It's Time to Break Up the NSA (2014)
schneier.com
schneier.com
Come to think of it, this NSA would probably also be responsible for chasing down companies who ask you for your SSN, wouldn't it?
They could also offer free pen-testing services (presumably through their defense subcontractors; they wouldn't have to employ any whitehats themselves) for small businesses who can't afford pen-testers, like a specialized form of industrial-development grant.
And, of course, they could also do the only legitimate/legal "active no-advance-notice" pen-testing for infrastructure they're concerned about (ISPs, hosts like AWS, etc.), converting taxpayer dollars directly into those "eyes that make bugs shallow."
Effectively, the NSA are to our sovereign data boundaries as the coast guard is to (most of) our physical ones. Since that's the case—where's our Lighthouse Service?
So you think making the NSA (or any govt agency) the gatekeeper for all data, public and private, would be a good idea? As if there's no way that could be abused? No thanks.
The one interesting thing is that this would likely enforce an open-core-SOA software development model: companies would be incentivized to build a "trust kernel" of services that the government regs apply to, exposing an API with stringent access controls; and then a view layer that consumes that API, which can have whatever sloppy code they wish. The trust kernel would then have to be at least shared-source to enable the peer review necessary for study. (The company couldn't just pass the code around within a cabal of trusted peer companies, since those peers might be unfairly positively-biased.)
Unfortunately, NIST has been dragging 140-3 in draft form on for years. 140-2 was written in the 1980's and reflects very badly on current hardware and software practices.
Another area you could look into is Common Criteria. I find these certifications to be much more modern.
I've taken products through both processes. If you're going for more than the basic levels they can be quite rigorous and thorough.
http://ec.europa.eu/justice/data-protection/bodies/authoriti...
e; well, not actually pen testing, but knowing what personal information companies store, and mandating minimum safekeeping measures and limits on sharing.
There is some merit to what you say, but I'd not use the FDA as a model. To me that sounds like a recipe for disaster, imagine the NSA auditing our software with FDA like cronyism and inefficiency? Green-light passes to be auctioned off to the highest bidder, and otherwise legitimate products will be hampered by woe-some delays. "Sorry, cant launch your new update until the NSA approves it."
For one, there has been little appreciable gain from this practice, but it's also way too easy for an adversary to subvert a backdoor planted for purposes of peeping around, and use it to do very serious damage. The more entrenched surveillance via cyberespionage becomes, the more it expands the attack surface for a foreign actor to exploit it.
Second, there is no guarantee at all that the NSA is impervious to the same sort of infiltration methods. If they become compromised themselves by a foreign hacking entity, then that's it for everyone they're "surveying".
"And third, the remainder of the NSA needs to be rebalanced so COMSEC (communications security) has priority over SIGINT (signals intelligence). Instead of working to deliberately weaken security for everyone, the NSA should work to improve security for everyone.
Computer and network security is hard, and we need the NSA's expertise to secure our social networks, business systems, computers, phones and critical infrastructure. Just recall the recent incidents of hacked accounts—from Target to Kickstarter. What once seemed occasional now seems routine. Any NSA work to secure our networks and infrastructure can be done openly—no secrecy required."
But yes, it's much smaller than their SIGINT wing, and yes, I also feel that having both teams under the same roof (so to speak) is not just an 'equities problem' - it's a full-scale irreconcilable conflict of interest.
You might feel that surely the NSA wouldn't backdoor their own stuff? But no: there they are, actually using Dual_EC_DRBG even in their own most trusted crypto hardware - in, I presume, the firm belief that "nobody but us" has the private key to use the backdoor. Which seems somewhat reckless in light of a working distinguisher and how very fragile (EC)DSA is… and a stark reminder of how the recent return to talk of backdoors - sorry, "front doors" or "secure golden keys", because they want to control the language to frame the debate in the way they want - are so much bullshit, and the only reasonable discussion we can have about things which undermine all of our collective security is one where the people who are asking for such idiotic things to - they think - make their jobs easier should kindly shut the fuck up.
Ahem.
GCHQ over here have the exact same issue with CESG and the MoD CRYPTO group versus the COMINT/ELINT/SIGINT bulk of their mission. GCHQ have even selected their own suppliers and political and other infrastructure for targeted surveillance in some cases! So for those who choose to try to work with them - surprise! - that doesn't mean they're not also working against you too. It just gives them another angle.
Title 10 explicitly disallows the NSA to proactively interfere (good or bad) with private industry services unless specifically requested by a law enforcement agency and in cases like you propose would have had to be requested by the private organization to the LEA in the first place.
