CIA’s Latest Layer: An Onion Site
cia.gov
cia.gov
How does one store links like this? You'd need a bookmark file, which would sort of give the game away, I'd have thought. How do you make sure you notice when you visit a URL with the same readable prefix?
Figure 10 shows that most users (52%) use bookmarks, followed by locally-saved text files (37%), and referral to trusted web pages (35%).
Also, lots of people find themselves unable to determine an onion service's legitimacy (Figure 12), which is why phishing attacks are successful. We document one such attack in Section 5.1 of another research paper: https://nymity.ch/sybilhunting/pdf/sybilhunting-sec16.pdf
One possible solution would be to issue a TLS certificates for both the clear-web and .onion domain (for services which are offering .onion services to provide better anonymity for users not their servers).
Unfortunately, the CAB forum has decided to not allow this -- only EV certificates can be issued for .onion services so you can't use LetsEncrypt for this.
HN discussed (https://news.ycombinator.com/item?id=14038013) about the issue and the post (https://blog.torproject.org/cooking-onions-names-your-onions) outlines some of the ways in which you can mitigate right now.
Cloudflare is using the 'alt-svc' header (https://blog.cloudflare.com/cloudflare-onion-service/).. The CIA is not, I'd have loved it.
curl -I https://www.cia.gov/index.html HTTP/1.1 200 OK Accept-Ranges: bytes Content-Type: text/html ETag: "<>" Last-Modified: Tue, 28 May 2019 15:05:25 GMT Content-Length: <> ID: <> SESSION: <> Date: Thu, 30 May 2019 12:36<> GMT Connection: keep-alive Set-Cookie: _session_=<>; path=/; domain=cia.gov; secure; HttpOnly ID: <> SESSION: <>
It should be noted that alt-svc is an HTTP header returned which means you have first made an HTTP request before the onion request which affects anonymity. It's not a big deal over Tor because that HTTP call is on an exit node, but still should be noted.
Once you have confirmed a domain is correct, you should save it yourself, and only access that saved link.
Using any forums/wikis/search to find onion links (may) leave you with stolen credentials or a hacked machine.
It's cumbersome for sure, but the beauty is it's self-authenticating. Don't forget to turn off JS. :)
[1] https://trac.torproject.org/projects/tor/wiki/doc/HiddenServ...
Cloudflare offers their DNS-over-https service at an onion address. In their documentation, they say:
"
Protip: if you ever forget the dns4torblahblahblah.onion address, you can simply use cURL:
curl -sI https://tor.cloudflare-dns.com | grep alt-svc
alt-svc: h2="dns4torpnlfs2ifuz2s2yf3fc7rdmsbhm6rw75euj35pac6ap25zgqad.onion:443"; ma=315360000; persist=1
"
It's a clever way, and standards-compliant, to distribute alternate onion addresses for existing services.
What I don't know is if Tor Browser Bundle has support for this natively, where if you visit tor.cloudflare-dns.com and it'll look for the alt-svc record and redirect you automatically to the onion address.
If it does, then you can just bookmark the regular URL knowing that you'll be redirected.
What can you do when there is no central DNS to trust. I suddenly felt that I couldn't trust anything at all. I started to question those around me and spiraled into existential philosophical crisis of truth testing even my own senses.
I eventually found a real solution, but I'm on mobile and don't feel like typing the whole thing out.
If it's not on you, they can't beat it out of you.
Of course, they might decide to beat you anyway. Which raises the question of whether it's strong crypto or rule of law that matters more. I'm not sure which way I come dwn on that myself, though could argue for bits of both.
So it being embraced by the US intelligence community is unsurprising.
Yes, it was, and it was released under a free license by the US Naval Research Lab in 2004.
> it was developed in public (by Roger Dingledine and the rest of the Tor community).
No, it was developed by Dingledine and others under contract with US Naval Research Lab before being released by that Lab under a free license. Further development occurred after it was released in a public project (most of whose funding over its life has come from...the US government.)
https://www.washingtonpost.com/news/the-switch/wp/2013/10/05...
