11 ms·
Core Secrets: NSA Saboteurs in China and Germany
- xnull2guest 12y ago“The facts contained in this program constitute a combination of the greatest number of highly sensitive facts related to NSA/CSS’s overall cryptologic mission,” the briefing document states. “Unauthorized disclosure…will cause exceptionally grave damage to U.S. national security. The loss of this information could critically compromise highly sensitive cryptologic U.S. and foreign relationships, multi-year past and future NSA investments, and the ability to exploit foreign adversary cyberspace while protecting U.S. cyberspace.” Maybe they could have not published this one. I'm very much interested in the Snowden Documents and am a strong advocate for civil liberties (look at some of my other posts, and the ones under the handle 'xnull'). I also repeatedly explain, on Hacker News, and other places, that there is a global cyber intelligence war and that the Snowden Leaks showed us key insights into what was going on, how it's not 'about terrorism' and a great number of other things. But I'm bewildered by this article. It seems really damaging, and like it doesn't really add very much to the corpus they've already published. Any ideas? Edit: Glenn Greenwald, Laura Poitras, Edward Snowden, etc all decide what material to publish and what material not to publish. Greenwald, by his own admission, works with US officials to redact information and to choose which stories make it out of the gate. He's also said that he isn't revealing (paraphrasing) 'the most horrendous material in the Snowden documents, for fear of the fallout'. My question should not be thought of a challenge to revealing Snowden documents as a whole. Contrary to this I think it is of the very highest service. My question is only 'why this document'?
- rainbowvac 12y agoWhat happened to the ideals of transparency? Was that given up along the way to an enterprise sized government?
- lawnchair_larry 12y agoDid you read it all? It talks about the NSA infiltrating companies and backdooring encryption. It's important to publish this.
- xnull2guest 12y agoYup. Plenty of leaks before on infiltrating companies and backdooring encryption. Was there anything in particular? Edit: Nothing in particular then I guess... :(
- nintendo1889 12y agoI wonder if they're subverting open source encryption software.
- xnull2guest 12y agoMost certainly 100% yes. Here's a pretty swell talk on some of the programs they use to do it. http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sunday/NSA_operation_ORCHESTRA_Annual_Status_Report.webm http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sund...
- nintendo1889 12y agoFascinating. I'm off to create a few phony shell corporations to get some free NSA money and get paid to surf the web!
- xnull2guest 12y agoHahahha. Had the same thought.
- nyolfen 12y agothe really excellent part of this presentation is that he calls attention to the exceptionally poor nature of openssl's code months before heartbleed
- Estragon 12y agoWhat happened in the jump cut at 44m50s?
- zwegner 12y ago
- rainwolf 12y agoIt is really damaging, but that's from a perspective that, as a superpower, they were benefiting from control and domination. The same perspective implies that the target was being damaged by these actions. Targets that are not always adversaries. Targets that could contribute if not being controlled, dominated, and damaged. It's not easy to see, but damaging others denies them the contributions they could bring, ultimately damaging themselves.
- xnull2guest 12y agoAre you saying it's retribution for participating in the global cyber intelligence war? Everybody is hacking everybody. Every major country has a cyberintelligence arm. The NSA is just one actor of dozens.
- meowface 12y agoI actually condone a lot of the NSA's activities, but I take serious issue with: -Warantless surveillance of US citizens (this is bad whether it's by law enforcement, intelligence agencies, or anyone). -Infiltration of foreign companies in allied or neutral nations purely for economic or geopolitical insight, not for military purposes (Brazil's Petrobras oil company, all sorts of spying in Germany and Norway and other places). Personally I'm all for the kind of operations they're conducting in Iran and China, as these countries have been doing the same to us and to others for a long time. But they've become far too greedy in their desire for information domination and power, to the point where there is clearly no line that shouldn't be crossed. To them, if anything anywhere in the world is open for exploitation or surveillance, then they feel like they have a right to use it.
