11 ms·
NSA OSS Technologies
- deepnotderp 9y agoI see the PR department is getting smarter...
- mtgx 9y agoFederal government is required to open source at least 20 percent of its code now: https://sourcecode.cio.gov/ https://sourcecode.cio.gov/
- qeternity 9y agoThe cynic in me wonders which 20% we'll get. The repo linked here is pretty impressive, so I may have to eat crow. I would have expected to get every html template and vba macro ever written, instead of the value add stuff.
- skynode 9y agoMy thoughts exactly. That 20% will probably provide you with a map of Russia while you're flying over the Swiss Alps. Some things are better not learned (or known) at all than learned (or known) the wrong way.
- nl 9y agoThere are pretty big national security exemptions which the NSA could use without any question: https://sourcecode.cio.gov/Exceptions/ https://sourcecode.cio.gov/Exceptions/ That makes this effort even more commendable.
- bflesch 9y agoWow, that's great. The US being a first mover in OSS again, a pity that Germany doesn't have this.
- Animats 9y agoNSA has an offense side and a defense side, and they're not that tightly coordinated.
- tptacek 9y agoThey also have several offense sides, none of which are tightly coordinated. :)
- ganoushoreilly 9y agoAt least they merged / are merging IAD and SID, less confusion more chaos! https://www.washingtonpost.com/world/national-security/national-security-agency-plans-major-reorganization/2016/02/02/2a66555e-c960-11e5-a7b2-5a2f824b02c9_story.html https://www.washingtonpost.com/world/national-security/natio...
- miclill_kit 9y agoThat was exactly my thought as well.
- voltagex_ 9y agohttps://github.com/ozoneplatform/owf-framework https://github.com/ozoneplatform/owf-framework looks very interesting - NSA wrote their own BI tool?
- killjoywashere 9y agoOWF came up in a meeting recently -- may not be as awesome as NSA wants you to believe.
- voltagex_ 9y agoCan you share any other info?
- digitalzombie 9y agoreddit have a comment thread about this. Once comment described it as a "shit show". Apparently its terrible and they tried to get the company to rebuild it and they made it the same. Another comment comment on how "buggy" it was. Or that the only dev that willing to work with it are contractors that want money.
- annnnd 9y ago> Or that the only dev that willing to work with it are contractors that want money. Greedy b*stards! </sarcasm>
- ganoushoreilly 9y agoThe Ozone Widget Framework is horrible, you have to build your application sets to function standalone as well as in a modular compatibility with other widgets. Things break frequently and for the longest time Silverlight was a requirement too (well after it was canceled). It was absolutely horrible when I used it.
- trigoman 9y agoYeah OWF is kind of OK, we tried to use it but the docs aren't straightforward.
- lsh 9y agoI've trialed Apache Nifi and it's very powerful. It's also a little unsettling as you use it thinking about how the NSA used it ...
- Laforet 9y agoFWIW, all your crypto is used by NSA as well.
- StreamBright 9y agoNo wonder Hortonworks wanted to integrate it.
- Toast_ 9y agoNiFi looks pretty interesting, what's the learning curve like? Looks like a supercharged yahoo pipes.
- deleted 9y ago[deleted]
- grandalf 9y agoSome very cool stuff.... useful from both a practical and anthropological standpoint.
- SomeStupidPoint 9y agoThere's a lot of neat things there. (This one looks interesting: https://iadgov.github.io/goSecure/ https://iadgov.github.io/goSecure/) Also interesting is splitting the repos: that the NSA and IAD have different repos, and that one seems focused on defensive tech while the other is publishing analysis tools. I know there's a lot of people who aren't fans of the NSA (or what they do), but I think most of us can see a need for a military-grade organization to research defensive technologies for helping secure our infrastructure. I don't think many of us would be unhappy with the NSA if that's all they did. (Or phrased another way: most of us are unhappy because of how they conduct intel work or compromise defensive capability for offensive ones, eg, that whole business with ECC.) So I think it's important to respond positively to things like the IAD github page, even if we're not fans in general.
