719 karma · joined March 26, 2011
His claim was that the NSA had issues in the past getting encryption devices certified for use in unclassified environments because NSA controlled the certification process for classified encryption algorithms (which were themselves generally classified), but NIST controlled the certification for government use in unclassified settings (and these algorithms could not be classified). The NSA wanted to be able to use an existing algorithm in an unclassified setting. As the article does point out, Mr. George stated that the algorithm was intended primarily for their own internal use and user should be able to use any P and Q, though they needed their own P and Q certified for their own use.
Later on in the presentation he states that the P and Q were both non-deterministically generated random numbers. He states that the NSA has office devoted specifically to producing random numbers for their own use, and they just got the P and Q from there.
Whether or not you believe this claim is an entirely different and reasonable question (there's no real way to verify it), but why bother quoting him if you're going to selectively quote like this? If the P and Q are in fact purely random as Mr. George claims, Dual_EC goes from being a grand conspiracy to just a slow, crappy PRNG. I think selectively quoting to make this guy sound more sinister makes it look like the author wants it to be a grand conspiracy and just undermines the argument.
Btw., the entire presentation is worth watching if you have time - he goes into the history of DES, espionage between the US and Soviets, getting cryptographic equipment working in tanks, etc...
[1] http://vimeo.com/97891042 (jump to 57:53)
[2] Same video, jump to 30:14
I don't understand the people who protest drone strikes. War is hell - if your country engages in any sort of violent military intervention, there will be civilian casualties. I can get behind opposing unnecessary usage of military force; I can get behind opposing attacks within the borders of a sovereign nation that we aren't at war with. Protesting the tools used to conduct war instead of the war itself makes little sense to me, particularly when that tool marks a dramatic improvement in reducing civilian casualties.
[1] https://www.thebureauinvestigates.com/category/projects/dron...
[2] http://thevietnamwar.info/operation-rolling-thunder/
[3] https://en.m.wikipedia.org/wiki/Civilian_casualties_of_strat...
The burden of proof rests on the person alleging it happened, not the person saying there is no evidence. You're asking me to concede that something must have happened in secret unless I can prove a negative. To top it off, Der Spiegel very strongly suggests that they just recently learned of the matter in the editor's note on the left hand of the page. Nowhere in their reporting (or, to my knowledge, anyone else's reporting) are they claiming that the government forced them to withhold a story.
> FOIA records on FBI and CIA show again and again ...
Could you provide links to these FOIA documents?
1) The first half of the headline reads "An Attack on Press Freedom". How exactly was freedom of the press attacked? Did the US or German governments stop Der Spiegel from publishing something? Were they blackmailed into suppressing a story (but for some reason not so for this one)? As far as the story indicates, the only action that was taken was to move the person accused of leaking from one department to another. But, hey, "An Attack on Press Freedom" gets more people to view those 9 ad banners scattered throughout the article...
2) I just read this article twice over, and I can't actually see any evidence that US intelligence services were targeting Der Spiegel. Somehow the CIA station chief finds out that someone in the German Department Six is passing information to Der Spiegel, and informs the head of Department Six. They don't actually give any indication as to how the CIA got that information, but just state that it was most likely the NSA spying on Der Spiegel as if it were a foregone conclusion. How do they know this? I can think of a number of other situations where the CIA may have received this information...
- The CIA had a source inside Der Spiegel
- The CIA was spying on their source (not Der Spiegel)
- The NSA was spying on their source
- The CIA/NSA was spying on a third party that knew of the leaks
- The source was drunk at a bar and bragged about it to or within earshot of a CIA agent
- One of the journalists was drunk at a bar and bragged about it.
- The CIA/NSA was spying on Russian intelligence (or any other country in the region) and that foreign intelligence service was doing any of the above
- etc. ...
I accept that they don't want to reveal their source, but there's no mention of an anonymous source, or documents acquired by Der Spiegel, or anything else substantiate the US targeting the news outlet. As far as I can tell, this is the extent of their attribution:Research conducted by SPIEGEL has determined the existence of CIA and NSA files filled with a large number of memos pertaining to the work of the German newsmagazine.
Really? That's it? They somehow know that documents exist which somehow make reference to a global news outlet known for breaking headlines concerning the work of these intelligence agencies? What kind of research was conducted, and what do these documents actually say? For god's sake - Der Spiegel is one of the few news agencies that has the whole Snowden trove and regularly releases documents from it, but they can't show anything from there proving their claim?
Not too long ago, the Sunday Times in England ran a story claiming that documents stolen by Edward Snowden were in the hands of Chinese and Russian intelligence services, relying solely on anonymous sources in the British government. They were rightly lambasted for it in a number of other media outlets. Der Spiegel is now doing almost the exact same thing.
