NSA Implementing 'Two-Person' Rule To Stop The Next Edward Snowden
forbes.com
forbes.com
A better solution is to stop making your country one people want to escape from.
Or in the NSA's case, stop violating the Constitution, lying to Congress, etc so people don't feel compelled to blow the whistle.
Is it that hard to follow the Constitution?
I'm imagining an embedded spy with access to this data wouldn't have to work too hard to circumvent such seemingly honor-based access systems.
For starters, disable all USB ports other than on dedicated systems that are closely monitored. Then you can physically (with a guard at the door), verify that no data is copied out without a second person signing in with the person doing the copying, and signing out the data being copied. Add on electronic restrictions requiring acknowledgement from a second person, and regular audits of who takes out what, and it'd be a lot harder to get data out without finding someone to help you, knowingly or not.
There will always be workarounds, but you can at least make people put in more efforts into doing things that increases the chance they'll be noticed.
Damn right. What an insane situation. My (Soviet) Russian-born wife keeps saying, 'yeah, that's what they did in the USSR'
His former coworkers are going to be smart, American, and patriotic too. Some percentage of that class of people will have strong opinions about being complicit in borderline-Constitutional activities. Snowden was the first to come forward, but do you really think there isn't a significant pool of sympathizers still at NSA considering making a similar move?
Requiring cooperation between two analysts does raise the bar somewhat. But I think NSA would be making a mistake to assume that this is an isolated problem, with a tactical solution. I hope that the next guy (or pair) to come forward is as circumspect as Snowden seems to have been. Thank goodness Bradley Manning didn't work at NSA -- that scenario would have real consequences for the world, instead of the noisy internal (and important and necessary) squabbling we'll be doing for the next several months.
So the NSA needs to offshore that work to China in future
That will be the NSA's finest hour - firing people for stating that they support the US Constitution...
They got lucky, nothing more, that Snowden is a concerned citizen and not an actual spy. No single person should be able to do what Snowden did even if you assume all NSA analysts are 100% comfortable with the mission.
In nuclear weapons two-person concept is a huge, huge, huge deal. NSA's stuff might not be to the exact same level of seriousness but at the same time "TOP SECRET" implies grave risk to national security if leaked and their internal controls should have been equal to the risk implied by that.
http://au.businessinsider.com/edward-snowden-top-secret-clea...
Actually Snowden may have been the NSA's lucky break. Doesn't it seem likely that there are poeple selling secrets to enemies within NSA/Booz Hamilton? This forces them to deal with a system that probably makes that relatively easy.
Cherish your bugs.
"the fierce surveillance within the Stasi of its own men, of how in a case ... there might have be a dozen agents: everything was checked and cross-checked." http://www.guardian.co.uk/books/2007/may/05/featuresreviews....
The more secretive or unjust an organization is, the more leaks induce fear and paranoia in its leadership and planning coterie. This must result in minimization of efficient internal communications mechanisms (an increase in cognitive "secrecy tax") and consequent system-wide cognitive decline resulting in decreased ability to hold onto power as the environment demands adaption.
Hence in a world where leaking is easy, secretive or unjust systems are nonlinearly hit relative to open, just systems. Since unjust systems, by their nature induce opponents, and in many places barely have the upper hand, mass leaking leaves them exquisitely vulnerable to those who seek to replace them with more open forms of governance.
In other words, in an increasingly digital world, its gets easier and easier for large scale leaks to happen, and although you can take measures to try and stop that, overall those measures will damage your effectiveness even more. Some leaks are 'good' and some are 'bad', but over time, in a leaky world, the overall long term effect should be positive - a move towards more openness.
* its pretty obvious who, but I don't want to derail.
- Julian Assange, The Nonlinear Effects of Leaks on Unjust Systems of Governance
1. Did not know about this surveillance
2. Would not have voted for it to be put in place
3. Are (for the most part) angry that it happened
4. Must pay extra taxes so they can be sure to keep it secret next time
I've never been more pissed off about my government.
In fact, some of nation's largest taxpayers (in the black corporations) are actively cooperating in this endeavor, so making this about taxes would seem to argue that the "taxpayer" has already spoken.
You bring up a point (perhaps frivolously)that I haven't seen before. With many many minors owning cell phones, where does the court stand on collecting meta-data from children. The law is very clear when it comes to crimes on how minors are treated, this seems to make assumptions without guardian approval or regards to their status as minors.
I'm not trying to be rude to you as much as I am express my frustration about what the government's doing, but look, nothing about this was particularly legal (we can debate the legality of FISA warrants off-thread, I'm happy to).
Certainly any sort of whole-sale capturing of traffic or messages or pictures or calls could cause the government to be in possession of materials that they shouldn't, but that's really not saying a whole lot, now is it?