And third, the remainder of the NSA needs to be rebalanced so COMSEC (communications security) has priority over SIGINT (signals intelligence). Instead of working to deliberately weaken security for everyone, the NSA should work to improve security for everyone.
The liberals will always be telling you that the drug war is a failure, and that drug users will be able to get their hands on drugs anyway, and we should embrace that fact so we can retain some level of control, and so otherwise innocent people don't have to interact with criminals. But guns on the other hand...
The conservatives will always be telling you that guns can't be controlled-- that criminals will get their hands on guns anyway and will conceal carry all the time, and that we're better off keeping them legal so we can retain some level of control, and so that innocent people don't have to be at a disadvantage to criminals. But drugs on the other hand...
I take this a level further: There's no containing cryptography. The people that are on tor looking at child pornography are protected. The people that are on tor plotting terrorist activities are also protected. The only people not protected are people that don't care or don't know, and they're not the people that are worth spying on in the first place.
The NSA internet data collection is perhaps the most frivolous government program in the history of the United States. We've spent god knows how much money building their Utah data center, and it will be useless as soon as the tech community starts encrypting. [1]
[1]: letsencrypt.org
http://www.cnet.com/news/nsa-working-on-quantum-computer-to-...
And now we have reports of the NSA developing dossiers of minor crimes and non-crimes of inconvenient people's behaviors for future use in discrediting them.
Is your suggestion that anyone who is (or may in the future) choose to be politically inconvenient should use strong encryption for everything even slightly unpopular they may do?
We can't contain cryptography, but neither can we depend on it being universally and effectively applied.
claimed he was having affairs. As you said he was politically inconvenient, why would I trust them?
If you care enough to explore the matter—although why you would consider it consequential I don’t know—you might start with Ralph David Abernathy, Sr., a close friend of King’s and a fellow civil rights leader, who confirms King’s alleged “weakness for women”.
Have you got any more on this? Would be interested to read.
http://www.nytimes.com/2014/11/16/magazine/what-an-uncensore...
To which one might be tempted to say "Well, sure, but J. Edger Hoover was totally out of control", but that's the thing: we let a totally out-of-control guy abuse a extremely powerful agency and do these things.
So, yes, they do need to break encryption. Especially as more and more apps move towards the "smart/encrypted client, dumb server as a storage dump" model.
For what definition of "broken"?
Encryption can't shape policy, but it can make policy nonsensical.
This.
If you listen to the old NSA guys who worked during the heights of the Cold War, who keep tabs on Russians and all the chaos in the Middle East, and had some of these tools at their disposal, they all say the NSA was a great machine for intelligence. It was a great machine for developing assets and tracking bad people. As soon as those weapons and the machine were turned inward on the people they were supposed to protect, they all said it was the worst possible scenario.
Also, if you look at some of the higher profile hacker cases, and to some degree the Ross Ulbricht case, how were they all cracked? Not by the NSA and all its tools, they were all done with your standard, "feet on the street" agents developing leads, connecting dots, and capturing human surveillance.
It wasn't some Flame or Stuxnet bug that brought down these guys, it was just solid detective work.
To bring it back to crypto: there is a correlation between easy to obtain $TECH and use of $TECH. Currently, HTTPS is not as easy as HTTP, so its adoption is less. Let's Encrypt will change that. Currently, access to guns is easy, so their adoption and use is high. With the current political climate that will never change.
it's not simple, it's not all because of guns, and until you modify the 2nd amendment, there is no right of the government to remove guns from the public.
I could go on about how our homicide rate is not too far out of line with other developed countries, how many many gun deaths are self inflicted, how there are a million things that kill more people each year than guns, but this goes way off the NSA topic.
to crypto, that's been the whole discussion today with PGP, isn't it? That the reason it's not adopted is because it isn't easy.
Our police in the US use this excuse far too often. They don't need to believe that someone has a weapon; many treat everyone as if it were the default when that simply isn't the case.
In fairness to the victims of police violence, this has got to stop.
>In a state where guns aren't common, the police officer would feel less threatened and be less likely to overreact.
We've allowed our police to develop a culture of brutality and cheating. Taking guns from the public (assuming that's possible) might make things worse.
Guns are controlled in many countries quite effectively. Not completely of course, but compare for example gun crime in the UK with the US.
There are fewer (if any) examples of drugs being controlled effectively (in non repressive regimes) I'll agree though.
The FBI is charged with counterterrorism in the United States, and it needs to play that role. Any operations focused against U.S. citizens need to be subject to U.S. law, and the FBI is the best place to apply that law.
No no no a thousand times no.
