Former NSA Employee Arrested on Espionage-Related Charges
justice.gov
justice.gov
(1) immediately opens a KYC custodial account (2) xfers the crypto there (3) converts it to USD and sends it to his KYC bank in Colorado.
You can't make this stuff up. Also I love how (ostensibly either proton or tutanota) is referred to "Foreign Email Provider". They should buy ForeignEmailProvider.com and make it another email domain for their users. I would love hackerman69420@foreignemailprovider.com
So some such system detected him as a threat and he left in under a month of employment? That's wild.
The FBI got lucky that one of their honeypot email addresses was the inbox. And then obtained records corroborating everything, such as from Kraken.
and the access logs of the top secret material from the agency's systems.
The access logs said Dalke accessed. Kraken's logs said "there were deposits of Monero in Dalke's accounts that are the exact amounts you sent Dalke, accounting for exchange rate fluctuations". Kraken's KYC records said "here's Dalke and his addresses". The UPS store he was using for an address said "Yep, Dalke keeps a drop here". The bank account connected to Kraken said "Yep, its Dalke". The setup at Union Station in Denver was for Dalke to come there between 11:30am and 3:30pm on September 28th, the affidavit ends 1 day before that, and Dalke was arrested in that exact location the next day.
he would have been emailing anyone and the compromised wires picked it up for the FBI to then begin their sting operation?
The FBI still had to do the work, but I think its also plausible that they have a bunch of honeypot email inboxes around. I think since they had to do all the communication as well as the transferring of funds that it's not really parallel construction, at least in any controversial way for evidence collection. They got additional evidence that doesn't need creating a rationale retroactively.
but what do you think happened here?
I don’t see the issue with this one to apply such a rigid stance
Maybe he did dumb things with it, but the whole thing was a sting.
Look at the VAT fraud in Europe, billions lost, virtually nobody arrested
https://en.wikipedia.org/wiki/Missing_trader_fraud
> Notwithstanding these measures, MTIC fraud remains a problem for the EU. As at November 2018, calculations estimating the annual costs of the fraud range from €20 billion up to more than €100 billion (depending on methodology adopted).[21] An EU Parliament study in October 2018 found that MTIC/carousel fraud is the most damaging type of cross-border VAT fraud with an estimated €50 billion losses on average per year.
France is also hemorrhaging billions through social benefits fraud, they don't even attempt to recover most of it as they don't have the manpower
Different figures are given but it looks that most those "billions" are in fact shortfall and not benefit fraud.
Drug crime gets a lot of attention because the statutes are written in a way that makes the crimes very easy to prove. It’s far easier to prove the elements of a drug possession charge than it is to prosecute something like fraud.
The authorities are strategic in their approach but at the end of the day they are operating on finite resources.
The advantage the authorities have though is that they are playing offence. They can make plenty of mistakes and still achieve their objective.
Criminals just have to make one mistake and it can undo all the she effort they have made to mitigate risk.
https://www.vox.com/2018/9/24/17896034/murder-crime-clearanc...
But if you are going to do a crime do it once and done and you may very well get away with it.
-> some gear get purchased bet never used/installed for a few years. Sits around gathering dust. -> Sheriff sees this, takes it home sells it on eBay. Nobody notices or cares. It wasn't being used after all. -> Sheriff finds other unused gear, takes home and sells it. -> No valuable unused gear left, so Sheriff starts buying stuff simply so he could take it home and sell it. -> At this point it is noticed. Seriff gets found out and arrested.
If it was just the first step, nobody would have noticed and the guy would have pocketed $20k or whatever, and no one in the world would have been the wiser. The auditors may have eventually discovered the piece missing, but long after any video recordings expired, and the original purchase was perfectly legit. But greed combined with stupidity got the guy arrested.
Those who could resist doing it more than once probably can resist doing it at all.
Also based on the value the crypto was Monero (and he use Kraken, which is only big US exchange that converts XMR/USD pair), so he probably didn't realize even though it is difficult to directly trace where it came via the blockchain the exact unique amount deposited on KYC exchange fucked him. A naive Monero user would probably think "impossible to find where monero came or went from, so I'm safe" not realizing they're leaking out the side-channel by depositing a unique amount on a centralized exchange.
Lol, I suppose he's guilty of lying on his resume too!