- xnull2guest 12y ago> Warantless surveillance of US citizens (this is bad whether it's by law enforcement, intelligence agencies, or anyone). Agreed very strongly. > Infiltration of foreign companies in allied or neutral nations purely for economic or geopolitical insight, not for military purposes (Brazil's Petrobras oil company, all sorts of spying in Germany and Norway and other places). See this is where the NSA really shines. We (The US) delayed Iran's nuclear program by THREE YEARS with Stuxnet! Three! And after they finally figured out it was sabotage the US and Israel had the director assassinated for further delays. Having Merkle's cell phone? During the Eurozone crisis? It would have been awful (financially) for the United States not to have that information. It's fun to look back and read the confused reports during the time "European Union suffering considerably from Eurozone crisis; America sees only limited effects." PETROBRAS? We won offshore oil drilling locations because we had that information. Energy security for the country going forward decades. Unfortunately geopolitics are important and you can't just not participate. Hacking is (one important way) that modern espionage, surveillance and sabotage are done.
- fiatmoney 12y agoBecause of this. It's likely the NSA is actively subverting American companies. "The most controversial revelation in Sentry Eagle might be a fleeting reference to the NSA infiltrating clandestine agents into “commercial entities.” The briefing document states that among Sentry Eagle’s most closely guarded components are “facts related to NSA personnel (under cover), operational meetings, specific operations, specific technology, specific locations and covert communications related to SIGINT enabling with specific commercial entities (A/B/C).” It is not clear whether these “commercial entities” are American or foreign or both. Generally the placeholder “(A/B/C)” is used in the briefing document to refer to American companies, though on one occasion it refers to both American and foreign companies. Foreign companies are referred to with the placeholder “(M/N/O).” The NSA refused to provide any clarification to The Intercept."
- xnull2guest 12y agoRight. But that's not new information. Prior Snowden leaks (and leaks by others) have showed conclusively that the NSA targets and infiltrates American corporations and also partners heavily with them.
- meowface 12y agoThis article seems a bit speculative. They don't seem to know for sure that "(A/B/C)" means American companies in this case. Everything else just seems like commentary from themselves and other security experts. As for foreign companies, it's pretty obvious that NSA and CIA have been conducting operations like these for many decades. I'm not going to argue that the NSA has not subverted American companies before (see DUAL_EC_DRBG), but this does not provide definitive proof that they're actively infiltrating homeland companies with human spies.
- xnull2guest 12y agoIt's not all that speculative - it agrees what was in prior leaks that claim that American companies are routinely infiltrated. Also remember that the authors of these articles have read huge volumes of Snowden documents have have not been publicly released and that the security experts (likely referencing Schneier here) are not just guys working in private industry. If you work in the security space you very quickly begin to interoperate with past- and current- military and government personnel. Schneier testifies as an expert witness on these things before congress and Greenwald is an ex-Constitutional lawyer. In short they have the pedigree to make these assertions. For the record I don't agree with the parent. I think the important thing about this document is that it lays out the broad tactical tools used in US cyberintelligence strategy. It's handing off some major tactical playbook material.
- acqq 12y agoYou summarized already in your sentences ("I'm bewildered by this article. It seems really damaging, and like it doesn't really add very much to the corpus they've already published") how you feel and why you feel that way: it appears damaging because it contains the paragraphs that explicitly contain the words "it's damaging." But it's just a general introduction to the "juicy bits" without the bits themselves. In fact you recognized this too writing: "it doesn't really add very much to the corpus they've already published." Once you attempt to identify the new information, you can recognize that 99.5% of it appeared in some other form before. The older published documents already were marked "top secret." This markings are given to the content that is considered "damaging" by these who write the documents. You just percieved it differently because these markings were just markings for you, not the sentences spelling out "damaging." Still, the value to the public of this very document is that it's a single document summarizing nicely the previously disclosed ones in much less words. By its nature though it doesn't contain the details published previously. (Edit: technically, it's a set of the documents but all of them together appear to me just as a big table of contents for the disclosures already published.) Now let's discuss the new 0.5% of information, even if it's very general.
