Showing posts with label Surveillance. Show all posts
Showing posts with label Surveillance. Show all posts

Monday, November 10, 2014

How the FBI Hacks Criminal Suspects

How the FBI Hacks Criminal Suspects

Agence France-Presse/Getty Images

By Jennifer Valentino-DeVries and Danny Yadron

When federal law-enforcement officials can’t track criminal suspects through traditional wiretaps, they turn to tools most commonly associated with hackers: software exploits.

An article in The Wall Street Journal reveals some of the techniques the Federal Bureau of Investigation uses for such surveillance, including delivering spyware to suspects’ computers through emails and Web links. Former U.S. officials say that use of such tools under court orders has grown as more suspects “go dark” by using encrypted and other sophisticated new digital communications technology.

To get such spyware running on a suspect’s machine, investigators often must use tools that exploit holes in the software already on the computer or phone. Through these holes, known as vulnerabilities, investigators are able to get their own programs to run on the machine. To be effective, the spyware must then be stable, run undetected and reliably send information back to law enforcement.

Former U.S. officials said the FBI employs people who are able to make such tools, and it also buys the technology from private companies. In recent years, several firms have begun selling the technology to law enforcement.

A spokeswoman for the FBI declined to comment.

In some cases, federal law enforcement has had contracts and subcontracts with U.S. companies to develop specific computer exploits, said one person familiar with the process. “They hand out a target list and you try to find something,” that person said. “It starts with stuff that lots of people have, like Safari on Mac, then works down into a bunch of weird and very specific software packages.”

As of several years ago, a reliable Safari Web browser exploit could fetch at least $50,000 and sometimes as much as $100,000, the person said. Exploits for Internet Explorer might bring in more, while those for less popular software might cost about $10,000, that person said.

“It’s not a trivial amount of labor,” the person said. “You’re looking at 100 to 200 hours of work to find” an exploit in popular software.

The person said the process when working with law-enforcement agencies is slightly different from the one used by military agencies, mainly because law-enforcement requests are sometimes designed for specific cases. “Some of the software requests were absurd unless you had a specific target in mind,” the person said.

In posts on resume sites, people from other private companies discuss similar work, including working with FBI field agents on “penetration software” and making surveillance tools that were “case specific.”

The Journal article also describes how a firm called Gamma International offers “0 day exploits”—meaning that the software maker doesn’t yet know about the security hole—for software including Microsoft Corp.’s Internet Explorer. Gamma has marketed its products within the U.S., but didn’t respond to requests for comment.

Christopher Soghoian, principal technologist at the American Civil Liberties Union, said he is concerned about the government “sitting on” computer exploits rather than helping companies fix the problems and protect people. The same hacking tools that law enforcement uses in investigations could also be employed by criminal hackers, he said.

Other computer-security researchers say the use of such hacking tools is preferable to rules that would require companies to put so-called back doors into software to easily enable wiretaps. Law-enforcement agencies have been seeking changes to the law to mandate wiretap capabilities in more Internet technologies.

Such back doors “become one-stop-shopping for criminals and foreign intelligence services, not just the FBI,” said Matt Blaze, a computer science professor at the University of Pennsylvania. But if law enforcement has to hack into a suspect’s machine to get information, it “doesn’t put the rest of the network at risk,” he said.

Saturday, November 30, 2013

WTF is the Internet of Things and how it will be used against you

WTF is the Internet of Things and how insurers will use it against you

November 27th 2013

The humbling sensation of having your stupidity monitored

Sysadmin Blog What is "the internet of things" and why should we care? Put simply, the internet of things is a catch-all term for ultra-low-power embedded devices that mostly consist of sensors and control systems.

This market segment is expanding rapidly; devices falling into this category will soon outnumber all other types of computers on the planet, if they don't already. The internet of things also signals new threats to personal privacy.

The widgetry

Devices that make up the internet of things are typically those which require minimal – or no – human interaction. Many of these are already in homes: they range from network addressable lightbulbs to the bleeding-edge biosensors and medical equipment that enable body hacking aka "the quantified self".

