US doesn't know what Snowden took, sources say
investigations.nbcnews.com
investigations.nbcnews.com
Wow. The NSA spent untold billions building advanced tech to snoop others but never bothered to set up proper internal controls for their own systems?
Of course this also raises the question, how can they continue to insist that there are reasonable controls in place to prevent abuse when they can't even determine what Snowden accessed, after he collected thousands of documents over a span of years?
Assuming, that is, the system was set up that way in the first place. Which is such a PITA that I totally believe they just skipped it.
The system they use is not really broken, it's just embarrassing to them when it's proven imperfect. The best fix would be to simply avoid doing things that are likely to piss off ethical people like Snowden.
It's rather unimpressive to claim that you can tell a customer that "your sysadmin had authorized access to all data, so any of it could have been copied".
It's rather embarrassing have your IT supplier tell you "This other person who you trusted with access to all your data may have copied some or all of it -- you should trust your employees more granularly."
(USB ports / CDs being what failed in the Bradley Manning case)
Theoretically it's trivial to audit sysadmins. In practice it's virtually impossible. Let me know when Red Hat wants to bet money on it.
The real issue is who cares about this (the information collected)
I've seen this with "limited administrators" where they were audited by senior people.
But there's always a point from where the trust is "absolute"
One that leaked to the public (Blew a Whistle). This in no way precludes previous leaks from leaking to
a) Foreign Governments b) Businesses c) for Extortion purposes d) Personal use.
And you can definitely control what access system admins have to your system. Not every person who joins workstations to a domain needs to have full domain permissions.
This kind of sloppy authorization and system state control is inexcusable.
His actions have probably made their jobs more difficult, but they also work with these same systems, have a sense of their scope, and know the extent to which internal controls are (apparently) more procedural than technical. I wonder how many secretly feel vindicated for some concern they have felt or expressed in the past.
It sounds like there are cloud services providers that are doing a better job at this today than the NSA. And we're supposed to trust them with their audit controls?
P.S. My undergraduate thesis in 1990 designed a symmetric key system that would allow data at rest to be encrypted, such that access could be controlled (and logged) via single key server system in which you invested all of your trust. This is not rocket science...
Now, a big concern is that even if they do audit access to the wiretap data, there are still too many people who have "legitimate" access to it, and it is still hard to prevent a rogue sysadmin or programmer from bypassing those controls. Merely having all of that data makes it a high value target for attack.
This will clearly be NSA's response -- whether it's true or not -- but Snowden didn't just take random PowerPoints and internal training docs. If I'm not mistaken, he also took copies of FISA court documents and other highly classified materials that were never intended to be shared among NSA staff.
I truly believe the lack of audits for these materials has destroyed NSA's credibility across the board:
1. We know that NSA hires/contracts incredibly smart and technically talented individuals who are experts at breaking into systems and avoiding detection.
2. The only way for NSA to provide reasonable controls in this environment is to create a culture of monitoring and accountability, and design all their systems from the ground up with auditing and security in mind.
3. But apparently they didn't do #2 (or never figured out how to enforce this for sysadmins), because Snowden repeatedly accessed restricted and highly classified material without an audit trail.
I don't see how they can credibly admit a Snowden sized failure but still ask us to trust them with our personal data.
I guess they haven't solved the problem technically yet as they have instituted "no lone zones" policy. They'll just have everyone work with an accountabil-a-buddy.
However, if NSA contractors are put under the same Federal Desktop Core Configuration requirements [0] at a minimum, I would imagine the client and/or server (if he was required to use Windows) are known, or the NSA contractors are not in compliance.
What they do with that information is another story. That said, any admin could change local policy settings, reboot with the computer, and reconnect it to the domain later. I got clever with such things to disable security policies like those when troubleshooting lab computers. We shall never know how smart/dumb Snowden was and they were.
Maybe Snowden's error is doing the right thing as opposed to making a few Renminbi.
Oh no, not a "thin clinet"!!!
"Set the Command and control server to engineer a virus to backdoor the system return code with a thin client."
"... oh no, not a thin client!"