Showing posts with label June 29. Show all posts
Showing posts with label June 29. Show all posts

Wednesday, June 29, 2016

House Homeland Security Committee Apparently Knows Little about Homeland Security

Here are the first 36 words of an otherwise useful House Homeland Security Committee report on encryption:

Public engagement on encryption issues surged following the 2015 terrorist attacks in Paris and San Bernardino, particularly when it became clear that the attackers used encrypted communications to evade detection—a phenomenon known as “going dark.”

The statement has grains of truth to it. It is true that engagement on encryption surged following the Paris attacks, largely because intelligence committee sources ran around assuming (and probably briefing the White House) that encryption must explain why those same intelligence committee sources had missed the attack. It surged further months later when FBI chose to pick a fight with Apple over Syed Rizwan Farook’s work phone which — it was clear from the start — had no evidence relating to the attack on it.

It is also true that ISIS had been using Telegram leading up to the Paris attack; in its wake, the social media company shut down a bunch of channels tied to the group. But there has never been a public claim the plotters used Telegram to plan their attack.

It is also true that an ISIS recruit, arrested and interrogated months before the Paris attack, had told French authorities he had been trained to use a Truecrypt key and an elaborate dead drop method to communicate back to Syria.

But it is not true that the Paris attackers used encryption to hide their plot. They used a great many burner phones, a close-knit network (and with it face-to-face planning), an unusual dialect. But even the one phone that had an encrypted product loaded on it was not using that service.

It is also not true that the San Bernardino attackers used encryption to evade detection. They used physical tools to destroy the phones presumably used to plan the attack. They hid a hard drive via some other, unidentified means. But the only known use of encryption — the encryption that came standard on Farook’s work phone — was shown, after the FBI paid to bypass it, not to be hiding anything at all.

Now it’s possible there was encryption involved in these attacks we don’t know about, that HLSC has gotten classified briefings on. But even if there was, it could not very well have led to a public surge of engagement last year, because it would not be public.

There are reasons to discuss encryption. But factually false claims about terrorists’ use of encryption are not among those reasons.

h/t to Access Now’s Nathaniel White, who pointed out this bogosity on Twitter.

Update: See this Grugq post laying out what little encryption ISIS has been known to use in any attack.

Wednesday: Wandering

All that is gold does not glitter; not all those who wander are lost.

— excerpt, The Lord of the Rings by J. R. R. Tolkien

It’s a lovely summer day here, cool and dry. Perfect to go walkabout, which I will do straight away after this post.

Hackety-hack-hack, Jack

  • Spearphishing method used on HRC and DNC revealed by security firm (SecureWorks) — Here’s their report, but read this Twitter thread if you don’t think you can handle the more detailed version. In short, best practice: DON’T CLICK ON SHORTENED LINKS using services like Bitly, which mask the underlying URL.
  • Researchers show speakerless computers can be hacked by listening to fans (arXiv.org) — Air-gapping a computer may not be enough if hackers can listen to fan operation to obtain information. I’ll have to check, but this may be the second such study.
  • Another massive U.S. voter database breached (Naked Security) — This time 154 million voters’ data exposed, revealing all manner of details. 154M is larger than the number of voters in the 2012 general election, though smaller than the 191M voters’ records breached in December. At least this time the database owner slammed the breach shut once they were notified of the hole by researcher Chris Vickery. Nobody’s fessed up to owning the database involved in the the December breach yet.
  • Speaking of Vickery: Terrorism databased leaked (Reddit) — Thomson-Reuters’ database used by governments and banks to identify and monitor terrorism suspects was leaked (left open?) by a third party. Vickery contacted Thomson-Reuters which responded promptly and closed the leak. Maybe some folks need to put Vickery on retainer…
  • Different kind of hack: Trump campaign hitting up overseas MPs for cash? Or is he? (Scotsman) — There are reports that Trump’s campaign sent fundraising emails received by elected representatives in the UK and Iceland. Based on what we know now about the spearphishing of HRC and DNC, has anybody thought to do forensics on these emails, especially since government officials are so willing to share them widely? Using these kinds of emails would be a particularly productive method to spearphish government and media at the same time, as well as map relationships. Oh, and sow dissension inside the Trump family, urm, campaign. On the other hand, lack of response from Trump and team suggests it’s all Trump.