Despite Intel's belated recognition of its own utter irrelevance in this space, it isn't a credible player. When we talk about the widgets powering the internet of things, we are talking almost exclusively about specialty ARM chips, the lower power the better.

Most devices that fall into the internet of things category don't need any real processing power, just enough guts to poll a sensor of some variety, wake up an ultra-low-power radio, fire off its findings and go back to sleep.

The overwhelming majority of first-wave internet of things devices will be dumb network-connected sensors providing raw data. The number-crunching and analysis will occur elsewhere.

You'll notice I said "ultra-low-power" a lot. That's because the power goal behind most internet of things devices is usually something seemingly absurd, like a Bluetooth device that can run for two years off a watch battery or ambient backscatter (PDF) devices that use so little power they can sustain themselves on the kinds of radio energy put out by everything from television stations to your home Wi-Fi.

There are a multitude of low-power wireless technologies. There is also research going on into passive data dispersion devices; think of small sensors with dynamic RFID tags that your smartphone could gather information from as you walk by and you're on the right track.

These are the kinds of technologies upon which the internet of things is built. Naturally, more complicated automated computing devices will take more power. As such, the internet of things can stretch from a tiny infrequently changing dynamic RFID sensor sipping photons on a shelf to a massively complex, juice-guzzling industrial control unit keeping a nuclear power plant ticking along. The term is rather broad.

Why do we want the internet of things?

Many of the "sensory and control" possibilities unlocked by internet of things technologies are pretty self-explanatory. Retrofitting an existing building with traditional centralised automation technologies aimed at lighting or HVAC is expensive.

It also tends not to be particularly granular; at best you're getting the ability to turn on or off everything you could have controlled with the light switch, in some cases you're limited to the breaker box.

The internet of things approach would be to bypass all that hullabaloo and simply install wireless light bulbs. These could be added as existing bulbs fail and each new bulb added gives your system individual control of that bulb.

Add some sensors and you can have the lights in your home turn on and off when they sense you (via cell phone, implant, watch, etc) enter or leave the room. In commercial or industrial buildings you could preprogram lighting cycles, typically augmented by sensors looking for movement or the presence of an employee cell phone.

Alternatively, you could use it to play video games on buildings, though youmay want to get permission first.

I'm wiring up my fish tank to the internet. The newest incarnation will automatically top itself up when the water gets low, feed the fish and other mundane tasks. I am working on sensors for PH, conductivity, and even a spectrometer so I can test for ammonia, nitrate, nitrite and phosphate levels.


Quantify and automate: this fish tank will be assimilated --

Deviances in any of these parameters can tell me ahead of time of there are problems, allowing me to proactively solve environmental issues for my fish. This is a big change over what was possible even five years ago. Test strips and chemical tests were time-intensive and subject to human fallibility; many aquarists simply had to wait until fish got sick to know something was wrong, by then it was often too late.

The humbling sensation of having your stupidity monitored

IoT as the insurers' don't-be-stoopid enforcer

It's not all roses. Consider the humble smoke detector. People are reinventing it, this time with extra internet.

While that could be great for me, how long do you think it will be before the cost of home insurance will depend on my purchasing, properly maintaining and configuring several of these devices to report back to the insurance company? In a single family home that's a minor annoyance to have to do. In a multi-unit dwelling there's a case to be made that their use be mandated by law.

What about other sensors? How warm do you keep your home? Based on your heating usage and the statistics on your house have you failed to invest in the proper insulation and eco-friendly upgrades? The value of a home could depend on such things; I know that for my next house purchase I'll be using a whole bunch of cheap sensors to determine the value of any house I fancy.

Wouldn't the bank that holds my mortgage or the company that insures it have a financial interest in real-time monitoring as well?

Go deeper. Did you leave the stove on and the leave the house? Did you usethe wrong kind of toilet paper the last time you used the washroom, or flush grease, paint or other no-nos down the drain?

If your insurance company could prove these were the factors that led to related claims they would not have to cover it. Your utilities provider or local fire hall might have an interest in monitoring as well. In many cases, this sort of monitoring could be added to the utilities-owned infrastructure where it meets your house, thus not requiring your cooperation at all.