The FISC has its own website which happens to answer your question right on the "About" page[1]:
The Court sits in Washington D.C., and is composed of eleven federal district court judges who are designated by the Chief Justice of the United States. Each judge serves for a maximum of seven years and their terms are staggered to ensure continuity on the Court. By statute, the judges must be drawn from at least seven of the United States judicial circuits, and three of the judges must reside within 20 miles of the District of Columbia. Judges typically sit for one week at a time, on a rotating basis.
> ...and that article suggests that (if we accept they rotate duty and meet monthly say) they spend, on average, (8 hours / 133 * 60 minutes) ~3.5 minutes carefully evaluating each application. If not, it's ~30 seconds per application.
No, the article says 33 per week. The judges aren't meeting together every few months; the sitting judge is replaced by the next every week or so. Assuming an 8 hour work day and 33 warrants per week, that (8 * 5) / 33 = 1.2 hours per warrant on average.
[1] http://www.fisc.uscourts.gov/about-foreign-intelligence-surv...
I may very well be able to do that, but it wouldn't do anything to disprove the notion that Wikileaks has a pro- Russian, anti-US bias.
I see two simple reasons for the lack of Russian coverage at Wikileaks: either Russians aren't providing material, or Assange isn't publishing it.
- Category:Russia - 57 pages total
- Cyprus - 54 pages
- Latvia - 50 pages
- Lithuania - 47 pages
- Estonia - 46 pages
-------
- Japan: 90 pages
- Italy: 99 pages
- France: 128 pages
- Canada: 153 pages
- Germany: 278 pages
- United Kingdom: 384 pages
- United States: 9729 pages
Interesting set of priorities they have there... I'm curious as to why a G8 country has as much information posted as a country with 1/140 its population.Much of what privacy advocates focus on in terms of privacy violations on the internet neglect to take into account privacy gains from those same technologies. A key factor to this is focusing on what information is being shared but neglecting to account who it is being shared with and the privacy benefits associated with interacting with that service instead of traditional alternatives. For example, Google can see every search a person conducts regarding their sexual preferences. However, a closeted homosexual might turn to Google to find social and support groups because they're afraid of judgement from their family and peers. Groups like the EFF would say that buying a book through a Kindle is awful for the privacy of the reader because Amazon tracks the fact that you specifically bought the book and can see when you're reading it and even what page you're on - but most readers don't care that Amazon knows they're reading 50 Shades of Grey; they'd rather that everyone else on the subway just sees them reading their Kindle instead of an erotic novel paperback.
In general, people are more afraid of having their sensitive personal details disclosed to the people they interact with in person - their families, friends, coworkers or even the checkout lady at the pharmacy. The loss of privacy to a remote party like Google is worth the net gain in privacy to avoid disclosing embarrassing information to people they are more concerned with. This is also dependent on the type information being disclosed - the set of information that you'd want to keep from your friends is not the same set that you'd want to keep from your spouse, which is not the same as what you'd keep from your coworkers, which is not the same as what you'd hide from the police.
For those that would prefer an audio version, Ben Wittes gives a good discussion of it on the Lawfare Podcast at http://traffic.libsyn.com/lawfare/Episode_129.mp3
- Snowden would not have been able to legally "wiretap anybody": http://electrospaces.blogspot.com/2015/02/snowden-would-not-...
- Snowden-documents show no evidence for global mass surveillance: http://electrospaces.blogspot.com/2014/06/snowden-documents-...
- Document shows that it was not NSA, but FBI that monitored 5 Americans: http://electrospaces.blogspot.com/2014/07/document-shows-tha...
- Screenshots from BOUNDLESSINFORMANT can be misleading: http://electrospaces.blogspot.com/2013/11/screenshots-from-b...
I suggested it for much more mundane than you suggested: Google is likely to have valuable political, economic and political information because politicians, businessmen and service members have personal Google accounts, and employees are the weakest link in an organization's security. I don't think anyone's going to be sending out the designs for the next stealth fighter over Gmail, but plenty of people would be sending out innocuous documents, contact information, personal problems, etc. Intelligence services thrive on innocuous information in aggregate.
I didn't mean to imply that I have any inside knowledge of the hack - I'm basing my views on this from what I've read in news outlets. I doubt I have any more knowledge on the subject than you. (Unless I'm misinterpreting sarcasm on your part)
> China and the US hack each other for strategic purposes and that when China hacks the US it is not about dissidents.
The Chinese intelligence services are going to focus on targets that will forward their own national goals. This will off course include strategic goals such as increasing economic and regional military influence, but don't discount their desire to maintain internal stability. They invest a significant amount of resources into controlling content on the internet and other media venues. In recent memory, their Great Firewall infrastructure was used to target dissidents hosting their materials within the US (which incensed the HN crowd with the whole Github DDOS).
There's plenty of good reasons for China to target Google. They have every reason to distrust Google as the US government has to distrust Chinese tech companies, and there's bound to be a wealth of information on their servers useful for counter intelligence, economic, political and likely even military gain as well. I don't we'll ever know exactly what all of their reasons were for breaking in, but I don't think the theory that one of the primary motivations was targeting dissidents can be waved away as just spin.