Makers making, takers taking

  • Apple granted a patent to block photo-taking (9to5Mac) — The technology relies on detecting infrared signals emitted when cameras are used. There’s another use for the technology: content can be triggered to play when infrared signal is detected.
  • Government suppressing inventions as military secrets (Bloomberg) — There’s merit to this, preventing development of products which may undermine national security. But like bug bounties, it might be worth paying folks who identify methods to breach security; it’s a lot cheaper than an actual breach, and a bargain compared to research detecting the same.
  • Google wants to make its own smartphone (Telegraph-UK) — This is an effort apart from development of the modular Ara device, and an odd move after ditching Motorola. Some tech industry folks say this doesn’t make sense. IMO, there’s one big reason why it’d be worth building a new smartphone from the ground up: security. Google can’t buy an existing manufacturer without a security risk.
  • Phonemaker ZTE’s spanking for Iran sanction violations deferred (Reuters) — This seems kind of odd; U.S. Commerce department agreed to a reprieve if ZTE cooperated with the government. But then think about the issue of security in phone manufacturing and it makes some sense.

A-brisket, a Brexit

  • EU health commissioner Andriukaitis’ response to Nigel Farage’s insulting remarks (European Commission) — Farage prefaced his speech to European Commissioners yesterday by saying “Most of you have never done a proper day’s work in your life.” Nice way to win friends and influence people, huh? Dr. Vytenis Andriukaitis is kinder than racist wanker Farage deserves.
  • Analysis of next couple years post-Brexit (Twitter) — Alex White, Director of Country Analysis at the Economist Intelligence Unit, offers what he says is “a moderate/constructive call” with “Risks definitely to the downside not to the upside.” It’s very ugly, hate to see what a more extreme view would look like. A pity so many Leave voters will never read him.

Follow-up: Facebook effery
Looks like Facebook’s thrown in the towel on users’ privacy altogether, opening personal profiles in a way that precludes anonymous browsing. Makes the flip-flop on users’ location look even more sketchy. (I can’t tell you anymore about this from personal experience because I gave up on Facebook several years ago.)

Happy hump day!

In 2010, DOJ Was Stalling Gang of Four Member Silvestre Reyes Over Common Commercial Services Memo

As far as the public record shows, Ron Wyden first started complaining about the Common Commercial Service OLC Memo in late 2010, in a letter with Russ Feingold written “over two years” before January 14, 2013. As I’ve written, John Yoo wrote the memo on May 30, 2003, as one of the last things he did before he left the Office of Legal Council. It seems to have something to do with both the Stellar Wind program and cybersecurity, and apparently deals with agreements with private sector partners. At least one agency has operated consistently with the memo (indeed, Ron Wyden’s secret memo submitted to the court probably says the memo was implemented) but the government claims that doesn’t mean that agency relied on the memo and so the ACLU can’t have it in its lawsuit.

According to a letter liberated by Jason Leopold, however, someone in Congress was raising concerns about the memo even before Wyden and Feingold were. On June 30, 2010, then Chair of the House Intelligence Committee Silvestre Reyes wrote Attorney General Holder a letter about the memo. On October 5, Ron Weich wrote Reyes,

We have conferred with Committee staff about your letter and your concerns regarding the potential implications of the opinion. We appreciate your concerns and your recognition of the complexities of the issues involved in our consideration of your request. We will let you know as soon as we are in a position to provide additional information.

In other words, three months after one of the top ranking intelligence overseers in government raised concerns about the memo, DOJ wrote back saying they weren’t yet “in a position to provide additional information.”

That seems like a problem to me.

It also seems to be another data point suggesting that — whatever the government did back in 2003, after Yoo wrote the memo — it was being discussed more generally in 2010, possibly with an eye to implement it.

 

IARPA’s MOSAIC FitBit for Psych

EFF’s Dave Maass discovered this conference notice from the Intelligence Advanced Research Projects Activity.

Selecting and evaluating a workforce that is well-suited for the psychological and cognitive demands of the diverse positions across the Intelligence Community (IC) is an important and persistent need. This is growing in importance as the pace and complexity of the challenges facing the IC workforce grow and expand. Methods that enhance our ability to evaluate an individual’s psychological drivers, cognitive abilities, and mental wellness and resilience will enable improved capabilities to select the right person for the right job, evaluate and help maintain optimal performance throughout their career, and better understand and anticipate changes in an individual that may impact their work effectiveness, productivity, and overall health and wellness.