Today, internet of things technologies can be used to help prove qualification for fitness tax credits. It is not inconceivable that one day they might be required in order to qualify.

The merging of the physical and the virtual worlds offers the carrot of increased efficiency, safety, and gentle reminders for those things we've forgotten. The internet of things brings with it ethical issues with which legislators are already struggling.

It is also the future of IT. "Wearable computing" is far more likely to manifest as a subset of the internet of things than be "yet another general computing platform". Innovation in mobile computing is levelling off, so growth stagnation can't be too far behind.

The bulk of new IT jobs – the IT practised by our successors – will be managing, maintaining and developing the internet of things. So what do you want to monitor today?


FBI Spooks Use Malware to Spy on Android Devices

FBI spooks use MALWARE to spy on suspects' Android mobes - report

August 2nd 2013

Magic Quadrant for Enterprise Backup/Recovery

The Federal Bureau of Investigation is using mobile malware to infect, and control, suspects' Android handsets, allowing it to record nearby sounds and copy data without physical access to the devices.

That's according to "former officers" interviewed by the Wall Street Journal ahead of privacy advocate Christopher Soghoian's presentation at hacker-conflab Black Hat later today.

The FBI's Remote Operations Unit has been listening in to desktop computers for years,explains the paper, but mobile phones are a relatively new target.

It would never work with tech-savvy suspects, though: suspects still need to infect themselves with the malware by clicking a dodgy link or opening the wrong attachment. This is why computer hackers are never targeted this way – they might notice and publicise the technique, said the "former officers", who noted that in other cases it had proved hugely valuable.

Such actions do require judicial oversight, but if one is recording activities rather than communications, the level of authorisation needed is much reduced. A US judge is apparently more likely to approve reaching out electronically into a suspect's hardware than a traditional wiretap, as the latter is considered a greater intrusion into their privacy.

Gaining control of that hardware still requires a hole to crawl through; ideally a zero-day exploit of which the platform manufacturer is unaware.

The WSJ cites UK-based lawful spook spyware supplier Gamma International as selling such exploits to the Feds. The company was recently in the news after allegations that it was also supplying dodgy governments with kit - allegedly including malware disguised as the Firefox browser.

Given the convergence of mobile and desktop, it's no surprise to see desktop techniques being applied to mobile phone platforms by both hackers and law enforcement agencies.

The usual techniques of not opening unknown attachments or unsigned downloads should protect you against the FBI, just as it would against any spear-phishing attempt. But then again, if you know that, they probably wouldn't try using it against you. ®

The Spy Files

The Spy Files

 | Dec 1st 2011

WikiLeaks: The Spy Files

Mass interception of entire populations is not only a reality, it is a secret new industry spanning 25 countries

It sounds like something out of Hollywood, but as of today, mass interception systems, built by Western intelligence contractors, including for ’political opponents’ are a reality. Today WikiLeaks began releasing a database of hundreds of documents from as many as 160 intelligence contractors in the mass surveillance industry. Working with Bugged Planet and Privacy International, as well as media organizations form six countries – ARD in Germany, The Bureau of Investigative Journalism in the UK, The Hindu in India, L’Espresso in Italy, OWNI in France and the Washington Post in the U.S. Wikileaks is shining a light on this secret industry that has boomed since September 11, 2001 and is worth billions of dollars per year. WikiLeaks has released 287 documents today, but the Spy Files project is ongoing and further information will be released this week and into next year.

International surveillance companies are based in the more technologically sophisticated countries, and they sell their technology on to every country of the world. This industry is, in practice, unregulated. Intelligence agencies, military forces and police authorities are able to silently, and on mass, and secretly intercept calls and take over computers without the help or knowledge of the telecommunication providers. Users’ physical location can be tracked if they are carrying a mobile phone, even if it is only on stand by.

