies. It’s between Greenwald’s article, on the one hand, and the reporting of the New York Times, the Washington Post, the Wall Street Journal, Mother JonesThe Nation  – oh hell, just about everyone who has done any digging on this story – on the other.  Indeed, even the Guardian now implicitly concedes that its “direct access” charge is a crock. But rather than run a correction, it buried the admission deep in a follow up story that ran almost a week after the original piece, and then continued to pretend that it was the Internet companies – rather than the Guardian itself – that are being evasive:
The Guardian understands that the NSA approached those companies and asked them to enable a ‘dropbox’ system whereby legally requested data could be copied from their own server out to an NSA-owned system. That has allowed the companies to deny that there is ‘direct or indirect’ NSA access, to deny that there is a ‘back door’ to their systems, and that they only comply with ‘legal’ requests – while not explaining the scope of that access.
In fact, as the Guardian well knows, the companies are precluded by the very court orders compelling them to turn over the data from disclosing the targets or scope of the FISA Court’s orders. That is why Google, Facebook, Microsoft and Twitter have pleaded with the U.S. Department of Justice to permit them to disclose the number of government requests they receive and their scope.
Some of the best reporting on PRISM has come from tech blogs such as ZDNet and CNET. Within 24 hours of the original publication, ZDNet’s Ed Bott did an epic takedown of the Post’s sloppy reporting and surreptitious updates, even posting a redlined comparison of the original and modified articles. CNET’s Declan McCullagh schooled the Post and its Pulitzer Award-winning reporter Gellman on how to quickly and thoroughly vet and run down a source’s story about the NSA and Internet surveillance, obtaining interviews with former government officials, Google’s former deputy counsel and the NSA’s former general counsel. McCullagh also provided a succinct layman’s explanation of Section 702 of FISA, the statutory provision under which the NSA obtains data from Internet companies.
The difference between the original Post and Guardian stories about PRISM, alleging “direct access” by the NSA to Internet companies’ servers, and the reality emerging from the companies’ denials and the reporting of multiple news outlets is enormous. Without this key and now debunked allegation, the only “stories” here are the poor PowerPoint skills of our country’s premier cyber warriors and Mr. Snowden’s handiness with a thumb drive. The fact that the government can compel Google, Yahoo, Microsoft, etc. to produce data from a user’s account pursuant to a warrant or court order is most decidedly not news. Companies have been complying with subpoenas and warrants for their customers’ records for decades, if not centuries. Nor does it make much difference whether the companies produce such data in the form of reams of paper packed in banker’s boxes, a DVD, or through a secure FTP server or electronic drop box.
Indeed, there is some reason to believe that PRISM is not a data collection program at all, but an unclassified data management tool for use by the military, which after all, is in charge of the NSA. If so, PRISM is less a surveillance program than a software app through which NSA analysts can retrieve data already produced in response to court orders.
As Mother Jones’ Kevin Drum notes, these questions about the nature of PRISM also go to Snowden’s credibility as he continues to serve as a source for additional revelations, something Greenwald has repeatedly promised. Snowden either knows what PRISM is but failed to explain it to Gellman and Greenwald, or he really is just a glorified tech support guy who stole classified files he did not fully understand and gave them to a couple of reporters. Given Snowden’s dubious boasts that he could wiretap anyone, even the president, and that he had access to every CIA station around the world, his credibility is hardly a given.
Snowden’s motives are also coming under increased scrutiny. His apparent disclosure of NSA documents detailing the hacking of computers in China to the South China Morning Post, a Hong Kong newspaper whose owners are reported to be friendly with the leadership in Beijing, seems to belie his claim that he is not out to harm U.S. interests. The same can be said of his disclosure of a directive by President Obama to draw up a list of targets for cyber attacks in the event of a crisis. Whatever the wisdom or morality of cyber warfare (and yes, I know the Obama administration’s hands are hardly clean given the Stuxnet attack on Iran’s uranium centrifuges), there is no doubt that America’s adversaries are planning for attacks on the U.S. as well.
But this isn’t just about the messenger. The questions about the nature of PRISM are more than a matter of semantics. The original stories’ suggestion that the government has been monitoring Americans’ emails and Internet usage and indiscriminately vacuuming up audio, video, photographs, messages, documents and connection logs has caused widespread alarm. Such a program would be far more intrusive than the telephone metadata collection that was the subject of the Verizon court order. Moreover, the failure of the Post and the Guardian to issue any corrections or clarifications has left pundits, bloggers and cable news hosts free to repeat and perpetuate the original conjecture about “direct access” to Internet companies’ main servers. Allusions to “Big Brother” are all the rage. On the bright side, I’m betting that a record number of Americans now know the phrase originated with a George Orwell novel and not the CBS reality show.
Suddenly, millions of Americans who never gave much thought to third-party tracking cookies, call center workers in Mumbai accessing their credit card records, or spring break photos posted on friends’ Facebook pages are freaking out over the government learning about the porn sites they’ve visited, the subversive (or reactionary) blogs they’re reading and the boxes of ammo they’re buying online. Woe unto anyone who tries to talk them down. It will only get you labeled an “apologist,” an “Obamabot,” a “fascist,” or worse.
Don’t get me wrong. I’m not saying the government isn’t engaged in pervasive snooping, and some future whistleblower may well expose a nefarious government conspiracy to spy on all of us 24/7. Just because you’re paranoid doesn’t mean they’re not out to get you. But if such a program exists, it doesn’t appear that PRISM is it.