Showing posts with label June 10. Show all posts
Showing posts with label June 10. Show all posts

Saturday, June 11, 2016

Friday: Ball and Chain

This end-of-the-work-week observation is a little different. I’ve posted some not-jazz jazz for your listening pleasure. This piece called Ball and Chain is performed by a loosely joined group of people who worked on development of a subgenre of jazz during the 1990s. It’s called M-base — short for “macro-basic array of structured extemporization” — which relies on improvisation along with non-European elements as jazz does. But its artists’ deliberation in composition combined with a more contemporary flare set this style of music apart from other jazz.

Sample a couple more pieces with a little extra estrogen — Cassandra Wilson’s vocals in You Don’t Know What Love Is, and Geri Allen’s keyboarding here with Esperanza Spalding and Terri Lyne Carrington performing Unconditional Love at a recent Jazz in Marciac festival. Wilson and Allen have both been members of the M-base collective, along with Steve Coleman, Robin Eubanks, Graham Haynes, and Greg Osby. I recommend searching out each of those folks in YouTube to explore their continuation of M-base in their work.

That’s enough to get you through your Friday evening nightcap. You’ll probably need one after this stuff.

Volkswagen’s Dieselgate

Living in a Digital World

  • Twitter says it wasn’t hacked after millions of users’ account data appears online (Bloomberg) — Hey, listen up, boneheads complaining about your Twitter account being locked: 1) Change your password periodically (like every 12 weeks) and 2) DON’T USE THE SAME PASSWORD ON MORE THAN ONE ACCOUNT. Looks like some folks haven’t learned that once one account is breached, more are at risk if they use the same password or a previous iteration from another account. ~smh~ It would take very little to create a database of breached addresses from multiple platforms and compare them for same passwords. If, for example, [123456PW] is used on two known accounts, why wouldn’t a hacker try that same password on other accounts attached to the same email address?
  • Oklahoma state police bought debit card scanning devices (KGOU) — They’re not merely reading account data if they pull you over and take your card to scan for information. They may confiscate any funds attached to the card, too, under civil forfeiture. This is ripe for abuse and overreach, given poor past legal precedent. Why is a magnetic strip any different than your wallet?

Economics of a different kind

  • Economics don’t match reality, and the root of the problem is academic (BloombergView) — Each of “coffee house macro,” finance macro, Fed macro, and academic macroeconomics are grossly out of sync with reality. But the root of this distortion is the one thing they all have in common: their origin in academic economics. Yeah — academia has become little more than an indoctrination factory for the same flawed concepts, while reducing any arguments against the current “free market uber alles” thought regime.
  • Adbusters isn’t waiting for academia; they’re ready to Battle for the Soul of Economics (kickitover.org) — Check it, social media warfare has begun.

That’s a wrap on this week. I’m fixing myself a stiff belt and shuffling off to bed. Catch you Monday, the Fates willing and the creek not rising due to climate change.

Friday, June 10, 2016

How Did Booz Employee Analyst-Trainee Edward Snowden Get the Verizon 215 Order?

One thing I’ve been pondering as I’ve been going through the Snowden emails liberated by Jason Leopold is the transition Snowden made just before he left. They show that in August 2012, Snowden was (as we’ve heard) a Dell contractor serving as a SysAdmin in Hawaii.

Screen Shot 2016-06-10 at 1.48.37 PM

The training he was taking (and complaining about) in around April 5 – 12, 2013 was in preparation to move into an analyst role with the National Threat Operations Center.

Screen Shot 2016-06-10 at 1.55.17 PM

That would mean Snowden would have been analyzing US vulnerabilities to cyberattack in what is a hybrid “best defense is a good offense” mode; given that he was in HI, these attacks would have been launched predominantly from, and countermeasures would be focused on, China. (Before Stewart Baker accuses me of showing no curiosity about this move, as Baker did about the Chinese invitation to Snowden’s girlfriend to a pole dancing competition, I did, but got remarkably little response from anyone on it.)

