NSA finds Snowden hijacked officials’ logins
arstechnica.com
arstechnica.com
Thats a bit hyperbolic and out of touch with reality. Sure I as a sysadmin with root to most UNIX machines in my companies environment could have been able to copy the raw Oracle db files to steal company secrets, SAP databases for other juicy data that I could sell to a competitor, run a network sniffer on important login servers to steal passwords, that is how the real world works. If anyone believes that you can totally lock down access to every system on your network from your trusted sysadmins and have 100% audibility and accountability you are unfortunately living in a fantasy land. NSA or not, this really isn't something that is 100% preventable.
It should be pretty basic to catch someone that's resetting user's passwords.
(Having sid that, I wonder how many people have patents or patent applications in for that idea right now?)
1] Do you log every single thing that happens on the machine?
2] If not, did you actually log the proper set of commands that were used to possibly commit a crime?
3] Granted you are not a small startup, do you have a process in place already to data mine, extract and analyze these potentially dangerous commands from log sets that are potentially TB in size?
4] Do you have the personnel in place with the qualifications and time each day/week/month to audit these potentially large results?
5] If you've caught something, aren't you already too late? Do you have some type of magical software in place that will somehow recognize these types of crimes in progress and cut off access in realtime?
Many of these articles totally ignore how these real world systems work (mainly I'm guessing because the authors have never been involved with companies that run 10k-200k servers around the world). It really is more complex than you think. Most companies that aren't startup size are continually playing catch up. Sure they need to put logging in place, auditing, yada yada. That is being balanced with the other day to day pressing tasks also. It always seems to be a game of catch up...
Do you have infrastructure in place to store all of that? How are you storing all of this content coherently so that you can go back and audit records of systems at a point in time you are concerned about? Do you have an internal Hadoop cluster configured (not trivial) and the hardware to ingest and process these logs? How are you actually logging everything? Do you have dedicated and qualified people to write this software and maintain it? When someone has su -'d to root, how are you logging everything they type coherently? Is your regex smart enough to ingest and contextualize multiline commands as root and add them to your report? What if no actual "bad" commands on your list were typed as root? What if I as a luser copied the "bad" commands to /tmp/kittens.txt, then su -'d to root and ran them there? Is this somehow captured? Are you 100% sure syslog is running 100% of the time on all hosts you are concerned about? Can't I as a sysadmin kill the syslog pid before I commit a crime? Are you using redundant syslog hosts? Are you using TCP and not the default UDP so that syslog doesn't drop packets under load?
Like I said, this isn't as simple as everyone thinks...
So I don't think your "do you have the infrastructure" argument holds too much water here.
The "do you have internal Hadoop clusters" question falls the same way. Sure, I don't have that connected to my 8TB of external USB drives plugged into my media server - but if I worked at Google or FaceBook or Twitter, I'd fully expect to be able to provision and spin up adequately sized clusters of VMs and storage to effectively consume and run reports on data that size and bigger. And it's surely not just the NSA and Google/Facebook/Twitter routinely dealing with collecting and processing data at that scale - any decent sized telco, any non-trivial web analytics service, any large financial institution, every HFT business, most bio-med businesses, probably every physics and astronomy department at any university – there must be tens of thousands of businesses routinely dealing with that sort of sized data sets.
It's not simple - certainly not simple enough for me to do it on a Mac Mini and a bunch of external hard drives – but I also don't think it's anything like "uncharted waters" territory. (I'm pretty sure I could find the expertise required in my 1st level LinkedIn connections, and have absolutely no doubt I'd be able to manage designing, developing and deploying exactly such a system if someone came to me with a high six or low seven figure budget.)
I also agree with the parent. There are so many possible scenarios and things to log that eventually you're playing a "logging" version of whack-a-mole. Even just managing these files (as the parent talks about) is really no trivial task. Honestly, I wouldn't even know how to begin managing a petabyte worth of daily data.
Second, I don't think anyone thinks it's totally trivial. But, this is the NSA we're discussing. Supposedly, their secrets are so special, the USA will collapse or something if they're compromised. If any organization in the world is set to handle an admin resetting people's passwords, it's the NSA.
Are you really arguing that it's just too hard for the NSA to notice a massive violation of policy?
The people you trust to admin systems are going to easily be able to abuse their power and it is very hard to stop them from doing so, without making their job so cumbersome for it to be near impossible.
[1] http://www.xceedium.com/solutions/privileged-identity-manage...
1+2) You could catch a decent portion of this type of behaviour with a tiny fraction of the effort. Logging local activity on individual user desktops is a waste of time, for example. Raising the difficulty of doing things undetected raises the bar significantly, particularly if users don't know exactly what's going to trip an alarm somewhere and get them caught.
