Showing posts with label CIA. Show all posts
Showing posts with label CIA. Show all posts

Saturday, April 1, 2017

WikiLeaks Vault 7 documents about vulnerable Cisco products exposes US govt’s stance on cyber security

WikiLeaks Vault 7 documents about vulnerable Cisco products exposes US govt’s stance on cyber security

Image Credit: REUTERS
When WikiLeaks founder Julian Assange disclosed earlier this month that his anti-secrecy group had obtained CIA tools for hacking into technology products made by U.S. companies, security engineers at Cisco Systems swung into action.
The Wikileaks documents described how the Central Intelligence Agency had learned more than a year ago how to exploit flaws in Cisco’s widely used Internet switches, which direct electronic traffic, to enable eavesdropping.
Senior Cisco managers immediately reassigned staff from other projects to figure out how the CIA hacking tricks worked, so they could help customers patch their systems and prevent criminal hackers or spies from using the same methods, three employees told Reuters on condition of anonymity.
The Cisco engineers worked around the clock for days to analyze the means of attack, create fixes, and craft a stopgap warning about a security risk affecting more than 300 different products, said the employees, who had direct knowledge of the effort.
That a major U.S. company had to rely on WikiLeaks to learn about security problems well-known to U.S. intelligence agencies underscores concerns expressed by dozens of current and former U.S. intelligence and security officials about the government’s approach to cybersecurity. That policy overwhelmingly emphasizes offensive cyber-security capabilities over defensive measures, these people told Reuters, even as an increasing number of U.S. organizations have been hit by hacks attributed to foreign governments.
Larry Pfeiffer, a former senior director of the White House Situation Room in the Obama administration, said now that others were catching up to the United States in their cyber capabilities, “maybe it is time to take a pause and fully consider the ramifications of what we’re doing.” U.S. intelligence agencies blamed Russia for the hack of the Democratic National Committee during the 2016 election. Nation-states are also believed to be behind the 2014 hack of Sony Pictures Entertainment and the 2015 breach of the U.S. Government’s Office of Personnel Management.
CIA spokeswoman Heather Fritz Horniak declined to comment on the Cisco case, but said it was the agency’s “job to be innovative, cutting-edge, and the first line of defense in protecting this country from enemies abroad.” The Office of the Director of National Intelligence, which oversees the CIA and NSA, referred questions to the White House, which declined to comment.
Across the federal government, about 90 percent of all spending on cyber programs is dedicated to offensive efforts, including penetrating the computer systems of adversaries, listening to communications and developing the means to disable or degrade infrastructure, senior intelligence officials told Reuters.
President Donald Trump’s budget proposal would put about $1.5 billion into cyber-security defense at the Department of Homeland Security (DHS). Private industry and the military also spend money to protect themselves.
But the secret part of the U.S. intelligence budget alone totaled about $50 billion annually as of 2013, documents leaked by NSA contractor Edward Snowden show. Just 8 percent of that figure went toward “enhanced cyber security,” while 72 percent was dedicated to collecting strategic intelligence and fighting violent extremism.
Departing NSA Deputy Director Rick Ledgett confirmed in an interview that 90 percent of government cyber spending was on offensive efforts and agreed it was lopsided. “It’s actually something we’re trying to address” with more appropriations in the military budget, Ledgett said. “As the cyber threat rises, the need for more and better cyber defense and information assurance is increasing as well.”
The long-standing emphasis on offense stems in part from the mission of the NSA, which has the most advanced cyber capabilities of any U.S. agency. It is responsible for the collection of intelligence overseas and also for helping defend government systems. It mainly aids U.S. companies indirectly, by assisting other agencies.
“I absolutely think we should be placing significantly more effort on the defense, particularly in light of where we are with exponential growth in threats and capabilities and intentions,” said Debora Plunkett, who headed the NSA’s defensive mission from 2010 to 2014.
Government Role
How big a role the government should play in defending the private sector remains a matter of debate. Former military and intelligence leaders such as ex-NSA Director Keith Alexander and former Secretary of Defense Ashton Carter say that U.S. companies and other institutions cannot be solely responsible for defending themselves against the likes of Russia, China, North Korea and Iran.
For tech companies, the government’s approach is frustrating, executives and engineers say. Sophisticated hacking campaigns typically rely on flaws in computer products. When the NSA or CIA find such flaws, under current policies they often choose to keep them for offensive attacks, rather than tell the companies.
In the case of Cisco, the company said the CIA did not inform the company after the agency learned late last year that information about the hacking tools had been leaked. “Cisco remains steadfast in the position that we should be notified of all vulnerabilities if they are found, so we can fix them and notify customers,” said company spokeswoman Yvonne Malmgren.
Side by Side
A recent reorganization at the NSA, known as NSA21, eliminated the branch that was explicitly responsible for defense, the Information Assurance Directorate (IAD), the largest cyber-defense workforce in the government. Its mission has now been combined with the dominant force in the agency, signals intelligence, in a broad operations division.
Top NSA officials, including director Mike Rogers, argue that it is better to have offensive and defensive specialists working side by side. Other NSA and White House veterans contend that perfect defense is impossible and therefore more resources should be poured into penetrating enemy networks – both to head off attacks and to determine their origin.
Curtis Dukes, the last head of IAD, said in an interview after retiring last month that he feared defense would get even less attention in a structure where it does not have a leader with a direct line to the NSA director. “It’s incumbent on the NSA to say, ‘This is an important mission’,” Dukes said. “That has not occurred.”
Reuters
Publish date: March 30, 2017 7:14 pm| Modified date: March 30, 2017 7:14 pm
×