When I read the RFCs behind the stuff to write what I needed in Rust, suddenly it dawned on me: wow this stuff isn't nearly as complicated and horrible as openssl's interface makes it seem like.
Honestly I would expect some to be more familiar with the hashXsum tools.
SmallPPDomainRegisterBot.com
Troll the troll into trolling themselves?
Monero was worth $154 on August 24th, is a privacy crypto and .64 of that would be $99
Sure they traced the crypto but that's not how they got him.
Perhaps a worse punishment than the inevitable long prison term is the fact that this guys entire trip through the alimentary canal of our criminal justice system is going to have a continuous laugh track.
I don't even know if any of us could ever pull this off unless one works for a defense contractor. Even if I did something horrendously malicious like selling trade secrets from my current company to some foreign competitor (e.g. Huawei, Tencent, or whatever Chinese cloud companies are these days?), I don't know if I could wrack up 3 counts of violating a law with the death penalty as consequences in as many weeks.
Do they have some sort of quota of how many terrorist they need to catch a year in order to get a bonus?
I mean a lot of corporates hire companies to send fake phishing mails to employees - I got caught out a few times by that because I clicked a link on emails thinking "wtf is this about". The issue there of course is that the enterprise I'm working for at the moment sends tons of "wtf is this about" emails. Currently I've got about two dozen emails from some guy updating all 100+ people in the IT organization on their deployment process, every hitch they run into, plus fixed timed updates.
He is basically a walking profile of insider threat behaviour modeling.
I don’t think it was anything other than his stupidity that put him on the radar so quickly. Reading the indictment it’s clear he was a bit of an idiot.
Given that his access of the documents was logged anyway, it wouldn't surprise me if the misconfiguration was itself a honeypot, using documents that are relatively low-value but still classified.
I could never get anything done in espionage. I’m far too paranoid.
https://www.namecheap.com/domains/registration/results/?doma...
Occasionally, though, it does work like you say. I think there was some Asian(?) politician that they tried to blackmail after something like this, and he basically said: "Hey, could you send me a copy of the sex tape? She was smokin' hot, and I'd love to have the video."
https://medium.com/war-is-boring/the-cia-and-kgb-tried-to-bl...
It doesn't even need to be true, just needs to be compelling.
I'm looking at this to be possible more like when you have company wide phishing tests going through the emails, and it catches Brenda the new person in accounting who's still on their probationary period.
People email that account with offers of providing information to the russian government, and then the FBI goes and sees who had access to the documents which get sent over. In this case, only one person accessed all the documents, so even if he doesn't identify himself to I_AM_A_RUSSIAN_SPY@gmail.com, they still get him.
It doesn't seem like this person was specifically targeted or had an operation against him. He just fell into the honey pot.
Say you are the CTO or engineering security staff of say Google.
What is the first 3 months of employment called behind the scenes?
Probation.
It's not just a nickname, as one would track all accesses to anything and higher access rights would obvious follow proven trust. And one might even set up honey pot traps to weed out the bad actors even.
Or a situation where the guy who an undercover agent approaches tells his superiors? Who then want him to go undercover to find out who the suspected foreign agent works for.
I’m sure this can happen in government.
Also the Book "A Scanner Darkly" by Philip K Dick which (no spoiler) explores the consequences of deep undercover.
Also, your username totally caught me off guard and made me laugh.
There's a subplot vaguely along the lines of everyone being an undercover, although saying more would be a bit too much of a spoiler.
Part of the reason they never tried Ross Ulbricht for the hit jobs is because a rogue FBI office in Baltimore was staging the hits in a studio (the evidence to show Ross, to get the rest of the payment), and the FBI office in Chicago also investigating Silk Road was like "why are you guys roleplaying, this can't be as cringy as it looks, what is going on in Maryland", and the Secret Service and DEA agents were roleplaying as moderators on Silk Road and creating fake controversy to both Ross Ulbricht and the FBI offices investigating, just so the Secret Service and DEA could extort Ross (for the fake hits) and ride off into the sunset with the money, landing a movie deal with Fox. They're in jail now. And the hitman stuff was dropped under equally fake pretexts just to save face.