- xnull2guest 12y agoTo clarify I mean that I don't believe it adds much to the corpus of information about domestic and civil rights infractions. On the other hand it deals a pretty big blow geopolitically/internationally. The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. Edit: Right now HN is limiting the number of replies I can initiate. Will reply as I can.
- acqq 12y ago> The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. It does? What is actually new and specific I fail to see. But it's a really, really nice summary.
- 12y ago
- aburan28 12y agoThere is nothing damaging in these latest documents. The documents reference programs that if revealed (which they were not) would be extremely harmful to national security.
- Perseids 12y ago> global cyber intelligence war I'm really starting to take an issue with declaring all this stuff as "cyber war" or "cyber warfare" (here and everywhere else in this thread). It's not a war if there is no intend of actually killing people. Even something as intense as the "cold war", had the qualifier cold in it, because there was no open confrontation. And what is now summarized as cyber (intelligence) warfare is orders of magnitude less deadly (though not necessarily less damaging to our civil rights). It's not a war if I steal your trade secrets and undermine your negotiation positions in international treaties. If you frame it as a "war" you get a whole different solution space. Instead of strengthening the IT security of domestic companies that build your core infrastructure you end up with "offense is the best defense" strategies and undermine the IT security of everyone. If you stop using war rhetoric this kind of statement: > If you didn't see it, there's a link on another branch of the conversation containing (at least) 37 other countries involved in cyber [espionage]. becomes far less of an existential threat.
- xnull2guest 12y ago> I'm really starting to take an issue with declaring all this stuff as "cyber war" or "cyber warfare" (here and everywhere else in this thread). It's not a war if there is no intend of actually killing people. Countries are owning each others' communications, power, transportation, energy, food production, etc infrastructure. Sabotaging these can cripple a nation, not to mention kill people (check out damage from the recent Great Northeast Blackout - note here that it is not known whether this was a cyber attack). The military and defense contractors are targets of attacks as well as industry. Titan Rain, Moonlight Maze and Operation Aurora are some well know geopolitically motivated attacks that breached defense contractors (includingLockheed Martin, Sandia), US internet infrastructure (including Rackspace, Google), aerospace (including NASA) and military (including the DoD). You may remember this year that Wall Street and JP Morgan was hacked, that the DoD was hacked, that several hundred defense contractors were hacked, and that the list of people with top secret clearance was hacked. You may remember this year that Israel's "Iron Dome" missile defense system schematics were hacked. In the eyes of the military, these things constitute an attack. They give it the name warfare. It certainly isn't classical warfare. Maybe we need a new term. I do like the "cold" term. No matter what we call it, it is serious. As a country we are invested in it. http://www.washingtonpost.com/wp-srv/special/national/black-budget/ http://www.washingtonpost.com/wp-srv/special/national/black-...
- revelation 12y agoCome on, it's been 13 years now of this "grave damage to national security" talk. They claim it for everything. I'm reasonably sure every thinking person has started, in their mind, to replace any invocation of "national security" with "covering up either incompetence, negligence or breaches of law". Theres zero reasons we should be paying any attention to that label. (I like to remind people of the case of Ibrahim vs. DHS, where the government spent all its time invoking various secrets related laws and privileges, citing national security, even having Holder sign a declaration to that purpose, and what for? To cover up the clerical error of some lowly FBI agent, who checked a wrong box.)
- xnull2guest 12y agoThe "grave damage to national security" wasn't something an official said. It was a warning inside the document. Certainly there are instances where this is the case. I can think of a few others to add to your example. But there's no good reason to assume that all invocations of classified and politically or strategically sensitive material are excuses to cover up incompetence, negligence or breaches of law. And in fact in this case I'm not sure what it would be covering up. What's listed here is hardly incompetence nor negligence and the argument for breach of law, while slightly stronger, wouldn't pass a smell test.