To address this challenge, the MOSAIC program aims to take advantage of multimodal mobile, worn, and carried sensors and the corresponding data to enable the measurement of an individual in situ, throughout their daily activities, using an aggregate of behavior, physiology, social dynamics, physical location and proximity, as well as other novel data sources. Research in this program will aim to establish convergent validity of multimodal signals across a range of researcher-defined contexts and over time to enable accurate and personalized evaluations. It is anticipated that research teams will develop and test a suite of multimodal sensors to collect a range of subject-focused and situational data; build capabilities to develop an integrated model of the subject, their behaviors, and the social and physical context; and advance methods to personalize modeling approaches to develop accurate assessments of an individual over time.

The Program, which uses the intelligence jargon “Mosaic” to stand for “Multimodal Objective Sensing to Assess Individuals with Context” would start with volunteers and then roll out better measurements, though it’s not clear whether the program, as conceived, would roll out to the IC as a whole.

It’s all very spooky, especially given that it doesn’t really say what it wants to measure. Is it going to be a running polygraph, a constant assessment of deceit of the kind the IC doesn’t encourage, if that can be distinguished from the kind it does? Will it measure how the best operatives respond to stress? What kind of spying on the spies will it enable?

But it’s nice to see IARPA making clear whether the push for things like FitBit will lead the rest of society.

Hillary’s National Security Alliance for Quivering Over Bank Prosecutions

Fresh off being caught lying about rolling her eyes in response to calls for Palestinian rights, Neera Tanden has rolled out something called the National Security Leadership Alliance. Best as I can tell, it exists mainly on paper right now — I couldn’t even find it on CAP’s site yet. But it seems designed to fear-monger about what will happen if Trump becomes Commander-in-Chief.

The project, called the National Security Leadership Alliance, will be funded by C.A.P. Action. It will feature a roster of major members of the foreign policy and national security community, including two retired four-star generals; Leon E. Panetta, the former C.I.A. director; Madeleine K. Albright, the former secretary of state; Eric H. Holder Jr., the former attorney general; and Carl Levin, the former Michigan senator. All have endorsed Mrs. Clinton.

There will be an effort to highlight precisely what, in the military arsenal, Donald J. Trump would have access to as president. Mr. Trump has been criticized for his views on foreign policy, criticisms that have been central to the case that Mrs. Clinton has made against him in an effort to describe the stakes of the 2016 presidential election. The Center for American Progress is led by a top outside adviser to Mrs. Clinton, Neera Tanden, and the new project seeks to put a spotlight on what officials are calling a progressive foreign policy vision.

I’m perfectly okay with fearmongering about Trump. But let’s look at this lineup. It features the woman who said letting half a million Iraqi children die was worth the price of enforcing sanctions against the country. It also includes a guy, Panetta, whose exposure of the identities of Osama bin Laden killers’ identities to Hollywood producers serves to reinforce what a double standard on classified information Hillary (and Panetta) benefit from.

But I’m most curious by a “national security” team that includes both Eric Holder and Carl Levin, especially given the NYT focus, in announcing the venture, on Brexit.

“I think what brought us together is obviously a lot of concern about some of the division and polarization that we’re seeing in the world,” Mr. Panetta said in an interview. “We know we’re living in a time of great change and uncertainty.”

But he added, “The concern we have is we see these forces of division that are prepared to throw out the fundamental” principles of foreign policy in the United States over many decades.

“What we’re learning from ‘Brexit’ is that there’s a price to be paid in terms of letting out emotion dictate policy instead of responsible leadership,” he said, referring to Britain’s vote to leave the European Union. “We shouldn’t throw the baby out with the bath water.”

Leon Panetta, in rolling out a venture including Carl Levin — who as head of the Senate’s Permanent Subcommittee on Investigations worked tirelessly for some kind of accountability on bank crime — and Eric Holder — who ignored multiple criminal referrals from Levin, including one pertaining to Goldman Sachs head Lloyd Blankfein — says the lesson from Brexit is that we can’t let emotion dictate policy but instead should practice “responsible leadership” guarding the “fundamental principles of foreign policy in the United States over many decades.”

Of course, as David Dayen argued convincingly, to the extent Brexit was an emotional vote, the emotions were largely inflamed by elite failures — the failures of people like Eric Holder to demand any responsibility (Dayen doesn’t deal with the equally large failures of hawks like Albright whose destabilizing policies in the Middle East have created the refugee crisis in Europe, which indirectly inflamed Brexit voters).

Again, I’m okay if Hillary wants to spend her time fearmongering about the dangers of Trump.

But to do so credibly, she needs to be a lot more cognizant of the dangers her own team have created.