Do you currently work for any three letter agencies? Did your smartest colleagues go to work at three letter agencies?
I am trying to gauge the quality of talent at CIA, NSA, FBI, etc. All of my best colleagues went to the private sector, usually tech or security companies. I know some of these companies contract for the departments / agencies (and many colleagues have clearances). However, they are not actually working at the agencies themselves.
So what is the talent pool at the CIA et al. like?
There are ex-Googlers and such as well, but they're not super common. One guy said he got bored at Google because he was rebasing code all the time so switched over. Not everyone will take the more money for a job where your role can feel meaningless. In comparison, these DOD jobs definitely feel meaningful, almost no matter your role. Feelings inside are very similar to what you hear from military servicemembers about feeling like you're making an important difference. If you don't, it's easy to change positions; it is very desirable to have a load of different skills, and learning/training is not only available but pushed hard. Internal and external classes, paying for degrees and having partnerships with local colleges, externships with large private corporations, internships in other departments are all common. If you like to learn, it is appealing. As a result, there are certainly a lot of very smart people.
Being government, you still have a chunk of the pool who are basically done but hanging on til retirement. I'd say it's past the 15-20 year mark that people really start to phone it in in technical positions. I won't get into this too much, but someone who is not known as top of their field but is close to or has maxed out the pay scale, they're probably not useful anymore. There are a lot of these (everywhere in government).
This makes a lot of sense if the state of the art inside the agency is sufficiently ahead of that outside - experience would be in the wrong stuff.
It might also make sense if they want to pretend that is the case.
He began trash talking Edward Snowden within 60 seconds, and complained that anyone under 25 (pretty much the sole demographic present at the event) were averse to paperwork and would never make it in the "real world". He also uncannily romanticized doing paperwork and laughed aloud at the prospect of any employees doing any sort of creative work, saying that "engineers are just pencil pushers" (paraphrasing).
He mocked the media's representation of the NSA in a characteristically dissociative way, alluding to that he genuinely had no clue why the public perception of the NSA is what it is.
He finished it off by rambling about "quantum tunneling and metaphysics" (never knew the NSA was so interested in the works of Arthur Schopenhauer) and more or less begging the public at the event to come work for the NSA, saying they were desperately in need of talent.
Up until this experience, I had often considered the public perception of the NSA to be probably unrepresentative of reality, and my opinion could be summed up as "a big fan of Splinter Cell". Now, personally, I am entirely turned off to the prospect of employment with them.
Previously, I had envisioned that any issues within the agency could be remedied by new talent reforming internal policies, but I believe the problems that exist within it are pathologic, and I was enthusiastically informed that any position I had within the agency would be "pencil pushing", "paperwork", and a complete lack of creative fulfillment. What a way to kill prospective talent.
Ask them for the NSA Sudoku books. They also publish crosswords. These are the only NSA documents Wikileaks wouldn't touch.
A serious consideration for recruiters working for these agencies is that millennial truly fear the interview process. They believe that the NSA/CIA has their entire browsing history on file, that the interview process may see them confronted by some awful website they visited late one night in their teens. Or they fear any examination of their past may be shared with law enforcement. These are legitimate fears that recruiters must address. The reality is that such histories are not kept on file and/or are not part of the interview process.
(Similarly, many people don't realize themselves illegal immigrants/dreamers until they try to enlist in the army.)
Having recruiters that further disparage the newer generations and grow increasingly out of touch is doing nothing to boost their numbers, at least in my field. Everyone I know who would be a best fit for their agency is a privacy geek who wants nothing to do with them. Outreach would be an incredibly lucrative opportunity for them to gain talent.
Even if they had this information, the most likely strike would be if you lied about it rather than if you actually did it.
They are fully aware of the range of behavior that humans are capable of, perhaps in a way that many 25 yos are not.
I am genuinely baffled why they wouldn't fire up XKeyscore to double-check the accuracy of the SSBIs.
Are you thinking about websites like 8chan?