One of the only saving graces about the massive surveillance from the NSA is that, I'm willing to wager, very little of it at all has made it over to where it could be used to oppress the citizens directly.
Bruce's claim that "FBI is charged with counterterrorism" means that they are also charged (along with DEA, ATFE, etc.) with the application of undue force on citizens--something we've been only somewhat spared from because of the difficulty they have in collecting information.
Turning over to them that capability--or even the just the current stockpile and archives of information!--would be a gigantic blow against freedom.
What's more, FBI is also a MUCH leakier boat when it comes to intel gathering, storage, analysis, and sharing. Law enforcement personnel and practice could not possibly hide the decade+ worth of mass surveillance practices from US senators, congress, and the office of the President as NSA has.
As it happens I know something about the mindset within both orgs. With FBI, eventually the truth will come out. Not so with NSA - unless another Snowden is willing to commit suicide, professionally and personally.
It's also become very clear from their response to Snowden's revelations that NSA is not going to get any closer oversight any time soon. The FBI and its partners cannot hope to maintain a comparable cloak of invulnerability. To Bruce's suggestion, I vote yea.
http://en.wikipedia.org/wiki/J._Edgar_Hoover
Giving NSA powers (or archives) to the NSA is a really, really, really bad idea.
The court system and legal system in the US these days is a joke and a farce--just look at the number of cases that make it to trial. We can't afford to give this sort of power over to any law enforcement agency.
Key word here is offensive military unit, like a bomber squad or tank devision. You should not send out this kind of units to allies, neutral states or neighbors, not matter how "valuable" it would be in trade negotiations. Its to the benefit of all that on-line communication is restored to peace, rather than a free-for-all combat zone.
Of the 3 changes suggested by Schneier, this I feel is the most important change that internationally need to happen. Since NSA is the biggest offender here, fixing that actor would encourage other nations to do the same.
Spying isn't even a military operation, it is mostly diplomatic.
Spying has always been common even amongst allies. It is a form of hacked transparency. Countries hide as much as they can.
The only reason I see a reason to distinguish is what the info collected is being used to so America can blackmail German citizens, that is shitty. But if we are just trying to collect information about Germany or people who just happen to be in German who are people of interest? That is the NSA mission.
The real issue is the potential for abuse. But the US government has plenty of stuff it could really abuse.
I think you've missed the part where everyone is now (effectively) a person of interest.
So maybe the US has a record of every call made in Germany, but nobody is tracking some random bus driver in Bavaria.
Right now there aren't is the manpower to actually look at even a tiny fraction of what is collected.
I guess in the future, if an AI with human like ability is created, the actual monitoring of every person could occur. But it just isn't a fear right now.
I'd call it psuedo-pirvacy.
Attacking civil infrastructure of a foreign nation is not spying, especially if that nation has an ongoing war. If one uses the term spying like that, then the term spying has been extended beyond what can possible be reasonable. Just because someones intent is information extraction does not make it any less of an offensive military operation if the method used are offensive military in nature.
hopefully, that's not deliberate. hopefully, they're just that naively convinced of their own goodness. but that's what they're doing.
the NSA's unconstitutional surveillance is a total disgrace, a national shame, a total failure to uphold the Constitution. that's the GOOD news. that's what it is today. add Moore's Law and 20 years, it's going to be something much worse.
(shoutout to everyone who was on Hacker News back when mentioning how Moore's Law ties into this would be worth an upvote.)
Right now it's Orwellian and sophisticated-- if they have Amazon's level of data crunching and prediction ability, they might be able to predict certain things about you, and, on average, be more right than wrong.
Wait until they have 20 more years of data on you, and 20 more years of advancing the quality of their algorithms and machine intelligences. You will be owned, and your buttons will be pushed as necessary to maintain what has already been built.
Fundamental risk assessment fail!
Of course, 20 years ago, or even 5 years ago, that wouldn't have been true, and that's the mindset most critics are coming from. That you need a really strong reason to be doing some kind of mass data collection like this. I just don't agree with that claim. If you can do it, you'd be stupid not to.
In 1971, the National Association of Securities Dealers (NASD) gave birth to NASDAQ, which became publicly traded in 2000, and then a national securities exchange in 2006. NASDAQ wasn't really independent of NASD until 2000, so for a while the same people who owned the exchange also regulated it.
The NYSE is much older and became a Not-for-Profit in 1971. In 2006 it merged with ArcaEx and became a publicly owned for-profit, later merging with Euronext in 2007 and acquiring AMEX in 2008.
