Formerly Top Secret NSA Cryptologs From 1974-1997
nsa.gov
nsa.gov
https://www.nsa.gov/public_info/_files/cryptologs/cryptolog_...
"In today's Age, the public has centered in on government as "the problem." Specifically, the focus is on the potential abuse of the Government's applications of this new information technology that will result in an invasion of personal privacy. For us, this is difficult to understand. We are "the government," and we have no interest in invading the personal privacy of U.S. citizens."
This attitude is similar to Bill Binney's (in that U.S. citizens are off-limits due to FISA)[1]. I presume he wasn't the only person within the NSA who felt like that…and I can't help but wonder what the internal dialog is like these days.
1: http://www.newyorker.com/reporting/2011/05/23/110523fa_fact_...
That is interesting. That may be true for the people who made that statement, though it's hard to guarantee it for anyone who has ever or will ever have access to NSA information. You don't have to believe in a nefarious Big Brother to be concerned about the perhaps inevitable potential for mistakes or abuse by some individuals behind "Government's applications of new information technology". History offers plenty of examples, after all.
So how do they end up sucking up tons of data from all over the internet, filtering and storing it (which includes private data of US citizens) -- easy, it is justified as fighting terrorism and protecting our country.
There is a story one needs to tell oneself continuously in order to maintain and support this brainwashing. These are stories that NSA tells itself (public is concerned but they have nothing to worry, we know we don't want to harm them, we are here to protect them).
Pretty sure if you asked those who conducted tortured at the CIA, they'd also tell you they are devout patriots and did what the did to protect the Country, the Constitution, the Flag and everything that stands behind it.
Did you work in HR at NSA/CIA or is this how you guess things work?
The background investigation helps determine the applicant's honesty, trustworthiness, reliability, discretion, and unquestioned loyalty to the United States.
unquestioned loyalty to the United States.
As soon as one stops questioning ones reasoning gets selective and biased.
> The students had to learn decades of classified cryptologic mathematics in two weeks, as well as a myriad of details about the four problems presented to them. During these two weeks, some learned to program for the first time. All were proficient programmers by the end of the summer.
> Incredibly, before they met us, two of our DSP students, juniors, had not been planning to go on to graduate school following their senior year. These two were performing exceptionally well in their current, demaning academic programs and, ironically, made the most direct contributions to the most significant results of the workshop. One went home from the DSP with a surge of confidence, applied to all the top graduate schools and is now in a Ph.D. program on a fellowship. The other wished to become an NSA employee, but we talked her out of joining us right away. She took all pure mathematics courses her senior year and is now in graduate school in a Ph.D. program on a fellowship.
It'd be fascinating to know what they're working on now.
(Vol. XX, No. 1 - 1st Issue 1994, #126 on the list)
They're almost certainly not working with technology that's "ahead by 10 years", as their recruiters like to advertise: Their hardware is basically standard stuff shipped by Sun (... I guess that's Oracle now), running mostly Java.
what's in them. I think that
████████████████████████████████████████████████
████████████████████████████████████████████████
████████████████████████████████████████████████
███████████████████████. Would that just make my day!
"An Example of Intelligence Community Synergy"
[four blank pages]
https://www.nsa.gov/public_info/_files/cryptologs/cryptolog_...
http://www.theonion.com/articles/cia-realizes-its-been-using...
A word that has been assigned a classification and a
classified meaning to safeguard intentions and
information regarding a classified plan or operation.
That is to say, the meaning of a code word is generally classified. It's not just a convenient label; its purpose is to obfuscate even the general intent behind . . . whatever's going on under that umbrella.If they think it's been compromised--that is, if they think someone has figured out UMBRA=COMINT--they'll generally change it. If it's made it all the way onto Wikipedia, they probably changed it long ago. And if it isn't redacted in declassified materials, they definitely changed it long ago.
Though it's always possible that they just don't care anymore. Sometimes programs persist under their code words long after what they're doing isn't classified anymore.