I was in the US Navy for 10 years, and this 100% false. I don't know if this was just a setup for your punchline, but it is absurd. If you test positive on urinalysis, the navy has a 0 tolerance policy so you will be discharged. If it "comes out" that you smoked, almost no one cares.
Just looking for some good RE blog posts.
Nice try Infernal Affairs.
I’ve known people with clearances at Govt contractors. They could say what they do, EE/ME for X project but not many details beside that.
It's like this for many gov agencies working with intelligence because labeling yourself as an intelligence worker makes you a target for foreign intelligence agents.
That may sound a little strange if you aren't part of that industry, but it is the truth.
I don't think this is as absolute as you make it sound. Plenty of NSA employees have published papers using their real names in conjunction with nsa.gov or ncsc.mil email addresses
What do the folks in Virginia say to their neighbors? “Oh I work for the DOD. So your a spy right haha?”
That seems like a difficult to keep secret
OTOH, I have never met anyone who has admitted to working for the CIA - either directly or as a contractor. There is a definitely a non-disclose policy for them.
The funny part is that he has a 100% chance of getting “randomly” selected for search every time he takes a plane.
For one thing, people grow & change. Out of some hypothetical cohort of peers in year X, some few may have been the “best” in science and engineering at the point of time when everyone was graduating college and getting jobs. Doesn’t mean they would still be the best 5 or 10 years later — in fact the best person from the cohort at that time may not even have ever studied computer science until later in life.
Even more importantly, top private firms like Google et al hire in a specific way that emphasizes a combination of rote memorization of facts and youthful resistance to burnout. While this may correlate with high skill in some age groups, for some types of work, it’s a very poor substitute for experience-based judgment and creativity, especially the stuff that cannot be mapped easily to rote memorization of computer science facts.
In this sense I’d guess the three letter agencies have employee skill about as good as most tech companies, with the exception that very junior employees are “better” on the rote memorization and burnout-avoidance predisposition at tech companies (and that agencies don’t care much about missing out on that overrated talent pool sector).
Many agencies also have long-time partnerships with professors and academic institutions that give them a lot of consulting support, often from literally world experts in things. Combined with FFRDCs that also have this type of consulting relationship and can often pay a little better to attract better talent, the agencies probably have no shortage of good talent.
The main question I have is why the agencies are able to pay such low salaries, sometimes even in urban areas, no bonuses, etc. I feel they have talented people who are massively underpaid.
I grew up in DC and have a bunch of friends that went to work for the Federal Government. Not in these types of agencies, but nonetheless instructive I think.
The incentives at these places are completely different. Pay is somewhat low at start but it's rock solid stable and grows predictably and can get pretty respectable over time, the level of stress and unpredictability can be very low, the promotions are on a schedule, and vacation time and flex time can be pretty attractive.
It's not for me, I would go crazy in that culture, but I have some friends that are really happy to have a job they can check into, do what they're told to do, and go home.
It was the best position I've ever had for work/life balance. The time off was extraordinary, the health insurance was stupid good, it was super stable, but the pay was 1/2 to 2/3 what I could make in private industry.
When I had small children, it was the perfect job, just due to the flexibility in time off and lack of real on-going stress.
They pay enough to get the talent they need * . Or in other words, if they're sufficiently staffed it's because people are willing to work there for less than market rate.
Patriotism, a chance (in some roles) to work on cutting edge tech / scale, and making a difference in the world attract people.
You can feel however you want about the agencies morally and ethically, but their work is unique.
* Subject to Congressional cooperation and government pay scales
Working for the NSA doesn't necessarily entail working on mass civilian surveillance, which I think is where the moral and ethical concerns are concentrated. They still do military and diplomatic intelligence, and defensive security for US many government systems, which I think only the most pacifist would have a problem with.
For tippy-top talent, I imagine it’s kind of like the same way academia can compete with tech firms. You get freedom to work on interesting problems in a relatively low pressure environment. Additionally a lot of federal agencies (ironically it might seem) are no-bullshit places to work. There’s a published pay scale and promotion schedule. You show up do the work you move up. You never get laid off. One other thing is that certain national security important roles do get paid on a higher scale than the usual GS scale.
