CIA 2010 covert communication websites
cirosantilli.com
cirosantilli.com
On another note it is easy to shame the CIA for making such a basic mistake as using subsequent IP numbers/same file layouts on sites. Of course they should be, but funnily enough mistakes such as these happen in every intelligence service. As example would be the Russian military intelligence (GRU/GU) who have for years sent agents abroad with fake/cleaned Russian passports. Only problem being of course that the passport numbers were sequential and as in the case of the CIA websites, if you identified one agent and his passport, you could look up the next ones in line on databases and identify all the other active agents as well.
Reference for GRU passports: https://www.voanews.com/a/russia-gru-operatives-unmasked/460...
Here's one about two agents with passports 3 digits apart: https://www.bellingcat.com/news/uk-and-europe/2018/09/20/skr...
I took a very cursory look, since they are obfuscated and reading obfuscated code sucks. I see swing (gui) drawing code, a few references to flash and activex, as well as code to load rsa and look for a program do to encryption/decryption: PGP, OpenPGP, CFB, OFB, SIC, GTCR. And a bit of url loading. So, probably nothing one didn't expect: It receives message over a network connection and uses these programs to decypher them, then shows it .. I don't know? directly in the gui probably. And the other way around.
But that's really just me looking for ten minutes. I could also be wildly off the mark here.
There's advantage in appearing incompetent and creating traps to distract from actual active capabilities that are working.
The cases where people walk away unscathed and achieve some proper good instead of long bad prisons, torture or outright execution are miniscule. You can be sacrificed by some bureaucrat which has lower intelligence than you, doesnt care a bit, is corrupt or just treats you as a pawn in some bigger game.
Greater good my ass, its almost never the case, its rather one of above.
Thats why they always go for desperate people, who they manipulate, extort, threaten to harm families etc. Normal balanced well off folks have no business with such, you can only lose.
People become moles for the greater good, usually, or protection. Sometimes it works out, sometimes not.
For example, rumours in the grapevine suggest that by 2013 all the efforts of the various agencies combined managed to plant a grand total of 1 mole into the State Council of China.
That's after 40 years of trying since the CIA office in Beijing was established, and likely hundreds of billions spent trying to secure promotions, favours, pay bribes, etc. Allegedly, the CIA had kept index cards on every prospective career official in China, and the filing cabinets took up a football pitch of floorspace.
This amounted to nothing pretty soon after, which would explain the geopolitical movements since.
Doesn't this describe all armed forces, everywhere, ever?
And that the reason it doesn't is because everyone involved has to constantly leak and brag all their confidential secrets out in the open so they will be considered hireable by other agencies tasked with secret-keeping?
Have I read that right?
If the internet knew, it wouldn’t be an elite op anymore.
One of them was arrested this year here in Norway.
Not to justify the CIA or anything, but that's exactly where I would most expect them to be actively conducting covert operations
The resulting military dictatorship was immediately recognised by the US and was responsible for innumerable human rights abuses until it fell in 1985.
This dictatorship and the US support for it is one of the main reasons that Brazil remains suspicious of the US and a primary driver behind it's continuing courtship of Russia and China.
I can understand the desire to gather intelligence from every other nation, even allies. But I do believe it's a bad idea. E.g. Brazil seems to be aligning with China more and more... largely economic driven. But no need to also give it political backing.
Intelligence agencies primarily spy on 'allies'. The biggest spy rings in the US are our "allies" - british, canadian, israeli, japanese, korean, etc. The biggest spy rings the soviet union had were in poland, ukraine, hungary, etc - aka their "allies". We have an infinitely larger spy ring in south korea than in north korea because holding onto an "ally" like south korea is far more important than converting an "enemy" like north korea.
It's why we demanded all our "allies" stop using huwaei tech because it would prevent us from spying on our allies. It wasn't about china spying on our "allies". Who cares about that? It's about our ability to spy on them.
The naive watch silly hollywood movies and think that's reality. Most of the spying during the cold war wasn't between the US and Soviet Union. It was mostly between warsaw pact "allies" and between NATO "allies".
> Brazil seems to be aligning with China more and more...
They should. Brazil's enemy is the US, not China. Might want to read up on the Monroe Doctrine. Think about it. The country that wants to keep brazil in check isn't china. It's the US. If Brazil has ambitions of being a major power, then it makes them our enemy and vice versa.
https://www.reuters.com/investigates/special-report/usa-spie...
With a bit of reverse engineering, I'm sure we'd be able to get a mockup of the JavaScript ones running however: https://cirosantilli.com/cia-2010-covert-communication-websi... But in the end, it's just going to be some kind of "click something, a box opens, you type, it encrypts and sends a POST request.".
The main interest of reverse engineering to me would be to possibly find some searchable fingerprint that we could use to find more of the websites.
I see that later on you switch to "we".
JFYI, there are a couple typos I could spot, "pubic" and "lits".
We includes me, and if at some point others might contribute. So when it's not something I did specifically, I tend to we.
Typos: fixed now and some others, thanks. Feel free to send any others. "Pubic" one was epic. Vim sometimes forgets to turn on spellcheck.
If both sides are educated and trained, you can do things like hiding messages in quasi-randomly selected posts on Hacker News; but that quickly breaks down if one side doesn't have the skillset needed to hide their actions that way.