The Secret Service and DEA agent were being tried at the same time as Ross Ulbricht was, this information and evidence was kept from Ross and his trial and only came to light afterwards. Wasn't accepted in the appeal. Sentencing didn't factor any of this in either. Embarrassing case.
https://www.vice.com/en/article/8q845p/dea-agent-who-faked-a...
There was once a bank that looked the other way when lots of shady cash came in, allowed transfers of those amounts to to foreign banks, basically ignored KYC rules, etc. Word got around, and lots of criminals all over started using this bank for all of their money laundering purposes.
Some banking authority started noticing a lot of suspicious transactions, and was preparing to shut the whole thing down, disconnect the bank from all transfers, raid offices, arrest employees, trumpet press releases about how they're protecting the American financial system, etc... (ie, exactly what they are supposed to do).
The bank was, of course, a honeypot run by some other 3-letter agency, who was actively facilitating money laundering in order to collect enormous amounts of info about who was involved.
(basically the banking version of that 'encrypted phone' scheme).
The raids were mere hours away when someone put two and two together, and managed to get it called off.
It has happened several times with cops.
Feds are a bit more professional I believe.
https://rmx.news/germany/german-domestic-intelligence-agents...
Hackers were at the cutting edge in 1983 when War Games came out. That era has come and gone, and we live in a different paradigm now.
Here's one https://storage.courtlistener.com/recap/gov.uscourts.nysd.42... for the sentencing submission for https://en.wikipedia.org/wiki/Paul_Le_Roux which reveals some pretty personal and operational information.
There's one about a Colombian paramilitary leader/drug trafficker turned informant which improperly redacted all the people he informed on: https://storage.courtlistener.com/recap/gov.uscourts.dcd.184.... This is from like a decade ago but goes to show how this kind of thing can literally put people's lives at risk.
There was another story about a memo with “top secret” or “secret “ stamps on pages, that an agency had distributed internally. The information was like, use AES-256 for important data, or key length 3072 with RSA. It was all well known material, nothing secret. I was like, WTF!
Just because there are public recommendations now days does not make the information not classified.
There’s a chance that in the past the recommendation was set out because of attacks that the NSA thought only they are knew about.
Interestingly enough I’ve seen the recommendations change depending on the classification of the document in some leaked secret document there was a recommendation to use some algorithm (RC4?). In the top secret document the recommendation was the same but to discard the first 3072 bytes to avoid a key stream bias vulnerability.
https://apply.intelligencecareers.gov/job-listings?agency=NS...
Must be a very tough job getting smart people to work for them given the average salaries.
This is a very grey area.
How can we interpret this as NSA competence?
Do please share your expertise from working in security about how this guy having access to secrets is a positive indicator of competence. I'm more than willing to change my views given a good argument based on strong evidence.
The NSA has a responsibility to remove weaknesses from their ranks, mission accomplished. If the problem you see is "Well agencies ought never give new people access to state secrets" then you can't have any changes ever - it's a dead organization.
The other competency I see is that none of the documents, which are of course going to be used in court, are available to the general public. They proved a weakness without leaking any information to parties outside the intel community. They essentially demonstrated that even if they hire a complete moron, state secrets will not leave protected facilities.
Hiring this guy to serve beer seems to me like it's not a super-competent move. But they did, then they stung him and he's likely going to jail and they get to talk up their success on thwarting "the baddies." Until you read the details and laugh at the idiocy of it. According to you it's because they can't determine who to trust before giving them security clearance. No way to do it. Can't even take a reasonable guess.
Do they still use totally discredited and shown to be utterly ineffective witch-doctor bullshit like "polygraph" machines? Or have they stepped up from throwing bones and reading tea-leaves? Or they've stopped and just give anyone clearance because there's no other way to do it as you seem to be claiming.
Is that your experience of working in security? Please share.
FBI/NSA/etc are just government backed criminals.
huh?
You can rely on a member of (say) the military to be at least somewhat resistant to bribes, threats and flattery, because they generally do honestly believe in the ideals of the country they're defending. The same applied to intelligence services in the west during the later cold war after the USSR became hopelessly corrupt. That's why the west won so many intelligence victories. And the vast majority of the losses where when the opposite applied: people who honestly believed in communism in the early cold war.
But in today's NSA, you cannot support freedom, democracy, the rule of law, basic honesty, or really anything except for "they pay well so I don't think about it". And when that's the case, there is always someone else willing to pay better...