I don't even think about these gross violations of our Constitution to even be a "legal" matter. How can you? It's not like a court can rule against these laws. The ruling is just suppresssed.
Of course, they also have the option to say fear is worse, enact special complicated safeguards that filter out children, or any number of other weasel work-arounds. But it's something, at least.
First, who cares? Honestly, of all the things I'm upset about, pretty much the bottom of the list is "pictures from Tor get mirrored in an NSA facility". The "terrible" things about child porn come from it's production, distribution and sale. None of those things are happening by it getting picked up in a dragnet and put on a HD. No one's going to be motivated to stop the government over CP if they haven't over privacy.
Second, child porn is bad. But do we really have to take their bullshit strategy of "OHMHYGOD THE CHILDREN!?" when "OH MY GOD, ANY SENSE OF PRIVACY?" should suffice?
tltltl;dr: If a "legal technicality" were going to trip up the NSA, it ought to be the Fourth Amendment.
I completely agree that "the children" is a minor blip in the entire program, but it is a blip that has a lot of emotional response attached to it.
I again agree that current laws can't even compare to something of this scale. But laws about minors and their entrapment or protection might be enough to waken the laymen on this apparent abuse of power.
It's like paying attention to the speed limit while mowing down pedestrians in your car.
On the plus side, "think of the children" is usually something everyone can get behind, which is why it's rolled out so often :/
But launching nuclear missiles is a command decision so the weak point in the system is the means by which an order to launch is authenticated. And whatever secret tokens are used in that process, those I want as few people as possible to know (ideally zero).
But when even the policy is secret, it is totally beyond even the possibility of democratic control.
Jump forward to the modern day, when the details of the crash are accidentally released with a bunch of other declassified information. It turns out that the flight had absolutely nothing to do with "National Security", it was just a routine flight in a plane with a poor maintenance history. The government was just covering their asses to avoid paying out for wrongful deaths, and bullshit so hard they created a legal precedent.
The second saddest part of the story is that the person responsible for securing the biggest DWH of all time freely admits that they have no protection against rogue sysadmins, most of whom don't even work for the NSA.
If Snowden was the first to leak information, who was the first to sell it? The way Snowden describes the access seems like a joke.
If anything, a contractor is going to have additional vetting. As an employer, the federal government is bound by constitutional restrictions that private employers are not. For example suspicion-less drug testing is not a requirement for a clearance (affirmation that you haven't used illegal drugs is a requirement, but actual testing is not). However most private employers are all gung-ho on the drug testing front and do force employees to be tested to whatever level their local state laws permit (there is significant variance by state as to what a private employer can require).
A government employee might be getting paid by a third party whose interest diverge from the government's.
A government contractor is, by definition, getting paid by a third party whose interest diverge from the government's.
Whistleblowing, sure, generally. Espionage on behalf of a foreign power, probably; espionage on behalf of the company itself... heck, government contractors in non-security related fields not-infrequently expend considerable effort to gather non-public information about their current and potential employers and competitors.
Even then it isn't quite espionage that's the problem but simply working to steer more business their way - inside information on operations feeds into the lobbying arm of the contractor and the lobbyists convince congress to create or expand the work available for which the contractor has a high probability of winning the bid.
"The statement that a SINGLE analyst can eavesdrop on domestic communications without proper legal authorization is incorrect"
http://www.dni.gov/index.php/newsroom/press-releases/191-pre...
But really, I don't believe anything they say, or believe that I'm capable of figuring out the true meaning of the careful wording that they think they are using to 'technically' tell the truth while intentionally making everyone think they meant something else that was really a lie. I mean, Clapper has already admitted he lied to Congress, right?
"Collect" apparently has an intelligence-community meaning that's quite different to the regular dictionary definition - when the NSA says they don't "collect" data, what they seem to mean is that their computer systems intercept and archive that data, but that human analysts haven't (yet) looked at it.
In what other profession would you get away with making up a new definition of a word that's almost 100% opposite to the "regualar" meaning of that word, then using the word with your meaning when talking to the government? "Oh no, I didn't 'steal' that money - in the investment-banking-community, 'steal' means spending stolen money. I haven't spent any of that money yet- it's still sitting in my bank account - so no, I didn't steal any money."
The words italicized are qualifiers- that is they reduce the scope of the statement. It is uncertain that if you removed any one of those qualifiers the statement would still be true.
http://en.wikipedia.org/wiki/Dutch_Ruppersberger
Dear Maryland: Please vote intelligently at your next opportunity.
"In 2012 the district was found to be the eleventh least compact congressional district in the United States."