You have a point, but I don't think it applies in this situation. Google was a valuable target for Chinese intelligence for a whole variety of reasons. Google itself suspected that the primary motivation was to gather information on Chinese activists that were using the service.[1] The fact that there was apparently a database of FBI targets is just added benefit for them, and there's no evidence that I've seen to indicate that they knew of the database to begin with.
[1] http://www.independent.co.uk/news/media/china-google-cyberat...
As I mentioned in a post above[3], in the case against Ramona Fricosu she didn't have a 5th Amendment right to not produce her password partly because she was granted immunity for any evidence that would have been collected from it (but her husband would not be). If you have evidence of a crime, you are required to provide to the courts when requested. You have the right to not provide evidence or testimony which incriminates yourself - if you cannot be incriminated for it, you no longer have the right to withhold it.
[1] http://cyb3rcrim3.blogspot.com/2010/04/passwords-and-5th-ame...
[2] http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....
[1] http://www.denverpost.com/ci_20080656
[2] http://www.wired.com/images_blogs/threatlevel/2012/01/decryp... (p.9)
"But Steinbach's testimony also suggests he meant that companies shouldn't put their customers' access to encryption ahead of national security concerns -- rather than saying the government's top priority should be preventing the use of the technology that secures basically everything people do online."
Here is the actual hearing: http://www.c-span.org/video/?326360-1/hearing-cartoon-contes...
The hearing was concerning ISIS use of social media as a recruitment platform and how it related to the recent shootings in Garland, Texas and in Boston on Tuesday.
The subject of encryption is not the primary focus of the hearing, but when it does come up I think he makes his point clear at about 39:30 when says this: "I think we need an honest conversation and get past the rhetoric of what we are talking about. We're not talking about large scale surveillance techniques. We are talking about going before the court, whether the criminal court or the national security court, with evidence, a burden of proof/probable cause, suggesting a crime has been committed or in our case there is a terrorist and showing that burden of proof, having the court sign off on it, and then going to those providers and requesting access to the stored information or communications that's ongoing. So we're not looking at going through a backdoor or being nefarious - we're talking about going to the company and asking for their assistance. We suggest and we are imploring Congress to help us seek legal remedies to that and asking companies to provide technological solutions to help that. We understand privacy. Privacy above all other things including safety and freedom from terrorism is not where we want to go. "
He later goes on to suggest expanding he scope of CALEA to include more than just telecommunications companies.
If people are going to debate this topic, I think they should start from his actual position and not a half sentence soundbite.
[1] http://www.usgovernmentspending.com/year_spending_2015USbn_1...
Which gets you into benefits/trade-offs territory; I think it's probably an overreaction for NASA to take their internet facing servers and all computers on the connected networks down to investigate for possible intrusions every time a new security patch comes out. I don't think it's unreasonable for them to do so when they have credible evidence that they've been hacked. (of course, I don't work for NASA, so I have no idea what procedures they have in place)
Which would involve taking the system down to conduct the snapshot. What gets put back in place will depend on the severity of the breach, perceived threat, sensitivity of data, etc. They had no way of knowing exactly how sophisticated the attack was until the cops finished their investigation - is this some script kiddie or the Chinese military? I'm not going to worry about a foreign intelligence service if I'm serving up web pages for an eCommerce site, but I would if I were working for NASA. Just because you patch the vulnerability in question doesn't mean you've denied the attacker access to your network...
If they suspected additional backdoors have been added during the breach, the affected systems would need to rebuilt entirely, patched, then have data selectively restored from backup (you don't want to reintroduce to the system any malware that was saved to a backup). What other systems were accessible from the one that was hacked? Are there rootkits sending beacons home on any of them? Is there reason to preemptively take them down and rebuild them? What if one of the affected systems is a mail server/file server/etc.?
No, I don't blame NASA for overreacting. The kid pulled back technical details for a space station. The Russian government would have done the same (and may even have already been in there). NASA took steps that they thought were sensible, and they ate the costs. The kid ended up getting 6 months of house arrest and 2 years probation.
EDIT: Now that I'm looking a little further into the case...
He was apparently raided by the FBI two weeks prior to the suicide during an investigation in the TJX hack. During the raid, the police found another suicide note that James had written several years prior. His suicide note[2] spends the first page and a half talking about something that's been redacted, then the next page and a half talking about some background on the TJX case, denying that he had any connection and noting the fact that one of the other suspects (Chris) had been arrested and subsequently released. He believed that meant that Chris had tried to pin the blame for the hack on him, and he believed that the FBI would be looking to arrest him for a crime he didn't commit.
[1] http://www.wired.com/2009/07/hacker-3/
[2] http://www.wired.com/images_blogs/threatlevel/2009/07/jamesn...