It’s not clear why Snowden made the switch, but we have certainly seen a number of cybersecurity related documents — see the packet published by Charlie Savage in conjunction with his upstream cyber article. Even the PRISM PowerPoint — the second thing released — actually has a cybersecurity focus (though I think there’s one detail that remains redacted). It’s about using upstream to track known cyberthreat actors.

Screen Shot 2016-06-10 at 2.09.14 PM

I suspect, given the inaccuracies and boosterism in this slide deck, that it was something Snowden picked up while at Booz training, when he was back in Maryland in April 2013. Which raises certain questions about what might have been available at Booz that wasn’t available at NSA itself, especially given the fact that all the PRISM providers’ names appear in uncoded fashion.

Incidentally, Snowden’s job changes at NSA also reveal that there are Booz analysts, not NSA direct employees, doing Section 702 analysis. In case that makes you feel any better about the way the NSA runs it warrantless surveillance programs.

Anyway, thus far, all that makes sense: Snowden got into a cybersecurity role, and some of the latest documents he took was a document that included a cybersecurity function (though presumably he could have gotten most of the ones that had already been completed as a SysAdmin before that).

But one of the most sensitive documents he got — the Verizon Section 215 primary order — has nothing to do with cybersecurity. The Section 215 dragnet was supposed to be used exclusively for counterterrorism .(And as I understand it, there are almost no documents, of any type, listing provider names in the Snowden stash, and not all that many listing encoded provider names). But the Verizon dragnet order it is dated April 23, 2013, several weeks into the time Snowden had moved into a cybersecurity analytical role.

Screen Shot 2016-06-10 at 2.29.20 PM

There’s probably an easy explanation: That even though NSA is supposed to shift people’s credentials as they move from job to job, it hadn’t happened for Snowden yet. That would say whoever was responsible for downgrading Snowden’s access from SysAdmin to analyst had not yet done so (there have been at least some cases of credentials not being adjusted since Snowden too, so they haven’t entirely addressed what would have to be regarded as a major fuck-up if that’s how this happened).

Interestingly, however, the declassification stamp on the document suggests it was classified on April 12, not April 23. On April 12, 2013, Snowden was still at Fort Meade.

Screen Shot 2016-06-10 at 2.34.33 PM

Whatever the underlying explanation, it should be noted that the most sensitive document Snowden leaked — the one that revealed that the government aspired to collect phone records from every single Verizon customer (and, significantly, the one that made court challenges possible) — had to have been obtained after Snowden formally left his SysAdmin, privileged user, position.

The SSCI Contemplates Splitting CyberCommand from DIRNSA

The Intercept’s Jenna McLaughlin liberated a copy of the Senate Intelligence Committee’s Intelligence Authorization for 2017 which was passed out of committee a few weeks back. There are two really shitty things — a move to enable FBI to get Electronic Communications Transaction Records with NSLs again (which I’ll return to) and a move to further muck up attempts to close Gitmo.

But there are a remarkable number of non-stupid things in the bill.

I’m particularly interested in this language.

Screen Shot 2016-06-10 at 9.01.03 AM

Unless I’m completely misreading it, this section would require the Director of NSA to be a separate person from the head of CyberCommand. It would require Admiral Mike Rogers’ current dual hat to be split.

Correction: DIRNSA and CyberCom would only need to be split if CyberCom gets elevated to be a full combatant command.

That’s a recommendation the President’s own Review Group made back in 2013, only to have the President pre-empt PRG’s recommendation before they could publicize it. It would also likely have some impact on NSA’s decision, earlier this year, to combine the Information Assurance Directorate — NSA’s defensive organization — in with its offensive mission.

Frankly, I think our entire cybersecurity approach deserves a more open debate. The IC has done a pretty crummy job at defending us from attacks, and it’s not clear what purpose their secrecy about that serves.

But I am intrigued that SSCI seems to think NSA should retain its defensive capability, independent of all its offensive ones.