Here's the weird thing: exchanges are supposed to self-regulate, with the SEC basically just approving the rules they make for themselves. And the exchanges kind of 'outsource' their regulation - but not all of it - and that's not all that well defined anyway.
In 2007, NASD's and NYSE's regulatory and enforcement committees were merged into a new organization, FINRA, which basically makes the rules their members are supposed to abide by and enforces them in coordination with the SEC.
The SEC has been investigating exchanges since the "flash crash" of 2010, when it was shown how completely fragile the market had become by large players making very large trades, as well as new high-frequency automated trading.
In 2011, NYSE Euronext tried to merge with Deutsche Börse, which would have become the largest stock market in the world by far. It actually passed US antitrust investigation. But in 2012 the European Commission blocked the merger as it would have created a 93% monopoly on European derivatives trading. This doesn't have anything to do with the exchanges violating rules, but it does show how without regulation, monopolies would be a virtual certainty.
In 2012 NYSE was fined 5 million for giving data to its customers before the public. In 2014 NYSE was fined 4.5 million when it was found to have violated its own rules, or lacked rules it should have had.
Compare this to NASDAQ settling with the SEC for 10 million just for mishandling Facebook's IPO in 2013. This is apparently because the SEC stopped short of finding the NYSE's actions as felonies. And all of this is relatively new, as exchanges historically were never legally scrutinized or punished for their actions. (Their revenue is in the billions, so these fines are basically just for show)
Still, good job not just demonizing the NSA, they serve a purpose in the game of international relations, one that the free world may not like, but that we all need.
I'm curious to know what exactly the NSA currently does to protect the US. Do they already use their existing SIGINT knowledge to update systems ahead of attacks?
Again, what the NSA does to protect the US is an open question; if they did their job right, you'll likely not know it. Updating systems, at least large commercial ones that foreign governments use as well as the US citizenry, is not in the purview of their mandate, its the opposite. They do try to tell the world what they do, so as to justify themselves in some degree to their ultimate bosses (the US voting public). The Iranian nuke viruses are a good example, though, as far as I know, they have not claimed that particular hack yet.
There is a middle ground here, but people are (rightfully) foaming at the mouth with anti-NSA rage. In my eyes, this whole situation (NSA going off the map and doing whatever they want) stems from giving them free range with little to no oversight. They simply need better oversight and real consequences for leadership who don't act in the public interest (as determined by a neutral party, albeit a neutral party with top secret clearances).
See, I can use a word or phrase in an internet comment as an excuse to be miserably pedantic too.
Let's draw a parallel to something more tangible than the cyberwar we don't see. Recently there was a number of high-profile cases where police got into a clash with unarmed civilians, with disastrous results. Should police be shut down completely? Would you be safe in a city with no police? Many cities in the world have places where the police don't go, and those are dangerous places.
NSA and CIA serve important functions. They just need to be properly balanced.
Also, we cannot confirm or deny that the NSA and CIA do anything important.
Sometimes, yes. When the corruption and brutality is so bad that there's no other option.
--Would you be safe in a city with no police?
In Acapulco, the answer was yes. The police went on strike and it was so much better without them that the people didn't want them back.
0:http://www.theguardian.com/us-news/2015/feb/25/chicago-homan...
The US signs a complete unconditional surrender on the deck of the $SHIP of $NEW_WORLD_POWER - at least that would be my guess based on history.
We don't stop for genocide.
As another commenter pointed out here: "Can we just flip their budget over to making sure US companies are secure?" That is, of course, what should be done. We get the results we spend money on. If the NSA's budget were spent on making security easy and routine, we would have easy and routine security. But that's not how we express our intentions with the budget right now.
Why commit ourselves to a massive overhaul of the entire NSA when we can address the actual problem here with some granularity and minimal cost yielding an impact almost all of us would enjoy?
That's to say that you're starting from false premises. It is not the NSA's job to advance the security of the nation at all. Hence the need to split it up now. It's time to move the legal basis from executive order to something else, that something else publicly debated and mandated by the people.
Because they've been exposed as untrustworthy. Any attempt at reasonable reform will be met with obstruction, obfuscation, and lies.
> 0day exploits, software and hardware backdooring
Up until it was proven, they denied doing these kind of things. What makes you think they'd tell the truth in the future?
Actually a pretty good article overall, but these two lines bother me greatly:
> "What was supposed to be a single agency with a dual mission—protecting the security of U.S. communications and eavesdropping on the communications of our enemies"
That was never the mission and is not the mission of any similar org in the past 100+ years. It is to eavesdrop on everyone, including ones allies. The Brits were eavesdropping on everyone's telegrams over 100 years ago. This isn't something new. > "The result is an agency that prioritizes intelligence gathering over security"
Again, that is the #1 goal of the NSA and other similar organizations. Security never has and never will be its #1 goal.This comment is not an endorsement of any NSA policies.