And a link to this article, which shows that district, and is titled "Maryland has least compact congressional districts in nation": http://marylandreporter.com/2012/10/03/maryland-has-least-co...
Now, in all fairness they do have a cragy coast, but it is very clear the districts are unconscionably gamed.
I'm not sure how it was done in the source for that news article, but gerrymandering-detection algorithms should ignore natural borders in that regard. See, for example, this paper which measures gerrymandering in terms of convexity: http://mathdl.maa.org/images/upload_library/22/Polya/Hodge20...
In short, gerrymandering, closed primaries, and private campaign finance form the Triangle of Doom. In combination, they provide the noose with which Congress is choking America to death. Abuse at the hands of the NSA (and their multi-billion dollar web of contractors) is just the latest, and perhaps the most chilling example of this phenomena.
Primary him. Primary him credibly. Primary him principally on this issue.
> * "We have to learn from these mistakes when they occur,” Representative Charlies Ruppersberger said to Alexander in the hearing. “What system are you or the director of national intelligence administration putting into place to make sure that if another person were to turn against his or her country we would have an alarm system that would not put us in this position?"*
So now the good Representative Ruppersberger is taking part in the automatic branding of Mr. Snowden as one who has turned against his country. For whistleblowing.
This is the wrong path.
After watching the USA Today interview with Binney, Drake, Weibe and Radack (http://www.usatoday.com/story/news/politics/2013/06/16/snowd...), Bachmann's demand and the language she used make me incandescent with rage.
I cannot get over the ignorance of the woman to be able to come out with something like that in good faith.
What makes you think she said it in good faith?
I mean, after watching the USA Today interview, it takes some pretty spectacular mental gymnastics to paint what Snowden has done as anything other than being in the public interest. Her constituents may be ill informed but she's a fucking member of congress for christ's sake.
Knowing the history of and present state of congress, I don't know why anyone would expect that.
Perhaps, but not always of sufficient moral character to, one they have the spotlight, not try to deflect attention away from the stark truth when that stark truth is hostile to their personal preferences.
But of course, this doesn't apply to the Government.
Why can't someone in power admit that surveillance has gotten out of bounds, maybe illegally, rather than devise ways to counter such divulgations?
Similarly with government workers. They don't care. They want a paycheck. It's not their fault, it's somebody else.
Until the government starts pointing fingers, nothing is going to happen.
We've been carefully coaxed into complacency.
Or, we rationally process the information we have and conclude that we're okay with the status quo.
While Julius Caesar's opponents called themselves "The Good", and were indeed the principle actors of the Roman Republic, the Roman Senate was also a homogenous bunch of rich assholes (nothing at all like our current Senate). Caesar was allied with a number of outsiders, including a number of liberated women, who felt oppressed by the old Republic.
That's not to say the Roman Empire was flowers and gummy bears, or would have been if Caesar had lived. Or that it was even better or could have been better than the Republic. But losing the oligarchical Republic wasn't necessarily that big a tragedy.
Rome, of course, had many occasions where the military was no longer willing to follow a rogue commander (the literal translation of Latin imperator, usually translated as emperor). So they kicked him out and installed a new one, in what we now call a coup d'état. The problem is, it turns out that militaries are not particularly good at determining which commanders are acting in accordance with the commonweal of the nation and which are not. The values you need to run a successful regiment are not the same values you need to run a successful country, and in many ways, they are opposite.
So I don't think that encouraging mutinies in the military really solves the problem.
When I first read it I felt a little like a snickering boy looking up dirty words in the dictionary, reading about failed institutions and government military and intelligence services as spun off corporations.
Now if you skim off the entertaining over-the-topness from the book, you have today. Booz Hamilton anyone? That program's never going away, there's too many jobs, billions, and lobbying money at stake.
Huh, that gives some idea as to the operational scale of NSA systems.
It's ironic how much we're learning about how the secretive NSA does things.... from public releases by the NSA themselves, in their attempts at PR damage control.
I think the current solution is to just trust that your sysadmin's career would be over if he/she took your data. Kind of doesn't work as well for stuff like this, though, considering the person who'd steal your data probably at this point doesn't care.
Don't mind me over here by myself, I'm not copying anything...
However, this scheme would seem to prevent previous "laptop leaks", so I think it's a good idea.
I'm sure some people do, but would imagine most don't. Most want a public overview of what they are doing and what rights they have, but understand that specifics/data need to stay secret.
For this to be the case, surely they do need to make sure security is as tight as possible. But on the flip side, if they were able to 100% prevent all leaks, it would mean that nothing like this could happen again, i.e. the kind of leaks that we want to see. So where should the line be drawn?
Why is it that everyone chooses to omit the most important thing about this new rule? It was designed especially to make sure the next Edward Snowden would have an accomplice when taking vac...fleeing to another country and would feel less homesick thanks to the presence of a fellow motherland-er.