- alpb 9y agoI wonder why https://www.iad.gov https://www.iad.gov (linked at https://github.com/iadgov https://github.com/iadgov) is not using a TLS certificate trusted in normal browsers. I cannot visit the webpage as it uses DoD Root CA, which is not installed on my computer.
- e12e 9y agoHaving the US department of defense be able to forge certificates for every site world-wide, in every major browser - out of the box - might be a little too much, even with the CA system as broken as it is. On the other hand, if you run your own CA and mostly care about your own users - using a cert signed by your own CA makes sense - to a certain extent.
- ccrush 9y agoI think the question was "why aren't they running this public website with a cert signed by a widely trusted CA"?
- angry_octet 9y ago
- rdtsc 9y agoThis caught my eye: > https://github.com/apache/incubator-pirk https://github.com/apache/incubator-pirk > Employing homomorphic encryption techniques, PIR enables datasets to remain resident in their native locations while giving the ability to query the datasets with sensitive terms. I can imagine a few scenarios there. One perhaps is when db admin should not find out what someone, possibly working on a classified project is querying. Or say one compartment / project collected the data and now they want to share it with another project. Those read into the second project don't want to reveal to the first one what they are querying because it would reveal classified information. Another scenario is a database which has results of possibly illegally intercepted communications. If the NSA can argue that the Constitutionally defined "search" doesn't occur until someone actually performs a search (as in runs an SQL query over the data). Then having PIR capability means being able to break the law but only let as few people as possible do it. Also https://github.com/redhawksdr https://github.com/redhawksdr is pretty damn impressive. It looks like a complete parallel implementation of GNU Radio. Completed with an IDE and such. Wonder how it compares?
- jamra 9y agoAll valid points, but I think it has more to do with this research being popular in the encryption community. One of the Coursera teachers was working on something like that. An example of use is video games that help prevent hacking and modification. I think that there could be some great consumer usage for having the ability to encrypt data, but still be able to search it.
- Tepix 9y agoIntriguing indeed. Could this tech also be used to query a database or service to plot a route (say for navigating with your car) without revealing the route?
- Spearchucker 9y agoThis is pretty common in the commercial world too, and something I've done more than once myself. The obvious use case is storing medical records. In the UK personal medical records are often stored by systems integrators in datacentres with nebulous locations, and need to be accessed by third parties for things like underwriting life insurance policies. To protect the data (compliance with the EU data protection act) it's encrypted in transit AND at rest. Access to data by third parties is managed through AMRAs (access medical record authorisation), which are completed by the third party, authorised by the data owner (private individual) and given to the data owner's general/dental practitioner or pharmacist, who is able to access and decrypt and appropriately share the sensitive data.
- _eht 9y agoFeeling triggered... http://i.imgur.com/OnlJYq7.png http://i.imgur.com/OnlJYq7.png
- microwavecamera 9y agoIt's nice to see a push for open security and solutions rather than secretive offensive counter-security. Thanks. :)
- alltakendamned 9y agoOne does not exclude the other though
- beelle 9y agopitbullandgoldfishes.wordpress.com
- blazespin 9y agoI suspect there are a lot of very incredible computer programmers at the NSA and they're probably using just regular open source non security related tools every day. It's good to see that they're contributing back to the OS community what they can.
- sneak 9y agoLet's not forget: these people may be skilled, but they are working against every principle of our community. https://www-androidauthority-com.cdn.ampproject.org/i/www.androidauthority.com/wp-content/uploads/2014/06/SSL-Added-and-Removed-Here.jpg https://www-androidauthority-com.cdn.ampproject.org/i/www.an...
- lawless123 9y agoone of their links is to a security enhanced linux android. https://source.android.com/security/selinux/ https://source.android.com/security/selinux/
- angry_octet 9y agoAnd you pasted an amp link? Was that deep sarcasm? The world is full of shades of grey, and black and white 'they are all evil!' is just pointless and dumb.