- stfu 12y agoSomewhat sad to see the cyber security war narrative becoming the top voted comment on hackernews. Until the public realize that they are themselves the target of those cyber security war activities by their own government, those revelations can not be damaging enough. Just to support the point: Today the new Snowden movie is all over the news, while practically nobody seems to care bout those revelations you claim being really damaging.
- xnull2guest 12y ago> Until the public realize that they are themselves the target of those cyber security war activities by their own government, those revelations can not be damaging enough This is entirely true. Us plebes have been caught in the middle. And the surveillance programs are not just about cyber warfare. The NSA/DHS use them for other things as well (handing off to CIA/FBI/DEA, building profiles of people, social manipulation, etc). But this article from firstlook IS about cyber warfare. The leaked document itself says "U.S. Strategic Command - Joint Function Component Command - Network Warfare". > Today the new Snowden movie is all over the news, while practically nobody seems to care bout those revelations you claim being really damaging Isn't that argumentum ad populum? The news media coverage of the Snowden revelations has been horrendous, limited and misleading through and through. In fact the Snowden movie being in the news is a great example of how the public is disconnected with what's going on. It's not a "Snowden documentary" or a "Snowden lecture" or a "Snowden document analysis". It's a short hour and change person story with a bleached narrative devoid of the content of the actual documents.
- coldtea 12y ago>But I'm bewildered by this article. It seems really damaging, and like it doesn't really add very much to the corpus they've already published. Really damaging for whom? 99% of the worlds population are victims (them or their countries) to the stuff described in the article, not cheering for its continuation.
- eyeareque 12y agoI read the entire article with the hopes that company names would be mentioned. Let's see who took cash to weaken encryption. Let's see who helped the government create back doors. That would have made this article stand out. But alas it contained more of the same things we already knew or assumed was going on. Here's hoping for next time.
- MichaelGG 12y agoWhy even let the companies know? The NSA should just have very talented people working for those companies. It's not far fetched to think they'd find a great candidate that's patriotic, and help their career any way possible (perhaps even sabotage other employees, if needed). I'd imagine other governments would do the same thing, too. Looking on a decade+ timeframe, it shouldn't be hard to get a few people into key positions. Companies would have to really try hard to avoid this type of compromise. For instance, run multiple, independent build labs, with multiple people comparing outputs. And then, an engineer or pair of engineers in collusion could probably easily slip a difficult to notice security bug into some code somewhere.
- xnull2guest 12y agoAll large corporations weaken encryption for the government. Some articles. If you want more, I'm sure I can dig up a few. https://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://en.wikipedia.org/wiki/Communications_Assistance_for_... http://www.foia.cia.gov/sites/default/files/DOC_0006231614.pdf http://www.foia.cia.gov/sites/default/files/DOC_0006231614.p...