I know this sounds silly, but i've been at big companies before (Fortune 10) and have seen some pretty ugly things (once, three reports of a manager alleged a sexual attack on a rival manager; rival manager is fired; manager who's people made the accusation gets promoted.)
Now I can imagine these types of political battles at three lettered agencies might involve false accusations that might land someone at jail. Is it like that?
I'd honestly love to work at the intelligence agencies and serve the country in a role better suited given my technical skills, but I dont want to end up in some shark tank.
How devastating that is depends entirely on your level of investment in your career in intelligence.
He was the type who could do whatever put his mind to and had the determination to do it, Doctor, Lawyer, engineer whatever. Professions were probably to easy for him to do.
In a way I think those in the spy-ish agencies also think along the same lines but they get no recognition from the public about the benefit compared to national health care.
It’s my experience that the NHS is taken for granted in the UK, and I can’t for one second believe that there’s ANY prestige there.
To be fair there is some ENORMOUS talent in certain directorates, but a lot of that has gove over to SpaceX, Blue Origin, et alia.
The solution would be to partner with universities for the post-grad research stuff and hire people from "industry" as much as possible. Hopefully the people from industry could pick better people to hire from the post-grad research programs. Likely this will never happen, and it might not fix everything (or anything).
(obviously there are perks working for the government that the private industry cannot match, so for some people lower pay is acceptable)
In the end, you are still right but it's still a factor.
I’m lost, what are those in the UK?
"mr Oldfield, that Kims a wrong un - I saw him taking money from the from the orphans fund"
M " I know lad I know"
Can confirm.
Went to MIT for EECS. Lots of us went to Google or trading companies.
So, in short, don’t work for them. It might seem cool, but it’s not worth it. If they don’t like you, they’ll fuck you.
I don't know enough about the case to form an opinion about it, but at first glance, uploading CIA-related source code to GitHub it's not what I would define as "smart".
https://www.vice.com/en_us/article/qvn83q/joshua-schulte-cia...
https://www.thedailybeast.com/exclusive-cia-leaker-josh-schu...
He may have thought he was serving some higher good, but that's hardly uncommon among spies.
When I say someone is a spy I mean "someone sold secrets to a foreign power". When a US judge says someone is a spy it roughly means "someone divulged classified information and/or ..<list of things>..".
The law considers divulging secrets as espionage because loose lips sink ships: using the espionage act to prosecute anyone posing a threat to national security is the easiest (and practical) way to make a danger harmless.
The main issue with defining espionage like this is the logical confusion that creates in people: quoting Daniel Ellsberg "the current state of whistleblowing prosecutions under the Espionage Act makes a truly fair trial wholly unavailable to an American who has exposed classified wrongdoing".
It's not my job to rule if someone is a whistleblower, a spy, or someone who protests against things he deems wrong through the disclosure of classified material. What I know is that the US law is bad because it does not distinguish between "someone who sold secrets to a foreign power" and "someone who divulged classified information": these are fundamentally different (illegal) things.
The whole situation gets worse when anybody gets to read stuff like "5. FBI told plaintiff they could not afford another Snowden" and "6. FBI steal plaintiff's cell phone and passport" (https://imgur.com/RMJk7QC).
It's ironic that the onion is "ciadotgov + 4SJW + __ ".
The year before I completed an aptitude test which predominantly focused on abstract reasoning. It was a strange experience and part of me wants to discuss it in a responsible/de-identified sort of way, but on the other hand, the take-away I got from the experience itself is kind of holding me back from following through with that desire to discuss it....I'm not sure if what I just wrote makes any sense to me now that I just typed it out.
It was still an interesting experience though which did have a positive impact on my life.
EDIT: Sorry, edited for a spelling mistake
https://security.stackexchange.com/questions/29772/how-do-yo...
cia.gov for Social Justice Warriors. Pretty sure he was just making a joke and only the first 9 characters were actually being tried for.