But the WikiLeaks Spy Files are more than just about ’good Western countries’ exporting to ’bad developing world countries’. Western companies are also selling a vast range of mass surveillance equipment to Western intelligence agencies. In traditional spy stories, intelligence agencies like MI5 bug the phone of one or two people of interest. In the last ten years systems for indiscriminate, mass surveillance have become the norm. Intelligence companies such as VASTech secretly sell equipment to permanently record the phone calls of entire nations. Others record the location of every mobile phone in a city, down to 50 meters. Systems to infect every Facebook user, or smart-phone owner of an entire population group are on the intelligence market.

Selling Surveillance to Dictators

When citizens overthrew the dictatorships in Egypt and Libya this year, they uncovered listening rooms where devices from Gamma corporation of the UK, Amesys of France, VASTech of South Africa and ZTE Corp of China monitored their every move online and on the phone.

Surveillance companies like SS8 in the U.S., Hacking Team in Italy and Vupen in France manufacture viruses (Trojans) that hijack individual computers and phones (including iPhones, Blackberries and Androids), take over the device, record its every use, movement, and even the sights and sounds of the room it is in. Other companies like Phoenexia in the Czech Republic collaborate with the military to create speech analysis tools. They identify individuals by gender, age and stress levels and track them based on ‘voiceprints’. Blue Coat in the U.S. and Ipoque in Germany sell tools to governments in countries like China and Iran to prevent dissidents from organizing online.

Trovicor, previously a subsidiary of Nokia Siemens Networks, supplied the Bahraini government with interception technologies that tracked human rights activist Abdul Ghani Al Khanjar. He was shown details of personal mobile phone conversations from before he was interrogated and beaten in the winter of 2010-2011.

How Mass Surveillance Contractors Share Your Data with the State

In January 2011, the National Security Agency broke ground on a $1.5 billion facility in the Utah desert that is designed to store terabytes of domestic and foreign intelligence data forever and process it for years to come.

Telecommunication companies are forthcoming when it comes to disclosing client information to the authorities - no matter the country. Headlines during August’s unrest in the UK exposed how Research in Motion (RIM), makers of the Blackberry, offered to help the government identify their clients. RIM has been in similar negotiations to share BlackBerry Messenger data with the governments of India, Lebanon, Saudi Arabia, and the United Arab Emirates.

Weaponizing Data Kills Innocent People

There are commercial firms that now sell special software that analyze this data and turn it into powerful tools that can be used by military and intelligence agencies.

For example, in military bases across the U.S., Air Force pilots use a video link and joystick to fly Predator drones to conduct surveillance over the Middle East and Central Asia. This data is available to Central Intelligence Agency officials who use it to fire Hellfire missiles on targets.

The CIA officials have bought software that allows them to match phone signals and voice prints instantly and pinpoint the specific identity and location of individuals. Intelligence Integration Systems, Inc., based in Massachusetts - sells a “location-based analytics” software called Geospatial Toolkit for this purpose. Another Massachusetts company named Netezza, which bought a copy of the software, allegedly reverse engineered the code and sold a hacked version to the Central Intelligence Agency for use in remotely piloted drone aircraft.

IISI, which says that the software could be wrong by a distance of up to 40 feet, sued Netezza to prevent the use of this software. Company founder Rich Zimmerman stated in court that his “reaction was one of stun, amazement that they (CIA) want to kill people with my software that doesn’t work."

Orwell’s World

Across the world, mass surveillance contractors are helping intelligence agencies spy on individuals and ‘communities of interest’ on an industrial scale.

The Wikileaks Spy Files reveal the details of which companies are making billions selling sophisticated tracking tools to government buyers, flouting export rules, and turning a blind eye to dictatorial regimes that abuse human rights.

How to use the Spy Files

To search inside those files, click one of the link on the left pane of this page, to get the list of documents by type, company date or tag.

To search all these companies on a world map use the following tool from Owni

The Government Is Spying On You Through Your iPhone

Wikileaks: The Government Is Spying On You Through Your iPhone

December 2nd 2011

Your iPhone could be spying on you, according to the latest trove of documents from Wikileaks, which looks like it could be the biggest scandal yet.

Called the Spyfiles, it’s a trove of documents about the “mass interception industry” — the massive post-9/11 surveillance community that electronically snoops on entire populations.