3+4) Considering the nature of their work, I'd expect the NSA to be the right people for this with existing processes, suitable personnel and the storage/processing power required. It's their job to intercept and analyse large quantities of network traffic.
5) There was a period of around a year end-to-end in Snowden's case, and was in contact with The Guardian months before leaving the US (http://www.reuters.com/article/2013/08/15/us-usa-security-sn...).
Yes, it's a difficult problem (and impossible to comprehensively solve, doubly so when you don't trust administrator-level users), but when you're dealing with classified information in government, security is more important than in a regular commercial context.
If anything, the lack of decent internal auditing at the NSA is probably intentional.
I was required to manually go through each 24-hour output with a highlighter and look for attacks....
This was not a fun part of my job.
They would be required to report on any strange activity they see from the other administrator(s).
Extremely inefficient, but it's far more secure than just allowing any administrator to do what they want with stuff.
So leaks payoff twice -- once in direct transparency, and again by damaging the ability of the organization to act.
http://cryptome.org/0002/ja-conspiracies.pdf
The more secretive or unjust an organization is, the more leaks induce
fear and paranoia in its leadership and planning coterie. This must
result in minimization of efficient internal communications
mechanisms (an increase in cognitive "secrecy tax") and consequent
system-wide cognitive decline resulting in decreased ability
to hold onto power as the environment demands adaption.Here is an example placard from a Titan II site:
http://www.flickr.com/photos/mattblaze/4182509642/
(By Matt Blaze)
Not a bad concept. But your accountabil-a-buddy has to be at the same level as you technically. One can easily fool or mislead non-technical people. "Q: What are you doing?" "A: Rebooting the flux capacitor"
My experiences with such processes is that unless you can have some sort of technical measure that proves both people are actually paying active attention to what is being done, the second person will often just zone out. Sometimes, if asked even a few hours later, they won't even have a clear recollection of the event taking place, much less what was actually done.
But really, you are going to lay off 90% of the sysadmins and require two different people involved to change a password?
What this shows is if anything how much you need a combination of good monitoring and enough people. And once one account is compromised you have a chance for the sysadmin to be using sock puppets for accountability actions.
A /huge/ part of managing systems is vetting the folks who must be completely trusted. As part of this, you want to reduce the number of people you trust 100%, but yeah, some still exist.
Those people you trust 100%? you must vet them carefully. You should not put some random contractor in that position. Clearly, as Regan would say, "mistakes were made" - and nobody seems to be taking responsibility.
Just keeping the secret data on a secured server that only a few, very highly vetted sysadmins had root access to, that carefully logged all requests for information (and set off a pager somewhere if too many unscheduled requests were made) would have solved the problem, assuming you didn't hire some random body shop to staff /those/ sysadmins.
I mean hell, I get paged sometimes because some fuckwit at one of my upstreams starts bouncing my packets that are traveling from san jose to sacramento through texas. Surely, someone could be woken up if someone starts accessing suspicious amounts of data at once.
This is part of the huge "who you know" factor in the valley; Generally speaking, you hire folks that your current folks know. Not only does this provide some technical validation, it also makes the cost of defection higher. (Of course, there are lots of downsides to that approach, too.)
But no matter how you do your vetting, you /must/ vet folks with root.
And you can (and should) reduce the number of folks with full root. Especially when there is sensitive data on hand. Give your contractors limited tools.
The problem with that theory is that you're assuming only some data is secret. Actually, all the data is secret. Even the information about which data is secret, or what are the criteria of secret data, or how secret data should be handled. Everything is secret.
So rather than dealing with a neat pack of documents that you want to keep secret, think of an organisation with 100k+ people where every single bit of data they produce or interact with every single day is top secret.
> He wasn't just a community college stooge, he was brilliant! The obscure flaw that he exploited has since been fixed, hooray too!
Meanwhile 'sudo su' has been criminalized as a precaution.
sudoedit (according to the manpage) makes a copy of the file first, lets your editor edit it, then copies back when you're done -- so even a compromised editor couldn't do much damage beyond corrupting the given file.
1) Some government agency builds massive computer system containing lots of information about the general public.
2) There are numerous obvious holes in the "massive" computer system for obvious reasons (government's haste, lack of oversight, etc).
3) The government's computers get hacked.
In my opinion, numbers two and three are inevitable when number one takes place.
Something similar just happened in Canada a few years ago with all of our driving information: http://www.huffingtonpost.ca/2012/11/06/service-ontario-kios...
Something like that would be grounds for a complete loss of trust in my books.
The only way to prevent it is to not store data.
I'm not trying to be pedantic, I'm just saying, it's not mathematically impossible to crack a salted encryption without the cipher key.