It wouldn't be the first time that a government enterprise had a misleading name.
If you are collecting data in order to analyze and identify threats to national security, how would you possibly exclude "the innocent" beforehand? These people are not innocent as much as they aren't guilty - however blinding oneself to observation seems like a knee-jerk alternative.
If these practices are "liable to be abused" isn't the solution proper oversight or accountability and not to shut down the entire program?
NSA is a organization, a empty shell without its people. If the people are not going to change their mindset in short-term (social change in mentality), it means that law has to be changed in short-term, so that very mentality gets more time to change.
But this is where I must contradict myself, does these people who are benefiting from such "Its abuse, not use of power" deserve such a delay? Given that for every second the situation remains the same, countless bottom-of-pyramid-people across the globe would keep suffering? Or have we become TOO used to looking away?
Also, a very important question is, that 'has NSA's Information Collection System become such a tool, where bulk of Americans are used to collect data on Bulk of Americans, and put that in the hands of Few, who then abuse it?' Or NSA has more to it than just the empty shell called: "Interest".
As Voltaire said: "You must ask, whether it is 'Just Interest' or 'National Interest'. "
A supporting question is, who is the Nation anyway? A few or all? Abraham Lincoln ought to be right here. But, fast forward 200 years, It is also important to question, whether "Nations" especially the idea of "America" stands as it is, given the fact that it is America itself that pushed for a "Globalized World" and still does.
While this is the PR, in practice it's categorically untrue.
Forbidden
You don't have permission to access /essays/archives/2014/02/its_time_to_break_up.html on this server. Apache Server at www.schneier.com Port 443
Would it be better for the FBI to be doing these things than the NSA? Or should we be instead fighting that they're done at all?
Whoops, too late:
https://www.eff.org/deeplinks/2015/02/dear-fcc-rethink-those...
That said, the EFF is getting what it has been advocating for: A government takeover of the internet.
That is what net neutrality has always been for and about.
Once we grant that the internet infrastructure is not private property and is open to government regulation, that means it's open to all government regulation, including speech regulation. There is no middle ground.
To think otherwise is to not understand principles and politics.
That is not the whole NSA; it's just a few key people in leadership positions that have been steering the ship lately.
If you keep those same people in power but split up the agency, yes, you'll just get the same thing again.
One seems to need the abolishing of (true) secure systems and privacy (although, so far there is no evidence that mass surveillance actually helps thwart terrorist plots - and it may never be able to do so [1] [2]), and the other is supposed to be about having super-secure systems and strong encryption.
However, since the NSA is in charge of both, it seems the anti-terrorism side has won, and it now causes the NSA to make terrible cyber-policy.
To Schneier's new post, I believe the EU is already getting ready to propose that a civil agency (not one that is run in secret) should be in charge of cybersecurity in EU nations. Although, I think the NSA is working hard to convince EU spy agencies to push legislation that makes them responsible for cybersecurity, at least in some EU countries that are more easily "persuaded".
EDIT: So I actually disagree with Scheneir here. I see no reason why a secretive unaccountable agency should be in charge of cybersecurity. Why should it be a state secret that a hacker hacked into a US company? Just because the NSA has the "expertise" in cybersecurity? If you want to keep the experts, fine, but then turn the NSA into a civil agency.
I agree with his suggestion that surveillance (not mass surveillance, though - that should be banned for all agencies) should only be the domain of FBI.
To recap:
1) Cybersecurity = civil agency
2) Surveillance of local citizens = civil agency (FBI in US, I guess. Mind you, this is what already happens, when referring to targeted surveillance, so the real proposal here is that the NSA or anyone else shouldn't be spying on local citizens, too - only the FBI and with warrants. This is not, or should not be about giving the FBI "mass surveillance powers". If that's what Schneier is proposing, then I completely disagree with this, too)
3) Cyber-offense/cyber-war = military/Pentagon/whatever
4) I'm unsure whether we need another agency for spying on "world leaders", but right now I'm strongly inclined to give this one to the military too. Also, it would be best if this wasn't actually targeted at allies (like Merkel), but actual rival (Russia) or rival-like (China) countries. I think it's just good foreign policy not to do nasty stuff to your allies, just to be slightly "ahead" in negotiations.
[1] - https://www.schneier.com/blog/archives/2006/03/data_mining_f...
[2] - https://www.schneier.com/blog/archives/2006/07/terrorists_da...