The industry is selling software to government agencies — some of it delivered by Trojans — that can take over your iPhone. It can track its every use, follow your movements (even in standby), recognize your voice, record conversations, and even capture video and audio from the room it is in.

It’s not just limited to iPhones, of course. There are various spyware packages that run on PCs, Android and Blackberry. The uses are mind-boggling. The CIA, for example, is using phone-tracking software to target drone strikes in the Middle East and Central Asia. It recognizes the subject by their voice print, but the actual targeting isn’t terribly accurate.

One of the most sophisticated spying packages — The FinFisher program, produced by the British company, Gamma International — is delivered via a phony iTunes update. The Wall Street Journal hasmore details on the FinFisher spyware, which is sold to police and government agencies. (Der Speigel has a fascinating article about how it is marketed).

Apple just patched the vulnerability in iTunes update 10.5.1. (The vulnerability appears to be Windows only, but it’s not clear. It’s claimed Apple knew about the problem for three years).

FinFisher says the spyware is legal and the company doesn’t know of abuses. But there’s evidence spyware was used to monitor political activists in Tunisia, Egypt and Libya during the Arab Spring, according to a big story about the latest Wikileaks leak in The Washington Post:

“We are seeing a growing number of repressive regimes get hold of the latest, greatest Western technologies and use them to spy on their own citizens for the purpose of quashing peaceful political dissent or even information that would allow citizens to know what is happening in their communities,” Michael Posner, assistant secretary of state for human rights, said in a speech last month in California. “We are monitoring this issue very closely.”

The Post mostly covers the sale of this technology by U.S. companies to repressive regimes, which are using it to spy on citizens and squish political dissent. But Wikileaks claims mass surveillance systems could be widely deployed in western countries:

Surveillance companies like SS8 in the U.S., Hacking Team in Italy and Vupen in France manufacture viruses (Trojans) that hijack individual computers and phones (including iPhones, Blackberries and Androids), take over the device, record its every use, movement, and even the sights and sounds of the room it is in. Other companies like Phoenexia in the Czech Republic collaborate with the military to create speech analysis tools. They identify individuals by gender, age and stress levels and track them based on ‘voiceprints’. Blue Coat in the U.S. and Ipoque in Germany sell tools to governments in countries like China and Iran to prevent dissidents from organizing online.

And you thought Carrier IQ was bad?

Wikileaks has promised to release hundreds of documents about 160 intelligence contractors in the mass surveillance industry through the rest of this month and next year. It released 278 documents on Thursday. Wikileaks is working with several privacy and media organizations.


NSA Report Outlines Goals for MORE Power

N.S.A. Report Outlined Goals for More Power

November 22nd 2013

WASHINGTON — Officials at the National Security Agency, intent on maintaining its dominance in intelligence collection, pledged last year to push to expand its surveillance powers, according to a top-secret strategy document.


Document

In a February 2012 paper laying out the four-year strategy for the N.S.A.’s signals intelligence operations, which include the agency’s eavesdropping and communications data collection around the world, agency officials set an objective to “aggressively pursue legal authorities and a policy framework mapped more fully to the information age.”

Written as an agency mission statement with broad goals, the five-page document said that existing American laws were not adequate to meet the needs of the N.S.A. to conduct broad surveillance in what it cited as “the golden age of Sigint,” or signals intelligence. “The interpretation and guidelines for applying our authorities, and in some cases the authorities themselves, have not kept pace with the complexity of the technology and target environments, or the operational expectations levied on N.S.A.’s mission,” the document concluded.

Using sweeping language, the paper also outlined some of the agency’s other ambitions. They included defeating the cybersecurity practices of adversaries in order to acquire the data the agency needs from “anyone, anytime, anywhere.” The agency also said it would try to decrypt or bypass codes that keep communications secret by influencing “the global commercial encryption market through commercial relationships,” human spies and intelligence partners in other countries. It also talked of the need to “revolutionize” analysis of its vast collections of data to “radically increase operational impact.”

The strategy document, provided by the former N.S.A. contractor Edward J. Snowden, was written at a time when the agency was at the peak of its powers and the scope of its surveillance operations was still secret. Since then, Mr. Snowden’s revelations have changed the political landscape.