Friday, December 23, 2016

Lithuania finds spyware on its government computers, holds Kremlin responsible

Lithuania finds spyware on its government computers, holds Kremlin responsible

Image Credit: Malwarebytes
The Baltic state of Lithuania, on the frontline of growing tensions between the West and Russia, says the Kremlin is responsible for cyber attacks that have hit government computers over the last two years.
The head of cyber security told Reuters three cases of Russian spyware on its government computers had been discovered since 2015, and there had been 20 attempts to infect them this year
“The spyware we found was operating for at least half a year before it was detected – similar to how it was in the USA,” Rimtautas Cerniauskas, head of Lithuanian Cyber Security Centre said.
The Kremlin did not immediately respond to a Reuters written request for comments over the Lithuanian claims. But Russia has in the past denied accusations of hacking Western institutions.
Fears of cyber attacks have come to the fore since the U.S. election campaign when hacking of Democratic Party emails led to allegations from U.S. intelligence that Russia was involved. Lithuania, Estonia and Latvia, all ruled by Moscow in communist times, have been alarmed by Russia’s annexation of Ukraine’s Crimea peninsula in 2014 and its support for pro-Russian separatists in eastern Ukraine.
In what Baltic officials say was a wake-up call, Estonia was hit by cyber attacks on extensive private and government Internet sites in 2007. State websites were brought to a crawl and an online banking site was closed. Lithuanian intelligence services, in their annual report, say cyber attacks have moved from being mainly targeted at financial crimes to more political spying on state institutions.
Russian spyware was transferring all documents it could find, as well as all passwords entered on websites such as GMail or Facebook, to an internet address commonly used by Russian spy agencies, Cerniaukas said. “This only confirms that attempts are made to infiltrate our political sphere,” said Cerniaukas.
Preparations
Germany’s domestic intelligence agency reported earlier this month a striking increase in Russian targeted cyber attacks against political parties and propaganda and disinformation campaigns aimed at destabilising German society. The domestic intelligence chief said Russia may seek to interfere in its national elections next year.
Although no Russian cyber meddling was detected in the run up and during the Lithuanian general election in October, Cerniauskas said his country needs to understand it is vulnerable to such meddling.”Russians are really quite good in this area. They have been using information warfare since the old times. Cyberspace is part of that, only more frowned upon by law than simple propaganda”, he said.
“They have capacity, they have the attitude, they are interested, and they will get to it – so we need to prepare for it and we need to apply countermeasures.” Lithuanian officials targeted by the Russian spyware held mid-to-low ranking positions at the government, but their computers contained a stream of drafts for government decisions of its positions on various matters, said Cerniauskas.
The head of the Lithuanian counter-intelligence agency Darius Jauniskis said Russia tried to sow chaos in Lithuania by orchestrating a cyber attack in 2012 against the Lithuanian central bank and its top online news website. “It is all part of psychological warfare,” he told Reuters earlier this month.
Reuters