- declan 12y ago> All large corporations weaken encryption for the government This is simply false. It is untrue to claim that all U.S. companies have somehow "weakened" encryption or inserted backdoors in their products for the Feds. I normally wouldn't waste my time correcting conspiracy theories, but sometimes it's necessary to stop the more credulous from believing them. Yes, the NSA has boasted of having a surveillance "partnership" with certain U.S. companies, but those are telecommunications carriers -- AT&T, Verizon, Sprint, etc., not Silicon Valley firms: http://www.cnet.com/news/surveillance-partnership-between-ns.. http://www.cnet.com/news/surveillance-partnership-between-ns.... For an additional indictment of AT&T, look at the sworn affidavit that EFF obtained from local SF bay area whistleblower Mark Klein -- an AT&T technician who revealed the existence of the NSA's fiber taps at the 2nd & Folsom Street SF facility. But the Silicon Valley companies that we know and more-or-less love have done the opposite. Look at the announcements about device encryption by Google and Apple in the last month (that have irked the Feds so much they're threatening new laws). Look at Google's Adam Langley, Wan-Teh Chang, Ben Laurie, and Elie Bursztein deploying a better TLS cipher suite in Chrome. Look at Twitter's surveillance lawsuit this week against the Feds over, apparently, the legality of a warrant canary. And of course the two links in the conspiracy theory posted above prove the opposite of the "weaken encryption" claim. First, CALEA doesn't apply to web companies. And even the carriers it does apply to are permitted to (at 47 USC 1002(b)(3)) provide secure end-to-end encryption: "A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication." Second, the FOIA'd doc was written in the late 1990s before the Feds liberalized encryption export controls. It's 15+ years out of date. You can now freely export strong crypto. And even in the dark days of the 1990s, there were no domestic controls on encryption use, though the TLAs did give it a shot at one point. A better argument for the conspiracy theory set is the very odd relationship between EMC Corporation's RSA business unit and NSA. But even if allegations of intentional security flaws are true, EMC is a Massachusetts company, not a left coast firm, and a cozy relationship between the NSA and EMC/AT&T/VZ/etc. certainly does not indict all companies and their founders.
- deleted 12y ago[deleted]
- illumen 12y agoTLDR; Secret police do secret police things.
- pluma 12y agoMore like: the US can't get rid of its Cold War era habits. The Cold War never ended. It was just extended from US vs the Soviet Union to US vs everybody else. But what do you expect from a nation that is now de facto in a perpetual state of war with an amorphous, heterogeneous and strictly confidential blob of groups, nations and assorted individuals that includes its own citizens.
- deleted 12y ago[deleted]
- rl3 12y agoThe document titled "ECI Compartments" is interesting: * It's possible work out the geographic region of certain compartments based on the organizational code attached to it. * The redactions in the "Control Authority" column are variable size, possibly even proportionate to character length. * The fact that document was merely classified "confidential" is odd. * I was able to identify[0][1] all but one item listed in the "Organization" column. The sole item that eluded identification was "S0242". It is listed alone under two compartments. I couldn't find anything on it; one can only surmise it is something within the Signals Intelligence Directorate (probably something boring, despite the mystique). [0] http://en.wikipedia.org/wiki/National_Security_Agency#Structure http://en.wikipedia.org/wiki/National_Security_Agency#Struct... [1] http://www.matthewaid.com/post/58339598875/organizational-structure-of-the-national-security http://www.matthewaid.com/post/58339598875/organizational-st...
- acqq 12y agoWhat could "NSA/CSS Commercial Solutions Center (NCSC)" (from [1]) actually do? They write on their public web page: https://www.nsa.gov/business/programs/ncsc.shtml https://www.nsa.gov/business/programs/ncsc.shtml "The NSA/CSS Commercial Solutions Center (NCSC) addresses the strategic needs of NSA/CSS and the national security community by harnessing the power of U.S. commercial technology."
- EthanHeilman 12y agoTwo pieces of information that add up to a larger story: * The NSA/CSS Commercial Solutions Center (NCSC) is specifically built around Elliptic Curve Cryptography that they acquired from Certicom. >The NCSC also manages the Elliptic Curve Cryptography (ECC) program on behalf of the NSA/CSS. Elliptic curve provides greater security and more efficient performance than first generation public key techniques currently in use. NSA/CSS purchased a license that covers intellectual property in a restricted field of use to assist in the implementation of elliptic curves to protect U.S. and allied government information. - https://www.nsa.gov/business/programs/ncsc.shtml https://www.nsa.gov/business/programs/ncsc.shtml * Certicom designed the Elliptic Curve DRBG (Dual_EC) algorithm including the backdoor (Certicom patented the backdoor functionality in 2005)[0]. The NSA then included this algorithm + backdoor into NIST standard and payed RSA 10 million dollars to make it the default DRBG. Putting these two facts together suggests that the NCSC was responsible for the Dual_EC backdoor. [0]: http://en.wikipedia.org/wiki/Dual_EC_DRBG http://en.wikipedia.org/wiki/Dual_EC_DRBG
- curiously 12y agoI wonder what's in the tip of the pyramid, shaded in black. Somethings I like to imagine: - Kennedy was assassinated by CIA - Aliens transferred technology to US government - Former strongman of South Korea was assassinated by CIA - List of other assassinations by CIA - Iraq WMD was made up and knew about it but went ahead with war anyway. etc...