There is always more than one way to skin a cat.
0) Your personal hardware has lots of holes in it. which changes the equation quite a bit, doesn't it?
I don't really know what you're getting at with this comment.
The answer is that it is much easier for black bag operations to be scrubbed from potential oversight when an individual holds the power to run the hidden|illegal analysis and clean their own log trails.
See: http://en.wikipedia.org/wiki/Randal_L._Schwartz
(Note: all 3 felony convictions were "expunged" eventually, but for 12 years he had all the restrictions and problems a convicted felon lives with, all for "doing his job", or possibly "overstepping the bounds of his authority while doing his job".)
Describing how Bradley Manning using 'wget' was considered computer fraud because it was not on the list of approved programs.
trawl?
Took me a while to figure out the humour inherent in the double meaning when I first came across it (in the 90s)
e.g., you might trawl for prawns but troll for snook.
I just assumed that with an american accent the words sounded the same so people stopped using 'trawl'... I've been wrong before though.
1. Snowden impersonated NSA officials, sources say
2. Edward Snowden accessed some secret national security documents by assuming the electronic identities of top NSA officials
3. forensic investigation has included trying to figure out which higher level officials Snowden impersonated
4. if an employee was on vacation while the on-line version of the employee was downloading a classified document, it might indicate that someone assumed the employee’s identity
5. NSA has already identified several instances where Snowden borrowed someone else’s user profile to access documents
6. “The damage, on a scale of 1 to 10, is a 12,” said a former intelligence official.
7. The NSA declined to comment <--- WTF, then who are the above sources?
[Edit: I wanted to add a little bit of clarity here: the language used is very vague and references things that could never possible be confirmed: sources say, "might indicate", "has identified" --- This story is like a bunch of paragraphs typed out, randomly put into a hat then shaken onto the floor into the pattern of the story. It is not a decisive, cohesive piece of information -- then it is ended saying that the NSA has no comment.
THe TITLE is "NSA finds Snowden hijacked officials’ logins" NSA FINDS....
So, if the NSA doesn't comment - and the "analysis by NBC" and the NSA declines to comment are all used -- then NOTHING in this piece can be believed.
Even if the entire premise is true - this is hands down the worst framing of the information, supposedly factual, one could imagine!
---
In my informed IT professional opinion, they are using this to brand him a hacker - and they make a bunch of "what if" type claims. Then they slide into a confirmed report. Then they claim the damage is off the scale (12 on a scale of 1-10)
This is a completely MISO built PR piece for the NSA.
As administrator on any system (administrator in Windows, and Root in *nix) one will have access to whatever you want.
Whilst at lockheed, I had admin rights to every machine and document in my realm - I would have had no need to "impersonate" any other lockheed employee...
The mistake here is if NSA was using the same root passwords/keys across entire tiers of machines. In that case - call it criminal negligence on the part of whomever architected that disaster.
But, yes - it is pretty clear that they have the MSM on their freaking sqwak-box right now against Snowden.
Funny how it was also revealed that they (the UK) were lying about being "leaked" info from Snowden to the "Independent" -- where Snowden came out and said he never communicated to them anything, and the "leak" was a lie and information that Snowden was specifically avoiding getting out because it was too pointed at actual personnel...
This info needs to KEEP COMING -- as we need to get to a tipping point where change is a reality.
Maybe the "media exploitation" is what you mentioned in your original post; in effect, "NSA officials", "sources inside the NSA", etc. all "anonymously" making off-the-record comments to journalists.
If the biggest story in the history of the NSA is that some college drop-out "genius" was able to exfiltrate 20,000 docs from the NSA - and the biggest key argument they have against the guy, to prove that he were some "hacker" who was impersonating people to gain access to said files -- how is it that "NBC" is revealing this with "sources say" "an official" etc...
Don't you think that the most critical point to the credibility of the NSA is to come out and state via an official means - that they have electronic logs of this activity?
Digital forensics are binary: Either you have a digital trace of actions taken, or you do not. Period.
Either they can determine 100% that Snowden logged into station X as person Y to grab file Z -- or they do not.
THe language used in this article is textbook MISO/Psyop PR.
"Oh, an official source with knowledge of the incident has said.." -- cool, I guess they have it figured out then, huh! I shouldn't dare question that. But if I do: "We can't comment" "we cannot reveal the details of an ongoing investigation" etc...
Utter crap.
If Bradley Manning got what he did for scary wget wizardry (making no statement about the validity of that charge or verdict) then I think Snowden can safely expect more consecutive life sentences than he has fingers and toes.
They're really non-specific about what he did (and play it off like he couldn't do anything), but it's coming across more & more like he really had his crap together.