Saturday, December 10, 2016

US and UK spies tried accessing data from passengers’ mobile phones on commercial airline, says report

US and UK spies tried accessing data from passengers’ mobile phones on commercial airline, says report

American and British spy agencies have tried to intercept data from passengers’ mobile phones on commercial airlines including Air France, French media has reported, citing documents from US whistleblower Edward Snowden.
The French flag-carrier was an early target of the US National Security Agency and its British counterpart GCHQ as it was seen as a terrorist target and it carried out tests in 2007 on allowing the use of mobile phones on its aircraft.
“The use of mobile phones with Internet connections in the sky gave rise to the creation of specific programs at the NSA and GCHQ,” said Le Monde, which has access to Snowden’s archive in partnership with news website The Intercept.
While it is not normally possible to make phone calls on planes, some carriers allow passengers to connect to a cabin Wi-Fi, allowing them to use internet-based functions on their handsets.
In 2012, at least 27 airlines allowed passengers to use mobile phones on board, including British Airways, Aeroflot, Etihad, Cathay Pacific, Lufthansa and Singapore Airlines.
But Air France was “such a symbol of the surveillance of communications on board airlines that the British spy agency used a drawing of one of their planes to illustrate how the interception worked.”
Asked about the British and American surveillance claims, Air France told Le Monde, “We are visibly not the only ones to have been targeted and we know absolutely nothing about these practices.”
According to the report, internal documents from the two agencies describe the results of the “impressive” programs – codenamed “Thieving Magpie” and “Homing Pigeon” – which allowed data to be collected “almost in real time”.
In order to spy on a telephone, all that was needed was that the aircraft be cruising at an altitude above 10,000 feet, the report said.
Secret aerial stations on the ground could intercept the signal as it transited through a satellite.
“The simple fact that the telephone was switched on was enough to give away its position, the interception could then be cross-referenced with the list of known passengers on the flight, the flight number, and the airline code to determine the name of the smartphone user,” the report said.
The mobile phone’s function could also be disrupted, it said, forcing the user to input their access codes and thereby allowing the British spy agency to intercept the information.
Snowden, a former National Security Agency contractor, leaked thousands of classified documents to the press in 2013 which revealed the vast scope of US surveillance of private data that was put in place after the 9/11 attacks.
After fleeing his home in Hawaii, he now lives in exile in Russia where he has sought asylum.
Should he ever return to the United States, Snowden would be tried for espionage and other charges carrying up to 30 years in prison.
AFP

Tuesday, October 11, 2016

CIA ‘Siren Servers’ can predict social uprisings 3-5 days in advance




The CIA claims to be able to predict social unrest days before it happens thanks to powerful super computers dubbed Siren Servers by the father of Virtual Reality, Jaron Lanier.
CIA Deputy Director for Digital Innovation Andrew Hallman announced that the agency has beefed-up its “anticipatory intelligence” through the use of deep learning and machine learning servers that can process an incredible amount of data.
“We have, in some instances, been able to improve our forecast to the point of being able to anticipate the development of social unrest and societal instability some I think as near as three to five days out,” said Hallman on Tuesday at the Federal Tech event, Fedstival.
This Minority Report-type technology has been viewed skeptically by policymakers as the data crunching hasn’t been perfected, and if policy were to be enacted based on faulty data, the results could be disastrous. Iraq WMDs?
The CIA deputy director said that it was “much harder to convey confidence for the policymaker who may make an important decision from advanced analytics with deep learning algorithms.”

JARON LANIER’S SIREN SERVERS

Computer science philosopher and author of “Who Owns the Future?” and “You are not a Gadget,” Jaron Lanier, coined the phrase “Siren Servers” to describe these types of giant computer networks that can crunch huge amounts of data.
“A siren server is the biggest and best computer on a network. Whoever has the most powerful computer would be the most powerful person, whether they plan to be or not,” said Lanier in an interview with the Huffington Post.
Lanier’s siren server definition was conceived to describe how companies with the most powerful computers can gain wealth by
Related Posts Plugin for WordPress, Blogger...