- WorldWideWayne 12y agoYou're not allowed to be imaginative or speculate here about topics that people have been conditioned to patriotically think non-critically about! Just give it up man! We all know that the official stories about 9/11 are 100% true! (For a group that hates censorship as much as these "hackers" do, isn't it funny how they love a site that lets everybody censor each other by downvoting comments into invisibility? See? Help meeee I'm meltinggggg....)
- dandelany 12y agoWhen you speak in front of a crowd of people and are arrested by police for the things you're saying, that's censorship. When the crowd boos you off the stage before you're finished, that's not censorship, it's other people also asserting their rights to free speech. Perhaps you should reconsider what you're saying or find a new group of people to say it to.
- WorldWideWayne 12y agoYour analogy doesn't work because 3 or 4 downvoters does not constitute a crowd. No, this is basically censorship by a small set of group-think leaders. Thanks for the unsolicited advice though!
- curiously 12y agodon't worry I got another account with lot of karma, gonna go for a coffee and you will feel my wrath.
- philip1209 12y agoI don't see any reference to domestic surveillance, so my interpretation is that a spy agency is spying.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- aburan28 12y agoThe NSA has clearly recruited employees from companies like Google, Facebook, Cisco, etc to compromise and place vulnerabilities that the NSA can exploit. The fact that the NSA has decided that the legal channels to acquire data through warrants and actual investigations no longer applies must be stopped.
- BugBrother 12y agoWhat surprise me about these recruitments is -- how do you convince people that it really is NSA/CIA/whatever that are asking them to be patriotic? E.g. a Chinese spy in Silicon Valley probably say "I represent NSA, we _really_ need to get access to mail accounts without letting anyone know, including your corporate CEOs" (except to people which would be open to nationalist Chinese arguments). A visit to Pentagon to shake some well known general's hand might be hard to arrange, since not only Google or Apple might monitor the GPS of the employees phone.
- MichaelGG 12y agoAs an example, I have a small VoIP company. At one point, we were processing about a billion calls a week. A malicious employee could probably setup a trace and collect call records or record calls. I'd have no real defense against hiring someone that worked for the NSA. An employee at a hosting company could do huge amounts of damage. Consider SSL certs can be issued just by checking email to prove "ownership". At some large ISPs/datacenters, it'd be "fairly easy" to intercept the confirmation email and get SSL issued in a company's name "legitimately" (that is, no bad effects to the CA and not traceable to the NSA). Subverted employees is a huge threat and we should really consider that when looking at security in general.
- angry_octet 12y agoHey BugBrother, I don't know who is downvoting all your comments, but they seem within scope and inoffensive to me, so don't let the cowardly phibjobblers get to you.
- t-rex1 12y agoRevealing mass surveillance is one thing (great!), but some of these leaks feels like revealing too much and some of whats meant to be protecting us...no??
- icantthinkofone 12y agoI can't find any article titled "Chinese and German Saboteurs in America". Why?
- duckery 12y agoThank God we are clustered with Germany and South Korea in this. I can only imagine the not-giving-a-fuckery if the targets were "China, Iran and Cuba"
- bmh100 12y agoIt is unfortunate the shadowing did not also go to homework and extra curricular activities. This is an area that is neglected too. If he had sat through a practice, then gone home to read 200 pages and do two hours of homework, his conclusions would be even more dramatic.
- chj 12y agoNot surprised. Good thing is we don't have to hear US gov criticizing other countries any more.