"We in the intelligence community have become accustomed to holding a monopoly on useful advanced cryptologic knowledge, so it is with surprise and apprehension that we have witnessed in recent years an increasing interest in cryptology on the part of American academicians."
You could at least estimate the length in characters of the blacked-out text. For a monospaced font this character count is trivial; for a proportionately-spaced font it'd be a little harder but you have lots of other non-censored characters to learn from.
There was a released-but-redacted CIA memo saying, "An Egyptian Islamic Jihad (EIJ) operative told an XXXXXXXX service at the same time..." From analysis of the size and shape of the blob, the missing text could only be "Egyptian".
In fact, a monospace font turns out to be harder for this; with a proportional font, as here, there is more variability in total word length due to the different letter widths, and so a greater ability to reduce the number of possible matches.
https://www.nsa.gov/public_info/_files/cryptologs/cryptolog_...
https://www.nsa.gov/public_info/_files/cryptologs/cryptolog_...
Page 33, Book Review "Rapid Development" by Steve McConnell. A "top secret" book review now sees the light of day!
edit: The introduction mentions some predecessor magazines targeted to specific groups. "Dragonseeds" to B group, "Keyword" to G group, "QRL" to language, "Command" to traffic analysis and special research. I wonder if anyone has FOIA'd these earlier publications?
Think of it from web development perspective. Years ago SSL were used only for financial transactions, then for e-commerce transactions. Nowadays it's considered a good practice to use it anywhere you transfer any user data or session. Isn't that our industry's equivalent of their over-classification routine? I think they basically do the same what we do with SSL - they apply their security layer to all content produced by all their users. It's exactly what we do with our security layers in software development.
It seems to me that the key difference here would be that no one is harmed by overuse of SSL, whereas over classification of information can have far-reaching negative effects. Failure by the intelligence community to realize such, or a systemic issue that incentivizes over classification, lead to our current situation where a FOIA is required to read a parking ticket.
Serving everything over SSL has removed HTTP's whole notion of "caching proxies." Now a website can be cached by your browser, or by the remote (i.e. through a CDN which they'll hand their X.509 cert to), but never by, say, your ISP.
And this is a shame, because HTTP's method idempotency semantics and Expire headers allowed intermediary caching to work perfectly--when something was set to expire from your local cache, it would also expire from any intermediary caches at the same time.
Sadly, some ISPs overreached and started modifying the content they proxied, at which point SSL-everything became the clear winner. Additionally, that kind of caching kind of screws things up when you serve any HTML that has been customized per-user on a generic cacheable endpoint (say "GET /timeline")--even though proper HATEOAS strongly indicates against this.
I think it's reasonable to neglect the time cost of SSL in this comparison.
Anyone stumbled upon Untangling the Web? It's a DOD "book" about web search, classified, remarkably interesting and nothing warranting being classified. I'm sure NSA has tons of actually interesting stuff they could make public
And the reason it hasn't all be declassified with a blanket order is no doubt simple bureaucratic conservatism. No one is going to get an award for "brilliant work in declassification", and the last thing any spook wants for her career is to be yelled at for declassifying something embarrassing.
Same goes for technology. What was done 40 years ago may not directly apply, but it might give clues to what's around today.
Seth Finkelstein
http://grep.law.harvard.edu/article.pl?sid=03/12/16/0526234&...
The habits of anyone working in any kind of role involving information security are so utterly obvious that they barely require discussion.
You make sure your office environment is secured, don't leave papers on your desk. Don't duplicate information more than necessary. Full disk encrypt everything. Never email documents without encryption. Don't use USB sticks without encryption. Know who you're talking to on the phone. Don't ever talk about incidents, jobs or the specifics of what you do.
Now think about people who reflexively do all this stuff and consider: a) how strong the urge to classify by default is and b) how much more work it takes to be 100% sure a document is safe for release.
What's the difference between reflexively classifying everything as highly as you can, and routinely covering up inefficiency and waste, and maybe a little graft on the side? Pretty much nothing.
https://www.nsa.gov/public_info/_files/cryptologs/cryptolog_...
"Writing for a competition may bring about revolutionary changes!"