I for one, welcome the attention and kindness of our new NSA overlords.
PS: Dear NSA agent reading this, I lost access to my old Yahoo! Mail account where I still have love letters sent by my ex-girlfriend and goth poetry I wrote when I was 18. Think you could help me? Thanks for your help! XOXO
What really happened:
Bob (via IM): Hey Mary, here's a change request link, can you hit 'approve' real quick? Mary: Done
I bet that some slightly more sophisticated version of this will happen with this new 'two-person' rule.
“What system are you or the director of national intelligence administration putting into place to make sure that if another person were to turn against his or her country we would have an alarm system that would not put us in this position?”
The thing is, Snowden didn't turn against his country. Snowden turned towards his country...and against the schnooks who were undermining it.
There's a balance here. There is danger in making it too hard for somebody with a conscience to use it to make things better. The fact that it took this long for the truth to get out suggests to me that the controls they already have in place (along with whatever social pressures surround them) might be fine or even a little too strict.
I've heard of high-security facilities prohibiting cameras, of any sort, so no cellphone to take pictures of the screen, either.
So the lesson is not how to prevent the NSA's domestic spying, but how to prevent getting caught?
While Snowden did have proper justifications and reasons for the exposure, the fact that he was able to is still not a good thing for the NSA isn't it? Someone else who might not have America's interest could do the same thing theoretically which is bad.
Since people working in groups never abuse their authority, this sounds like a foolproof plan.
;-)
Just like you can't get 100% security.
Truly yours,
Current NSA Chief, and future Booz Allen Hamilton CEO.
I guess with some right group policy settings, a TPM and BitLocker, you could get close maybe. Still going to be challenging to keep me from booting the machine, logging into it and catting that file... somewhere. Give me `wget` and a script and I could transmit data using only GETs.
You can't even access your own work computer without another person present.
It works. It's just extremely inefficient.
Of course, setting it up as a security measure would take rather more work.
That will leave a handful of system that do have external media. Those will have extreme access restrictions - at a minimum account restrictions and audit logs that will be regularly correlated with a hand-written log that contains timestamps and signatures of both people. They may even put the system in a room with keycard access that requires two different keycards and associated PINs to be entered before the door opens.
It goes without saying that their entire operational network is firewalled with an air-gap. If a user needs to have internet (or other extranet) access from the same desk as their operational network, they will have an entirely separate terminal for it, they may even have rules that require a minimum distance between the two terminals.
If you push decryption to the client (where it should be anyway, don't want plain text over the wires), then even with access to the data center, you cannot get the plaintext.
What I don't think pure crypto can get you is a quota on how much an individual can access.
Also, the fact that a single person can bypass whatever alarm systems they have means that if an external adversary gets root, they are undectable.
Sure, right, that's kinda what I implied with my post. As long as I have access to decrypted bytes in memory and I have access to: my eyeballs + pen + paper, then the jig is up.
The TPM+BitLocker scenario would protect the data on the hard disk and prevent offline attacks and would prevent someone from trying to extract the key from the running OS.
> the implied means of power, the threat of force, rather than by direct military force
Ding ding, exactly. That's why I mentioned "Group Policy". At best, you could attempt to restrict user access to the LIVE mounted decrypted data... but at that point you're trusting the client and a dedicated individual would get around it.
You'd almost need this:
Request remotely-stored invididual encrypted file -> Receive it locally -> Decrypt locally.
which would give you a chokepoint to be able to cut off access to the encrypted data, but there are a thousand problems with this scenario as well, just from a technical standpoint.
What is this quote?
>Request remotely-stored invididual encrypted file -> Receive it locally -> Decrypt locally.
Is there any reason you wouldn't want to do it this way. Aside from the security benifits of having the data be in plain text for as little as possible (and eliminates a centralized point of failure), this also offloads CPU resources to the local computer, which is a win from a purely efficiency standpoint as well.
Sigh, no idea how that slipped onto my clipboard. I was looking up a good "hegemony" definition for an unrelated discussion. Sorry about that. I meant to reference the line in your post, but it's not important.
>Is there any reason you wouldn't want to do it this way
Hm, so I didn't spend a ton of time thinking about it, but it doesn't seem conventional to me and thus I'm inclined to think there's probably something "bad" obviously... but I'm not sure.
It seems like it would be hard to have work "properly", in terms of actual day-to-day usage. For example, what if I really do need to access hundreds of 1GB files all day? Or a thousands of tiny files? Or one massive file? Etc.
Additionally, you'd lose any advantage of having plain-text on server, like potentially losing collaborative editting/viewing, etc.