- sneak 9y agoIt wasn't intentionally ironic. Where did I call anyone evil? I didn't even vilify people - I specifically focused on the work that these people are performing. It works to make the world a worse place. How should I criticize them?
- angry_octet 9y agoFor breaking the law and working to undermine the Constitution? Is that not a big enough claim? Maybe blame specific people (the DIR NSA Hayden, Bush, Obama). There was a strong culture at NSA of NOT spying on Americans until those clowns came along.
- hueving 9y agoViolating the sanctity of the captive portal license agreement! https://github.com/iadgov/goSecure/blob/master/scripts/wifi_captive_portal.py https://github.com/iadgov/goSecure/blob/master/scripts/wifi_... :)
- libeclipse 9y agoThe captive portal license agreement?
- deleted 9y ago[deleted]
- aramas 9y agoIt's generous to have all in royalty free license.
- bigon 9y agoAlso don't forget SELinux https://github.com/SELinuxProject/ https://github.com/SELinuxProject/ which is a project that comes from the NSA as well
- Cakez0r 9y agoSELinux is on the list :)
- forgottenacc57 9y agoWhy are people so welcoming to the filthy spies invading citizen privacy?
- zby 9y agoArmy is created to do arguably worse things than spies. There are people who completely reject the idea of military - but the bulk of society tend to accept it as a unavoidable and tries to control it and make it least evil possible. Some spying is probably unavoidable in the current world - and just like with the army we need to think how to control it and make it civilized. Getting on a high moral horse only makes the matters worse.
- ganoushoreilly 9y agoSide note *The Army/Navy/Marines/Af/and Coast Guard share employees with the NSA. As in, close to half the NSA employees are D.o.D Military.
- Tepix 9y agoSome of the are defending against other filthy spies.
- xythobuz 9y agoI really don't understand it, to be honest I think it's unbelievable. I'd say we, as in the IT community, shouldn't touch anything coming out of the NSA with a 10 feet pole, even if we're absolutely sure it's not some kind of morally dubious attack tool. Fuck the NSA!
- r3bl 9y agoFun sidenote: I was the very first civilian to contribute to their GitHub project back in July 2015, when SIMP was the only project they had up on GitHub. It was literally a one letter change in the README file, but I still have the privilege to call myself the very first civilian to contribute to the NSA's open source project: https://github.com/NationalSecurityAgency/SIMP/pull/1 https://github.com/NationalSecurityAgency/SIMP/pull/1
- jameskegel 9y agoI'd shake your hand
- 0xADADA 9y agogreat job collaborating with what is, in essence; the American version of the Stasi.
- sametmax 9y agoBut with much better pr.
- temp1245 9y agoFrom the Stasi's wikipedia page: "Numerous Stasi officials were prosecuted for their crimes after 1990. After German reunification, the surveillance files that the Stasi had maintained on millions of East Germans were laid open, so that any citizen could inspect their personal file on request; these files are now maintained by the Federal Commissioner for the Stasi Records." I wonder if that will ever happen in the US.
- dangerlibrary 9y agoThere's something .. out of proportion when equating fixing a capitalization error with "collaborating." Collaborating with the Stasi often meant compromising the safety of one's friends, family, and fellow citizens - to the tune of seeing them killed or cruelly imprisoned. Changing "Github" to "GitHub" in a text file isn't even close to the same scale, and using that language is pretty tone-deaf.
- 9y ago
- reiz 9y agoThat's nice to see the NSA is contributing to the OSS community. I just randomly picked one of the NSA GitHub repositories, analysed it with VersionEye (https://www.versioneye.com https://www.versioneye.com) and found already 25 security vulnerabilities. Who is the best person to contact in this case? Here is the security report: https://www.versioneye.com/user/projects/59479cd06725bd001230f152?child=summary#tab-security https://www.versioneye.com/user/projects/59479cd06725bd00123....