Prompted by a public outcry over the N.S.A.’s domestic operations, the agency’s critics in Congress have been pushing to limit, rather than expand, its ability to routinely collect the phone and email records of millions of Americans, while foreign leaders have protested reports of virtually unlimited N.S.A. surveillance overseas, even in allied nations. Several inquiries are underway in Washington; Gen. Keith B. Alexander, the N.S.A.’s longest-serving director, has announced plans to retire; and the White House has offered proposals to disclose more information about the agency’s domestic surveillance activities.

The N.S.A. document, titled “Sigint Strategy 2012-2016,” does not make clear what legal or policy changes the agency might seek. The N.S.A.’s powers are determined variously by Congress, executive orders and the nation’s secret intelligence court, and its operations are governed by layers of regulations. While asserting that the agency’s “culture of compliance” would not be compromised, N.S.A. officials argued that they needed more flexibility, according to the paper.

Senior intelligence officials, responding to questions about the document, said that the N.S.A. believed that legal impediments limited its ability to conduct surveillance of terrorism suspects inside the United States. Despite an overhaul of national security law in 2008, the officials said, if a terrorism suspect who is under surveillance overseas enters the United States, the agency has to stop monitoring him until it obtains a warrant from the Foreign Intelligence Surveillance Court.

“N.S.A.’s Sigint strategy is designed to guide investments in future capabilities and close gaps in current capabilities,” the agency said in a statement. “In an ever-changing technology and telecommunications environment, N.S.A. tries to get in front of issues to better fulfill the foreign-intelligence requirements of the U.S. government.”

Critics, including some congressional leaders, say that the role of N.S.A. surveillance in thwarting terrorist attacks — often cited by the agency to justify expanded powers — has been exaggerated. In response to the controversy about its activities after Mr. Snowden’s disclosures, agency officials claimed that the N.S.A.’s sweeping domestic surveillance programs had helped in 54 “terrorist-related activities.” But under growing scrutiny, congressional staff members and other critics say that the use of such figures by defenders of the agency has drastically overstated the value of the domestic surveillance programs in counterterrorism.

Agency leaders believe that the N.S.A. has never enjoyed such a target-rich environment as it does now because of the global explosion of digital information — and they want to make certain that they can dominate “the Sigint battle space” in the future, the document said. To be “optimally effective,” the paper said, “legal, policy and process authorities must be as adaptive and dynamic as the technological and operational advances we seek to exploit.”

Intent on unlocking the secrets of adversaries, the paper underscores the agency’s long-term goal of being able to collect virtually everything available in the digital world. To achieve that objective, the paper suggests that the N.S.A. plans to gain greater access, in a variety of ways, to the infrastructure of the world’s telecommunications networks.

Reports based on other documents previously leaked by Mr. Snowden showed that the N.S.A. has infiltrated the cable links to Google and Yahoo data centers around the world, leading to protests from company executives and a growing backlash against the N.S.A. in Silicon Valley.

Yet the paper also shows how the agency believes it can influence and shape trends in high-tech industries in other ways to suit its needs. One of the agency’s goals is to “continue to invest in the industrial base and drive the state of the art for high performance computing to maintain pre-eminent cryptanalytic capability for the nation.” The paper added that the N.S.A. must seek to “identify new access, collection and exploitation methods by leveraging global business trends in data and communications services.”

And it wants to find ways to combine all of its technical tools to enhance its surveillance powers. The N.S.A. will seek to integrate its “capabilities to reach previously inaccessible targets in support of exploitation, cyberdefense and cyberoperations,” the paper stated.

The agency also intends to improve its access to encrypted communications used by individuals, businesses and foreign governments, the strategy document said. The N.S.A. has already had some success in defeating encryption, The New York Timeshas reported, but the document makes it clear that countering “ubiquitous, strong, commercial network encryption” is a top priority. The agency plans to fight back against the rise of encryption through relationships with companies that develop encryption tools and through espionage operations. In other countries, the document said, the N.S.A. must also “counter indigenous cryptographic programs by targeting their industrial bases with all available Sigint and Humint” — human intelligence, meaning spies.