Things like TOR can help, but that can be difficult to completely hide, and so on.
I think stuff like TOR are actively harmful to a site like the CIA is trying to run.
Accessing TOR would make you light up like a Christmas tree, it's a much harder problem to solve without TOR (as the CIA tried).
> It's interesting to consider "how would you build it better" - especially when you realize that half of the equation is trained, educated, and safely in America, the other half is potentially anyone in the world anywhere.
Randomising the structure and sanitising the element names (not having password in them) would probably go a long way. It seems like it wasn't designed with a large amount of OPSEC in mind to be honest.
I wonder what the "bandwidth breakdown" of various traffic types is, and which ones average Tor usage would be comparable to. Could you encapsulate a Tor session in a Youtube video (with cooperation from Google)? Or would that be noticeable because Youtube is 99/1 and Tor is 80/20?
But I tend to agree, for single agent TOR is probably a bad tradeoff, I suspect the intended use case of TOR is likely more about larger groups like opposition movements or rebel groups
Creating these one-off websites was easy but also pretty easy to track once detected, since virtually no one visited the fake sites (and they re-used unique components). Since the NSA and their "Five Eyes" partners tap into the global internet at so many points for "full take" feeds, it seems like it should be possible to devise a passive approach that monitors seemingly normal interactions with legit high-traffic sites. Just combining commercial browser fingerprinting and broad geolocation with certain patterns of behavior, like visiting a few particular sites in sequence, should be enough to identify the asset trying to make contact. Then the asset's subsequent connection to a different unrelated (and equally legit) site could be taken over by a MITM-style interception.
I'm assuming here the NSA can gain sufficient certificate access for some major sites either surreptitiously or by gaining certain corporate employee's cooperation. Once the NSA has stepped into the online transaction with the legit site, it serves up slightly modified pass-through data from the real site to the asset. While more work to set up, it seems something along those lines would be virtually impossible to detect via bulk monitoring, especially if, at the end of each communication session, the asset is given a different ID behavior sequence to use for the next contact. Thus, there's no repeating behavior pattern statistically different enough to stand out.
The ideal communication mechanism is one that blends in with a huge number of other "legitimate" users. E.g. for Tor, it only works if many people are also using Tor for other non-spy things. I wonder why not just email.
Email has many problems but may be better than most, but you need to use something like gmail which everyone is using, and even that may be noticeable.
Once they suspect you, you're pretty much done for unless you find out that you're on the list and you stop communicating outbound. It's much harder to track one-way broadcast communications (many still think that there are/were communications to spies hidden in BBC shortwave broadcasts, and numbers stations are still a thing).
<span class="age" title="2023-06-11T12:31:28">
<a href="item?id=36280770">22 minutes ago</a>
so —in principle— the minutes field could be used to provide a very low bandwidth covert channel on top of innocuous commentary. Wouldn't it be pretty difficult to pick up even an outbound one-if-by-land two-if-by-sea style communication from the general noise floor?The first part seems true, but the second part doesn’t follow. Spying on allies seems an entirely reasonable, possibly even necessary, part of effective diplomacy.
I trust what you are saying more when I can verify congruence with things I can observe.
Many Brazilians are deeply distrustful of the USA, and are even willing to align themselves with dictatorships. Personally, I'll never support a dictatorship. But many people will just to have an alternative world power pole.
Alliances are like friendships. If you spy one your friends, of course they are going to get mad and push you away. We have instead to make opt-in intelligence sharing programs with our allies.
Even if you try to keep it on the down-low, it makes it really easy for a third country to drive a wedge in the relationship.
Free countries have the greatest need to properly "educate" the population that it's all just prudent and good, actually -- and the US has done an excellent job at that.
Is there a log of who instigated a wayback archive? Could they have been a different group doing what this person was?
>Given that we cannot rule out ongoing risks to CIA employees or assets, we are not publishing full technical details regarding our process of mapping out the network at this time
I guess it's a hard thing to rule out, but I certainly hope the CIA isn't still using a communication method broken more than a decade ago.
You can request it to archive a page at a time, but for many things it will have already found it.
Yes, IA now has a "About this capture" popdown at the far right of the injected toolbar. The first ever capture and some of the subsequent captures for one of the sites was from Alexa Crawls, provided by Alexa Internet; some later captures were from a "Survey Crawl" based on "a list of every host in the wayback machine". So this is basically automated, long-tail vacuum cleaning work.
Thanks to both people that cleared up my mistake, it has always seemed they had much stronger coverage than they should for my mistaken view of how it worked.
https://www.reuters.com/investigates/special-report/usa-spie...
Great article, it’s a shame that they don’t offer any more assistance to burned informants
Is wakatime ran by three letter agencies?
According to https://tools.whoisxmlapi.com/whois-history-search the domains were registered June 11, 2023, shortly after my article came out.
They are therefore likely just made by wakatime's founder Alan Hamlett: https://www.linkedin.com/in/alanhamlett/ as a bit of Guerrilla Marketing. Fair play.
When I saw on LinkedIn that he worked for a web security contractor until September 2013, I almost flipped. But appears unrelated however unfortunately except for his general interst in WEBSEC, so another dead end.
Conspiracy thinking: Example?