- 0xADADA 9y agoThey say it clearly themselves: > The government benefits from the open source community’s enhancements to the technology. They're hoping that by putting this code out there, unwitting dupes will then collaborate with them to contribute to the surveillance state.
- headmelted 9y agoFemto (https://github.com/femto-dev/femto https://github.com/femto-dev/femto) looks pretty interesting to me just based on some work I've needed to do in the past that it would've come in handy for. It looks like the last commit was over a year ago, though. Is there information I'm not seeing of whether these projects are actively maintained (or still in use at NSA?).
- nautilus12 9y agoIm also curious, without digging into it deeply is it something comparable to Solr or Elasticsearch? If so i wonder how it stacks up
- frogboglog 9y ago"THE TECHNOLOGIES LISTED BELOW were developed within the National Security Agency (NSA) " OK, moving along, is there some secure software somewhere in there?
- nautilus12 9y agoDoes the fact that many of these havent been updated in months or years mean that these are really old projects that effectively hold no value to the NSA and arent close to any of their core operations?
- kingbirdy 9y agoOr they've received updates that make them too important to release? But likely it's just that they haven't had any major updates, and NSA internal bugfixes aren't important enough to push out, or aren't given out due to worries that that would be a national security issue somehow
- angry_octet 9y agoFor every one of these projects someone spent a considerable effort do the paperwork to get it pushed out, have it signed off as sanitized, non-embarassing, etc. It is a lot of work to get that done in bureaucratic and risk-averse organisations. If there had been a community contributing back I expect that there would have been more activity, but if it seems like noone will, would you spend your time pushing out regular updates?
- thrillgore 9y agoIf they're looking for pull requests, they won't find any salvation in the OSS world.
- wfunction 9y agoCan someone explain how some of projects can be MIT-licensed (or anything-else-licensed) as they claim? Aren't they necessarily in the public domain given that they're works of the U.S. Government?
- dagw 9y agoCertain government agencies and subsidiaries are exempt from having their work considered "government work" and can thus claim copyright if they want. I'm guessing the NSA is such and agency. Also if the work was actually done by a contractor then there are other exemptions.
- wfunction 9y agoThanks, but I'm not sure that's it. For example, when I look at at [1], I see an apparent contradiction with [2]. It almost seems like they don't know what they're doing, but surely that's because I'm misunderstanding what's going on? [1] https://github.com/NationalSecurityAgency/DCP/blob/21c8d3efecd0ceb5fc38dfe8e2c3aa8011ed58cd/COPYING https://github.com/NationalSecurityAgency/DCP/blob/21c8d3efe... [2] https://github.com/NationalSecurityAgency/DCP/blob/496402fa92aa61acfbb871f6faa0988b16d1e2c1/LICENSE https://github.com/NationalSecurityAgency/DCP/blob/496402fa9...
- ganoushoreilly 9y agoIt could also be based upon patent rights, I know that employees get a 50% ownership of all patents, maybe that's part of it?
- ganoushoreilly 9y agoIt could also be based upon patent rights, I know that employees get a 50% ownership of all patents, maybe that's part of it?
- ginreaper 9y agoWell if they are forking or contributing to other software or any type of derivative work, they probably have to retain the original license by law
- api 9y agoOne of my favorites is the Speck cipher, which has been released before: https://en.wikipedia.org/wiki/Speck_(cipher) https://en.wikipedia.org/wiki/Speck_(cipher) I'd be very interested in more public cryptanalysis of this. It's a damn simple cipher to implement, and if it were at least as secure as say Salsa20/12 it'd be very nice for all kinds of applications.
- corpMaverick 9y agoThis is nice. It should all be about protecting electronic systems. To help individuals and companies build resilient systems. It protects the USA and the world economy as a whole. It should never be about spying people or even catching criminals IMHO.
- Cryptoholic 9y agoI wonder if all the people who are really suspicious of it in here realize that this (releasing their projects as OSS) has been a thing for a while. SELinux Accumulo (a popular NoSQL distributed key-value store) Apache NiFi (data processing system) etc.