The document also mentioned a goal of integrating the agency’s eavesdropping and data collection systems into a national network of sensors that interactively “sense, respond and alert one another at machine speed.” Senior intelligence officials said that the system of sensors is designed to protect the computer networks of the Defense Department, and that the N.S.A. does not use data collected from Americans for the system.

One of the agency’s other four-year goals was to “share bulk data” more broadly to allow for better analysis. While the paper does not explain in detail how widely it would disseminate bulk data within the intelligence community, the proposal raises questions about what safeguards the N.S.A. plans to place on its domestic phone and email data collection programs to protect Americans’ privacy.

N.S.A. officials have insisted that they have placed tight controls on those programs. In an interview, the senior intelligence officials said that the strategy paper was referring to the agency’s desire to share foreign data more broadly, not phone logs of Americans collected under the Patriot Act.

Above all, the strategy paper suggests the N.S.A.’s vast view of its mission: nothing less than to “dramatically increase mastery of the global network.”

Other N.S.A. documents offer hints of how the agency is trying to do just that. One program, code-named Treasure Map, provides what a secret N.S.A. PowerPoint presentation describes as “a near real-time, interactive map of the global Internet.” According to the undated PowerPoint presentation, disclosed by Mr. Snowden, Treasure Map gives the N.S.A. “a 300,000 foot view of the Internet.” 

Relying on Internet routing data, commercial and Sigint information, Treasure Map is a sophisticated tool, one that the PowerPoint presentation describes as a “massive Internet mapping, analysis and exploration engine.” It collects Wi-Fi network and geolocation data, and between 30 million and 50 million unique Internet provider addresses — code that can reveal the location and owner of a computer, mobile device or router — are represented each day on Treasure Map, according to the document. It boasts that the program can map “any device, anywhere, all the time.” 

The documents include addresses labeled as based in the “U.S.,” and because so much Internet traffic flows through the United States, it would be difficult to map much of the world without capturing such addresses.

But the intelligence officials said that Treasure Map maps only foreign and Defense Department networks, and is limited by the amount of data available to the agency. There are several billion I.P. addresses on the Internet, the officials said, and Treasure Map cannot map them all. The program is not used for surveillance, they said, but to understand computer networks.

The program takes advantage of the capabilities of other secret N.S.A. programs. To support Treasure Map, for example, the document states that another program, called Packaged Goods, tracks the “traceroutes” through which data flows around the Internet. Through Packaged Goods, the N.S.A. has gained access to “13 covered servers in unwitting data centers around the globe,” according to the PowerPoint. The document identifies a list of countries where the data centers are located, including Germany, Poland, Denmark, South Africa and Taiwan as well as Russia, China and Singapore.

Despite the document’s reference to “unwitting data centers,” government officials said that the agency does not hack into those centers. Instead, the officials said, the intelligence community secretly uses front companies to lease space on the servers.

Despite the N.S.A.’s broad surveillance powers, the strategy paper shows that N.S.A. officials still worry about the agency’s ability to fend off bureaucratic inertia while keeping pace with change.

“To sustain current mission relevance,” the document said, Signals Intelligence Directorate, the N.S.A.’s signals intelligence arm, “must undertake a profound and revolutionary shift from the mission approach which has served us so well in the decades preceding the onset of the information age.”

© 2013 The New York Times Company.

The content you have chosen to save (which may include videos, articles, images and other copyrighted materials) is intended for your personal, noncommercial use. Such content is owned or controlled by The New York Times Company or the party credited as the content provider. Please refer to nytimes.com and the Terms of Service available on its website for information and restrictions related to the content.

Friday, August 30, 2013

NSA Spying on Congress for Decades

During the drama over the so-called Amash Amendment General Keith Alexander, head of the NSA, went to Capitol Hill to lobby against the law. During the course of his lobbying members of Congress responded to his presentations with a reasonable question – can we see our own files?Alexander said no. According to David Sirota of NSFW Corp these exchanges are quite revealing as to how the NSA’s power works in Washington.

Consider the deep messaging of the NSA’s brand. Only forty years removed from the blackmail-tinged reign of J. Edgar Hoover, the NSA has developed an image which implies the agency is vacuuming up more than enough incriminating phone records, emails and text/sext messages to politically torpedo any rank-and-file congressman, should that congressman step out of line.

And here’s the thing: for all the agita intelligence officials express about new disclosures, those disclosures illustrate the sheer size and scope of governement surveillance. That doesn’t weaken the NSA – on the contrary, it serves to politically strengthen the agency by constantly reminding lawmakers that the NSA 1) probably has absolutely everythingon them and 2) could use that stuffagainst them.

Sirota also spoke with Rep. Alan Grayson who told him that in the course of the conversation about the NSA and files they might have on members of Congress said “one of my colleagues asked the NSA point blank will you give me a copy of my own record and the NSA said no, we won’t. They didn’t say no we don’t have one. They said no we won’t.” Dare anyone accuse the NSA of being cryptic?

Of course we already know that it wasNancy Pelosi that killed the Amash Amendment. What we don’t know is whether she did so out of fear of an NSA file, party interests or both. We also know she was involved in insider trading while in Congress. What more does the NSA know about her?

There was also a report by a former intelligence analyst and whistleblower Russell Tice that the NSA wiretapped Barack Obama in 2004. Is there some massive archive of politicians’ dirty secrets somewhere at the NSA? Surely the NSA at least has their metadata – they have everyone’s. It is hard to imagine when push comes to shove and its budget time that the NSA doesn’t take a peek at who they are doing business with in Congress. Intelligence is all about having as much information as possible, that’s the training and that’s the game. Old habits probably die hard.

It was a troubling thought, but I had no smoking gun evidence to support it, until I heard Mark Ames discussing Sirota’s story with Sirota yesterday. Ames referenced a blockbuster story broken by New York Times reporter Scott Shane. Published by the Baltimore Sun, the story Listening in: Though the National Security Agency can’t target Americans, it can — and does — listen to everyone from senators to lovers, provides smoking gun evidence that the NSA has been spying on members of Congress and allowing the information to be used for leverage since at least the Reagan Administration.

“We listened to all the calls in and out of Washington,” says one former NSA linguist, recalling a class at the Warrenton Training Center, a CIA communications school on a Virginia hilltop. “We’d listen to senators, representatives, government agencies, housewives talking to their lovers.”

“Even when they target foreigners, they end up picking up a lot of Americans,” says Mark H. Lynch, an attorney who tracked NSA for the American Civil Liberties Union from 1977 to 1985. Just ask formerMaryland Rep. Michael D. Barnes. His calls to Nicaraguan government officials were intercepted and recorded by NSA – as he learned only after transcripts were leaked by the Reagan White House, he says.

Congressman Barnes became a thorn in the side of the Reagan Administration and the US intelligence community over his opposition to US activity in Nicaragua.

“Reporters told me right-wingers werecirculating excerpts from phone conversations I’d had,” says Mr. Barnes, now a Washington lawyer. He says the calls included one to the Nicaraguan foreign minister protesting his government’s declaration of martial law.

On another occasion, Mr. Barnes says, the director of central intelligence, William J. Casey, showed him a Nicaraguan Embassy cable intercepted by NSA that reported a meeting between embassy officials and a Barnes’ aide. Mr. Casey told him he should fire the aide; Mr. Barnes angrily replied that it was perfectly proper for his staff to meet with foreign diplomats.

Mr. Barnes says he did not object to being overheard. But he said the incidents were a reminder of the potential for the abuse of NSA’s awesome eavesdropping capacity. “I was aware that NSA monitored international calls, that it was a standard part of intelligence gathering,” he says. “But to use it for domestic political purposes is absolutely outrageous and probably illegal.”

So there is nothing new under the sun. Information is power and in political struggles one should not be so surprised that information will be used and abused by political actors. Now solid and reasonable curtailments of NSA’s wildly expansive power are getting crushed in Congress despite widespread popularity in both parties.

What’s going on behind the scenes? Is the NSA using its data for political gain?