IT Security Professional
3387 stories
·
14 followers

NSA Leaks of Its Cyber Weapons Leave the Agency Shaken to its Core

1 Share

As The New York Times reported on November 12th, Jake Williams awoke last April in an Orlando, Florida hotel where he was leading a training session. Checking Twitter, Mr. Williams, a cybersecurity expert, found that he had been thrust into the middle of one of the worst security nightmares of American intelligence.

Mr. Williams had written on his company blog about the Shadow Brokers, a mysterious group that had somehow obtained many of the hacking tools the United States used to spy on other countries. Now the group had replied angrily online. It identified him as a former member of the National Security Agency's hacking group, Tailored Access Operations, or TAO, a job he had not publicly disclosed. Then the Shadow Brokers revealed technical details that made it clear they knew about highly classified hacking operations that he had conducted.

Conclusion? America's largest and most secretive intelligence agency had been deeply infiltrated.

The shock to Mr. Williams was part of a much broader disaster that has shaken the NSA to its core. Current and former agency officials say the Shadow Brokers disclosures, which began in August 2016, have been catastrophic for the NSA, calling into question its ability to protect potent cyberweapons and its value to national security. The agency hailed as the world's leader in breaking into adversaries' computer networks had failed to protect its own.

Fifteen months into a wide-ranging investigation by the agency's counterintelligence arm, known as Q Group, and the FBI, officials still do not know whether the NSA is the victim of a brilliantly executed hack, with Russia as the most likely perpetrator, an insider's leak, or both. Three employees have been arrested since 2015 for taking classified files, but there is fear that one or more leakers may still be in place. There is widespread agreement that the damage from the Shadow Brokers already far exceeds the harm to American intelligence done by Edward J. Snowden.

Created at enormous expense to American taxpayers, our cyberweapons have now been picked up by hackers from North Korea to Russia and fired back at the United States and its allies.

Much of the NSA's arsenal is still being replaced, limiting operations. Morale is in the tank, and experienced specialists are leaving the agency for better-paying jobs — including with firms defending computer networks from intrusions that use the NSA's leaked tools.

Russia is the prime suspect in a another leak of hacking tools and secret documents from the CIA's Center for Cyber Intelligence, posted week after week since March to the WikiLeaks website under the names Vault7 and Vault8. That breach, too, is unsolved. The tsunami of digital secrets leaked from agencies that invest huge resources in preventing such breaches is raising profound questions.

Some veteran intelligence officials believe a focus on offensive weapons and hacking tools has left American cyberdefense dangerously weak. "We have had a train wreck coming," said Mike McConnell, the former NSA director and national intelligence director. "We should have ratcheted up the defense parts significantly."

In the meantime, Russia's most prominent cybersecurity firm, Kaspersky Lab, had started hunting for the spying malware planted by NSA hackers, guided in part by the keywords and code names in the files taken by Mr. Snowden and published by journalists. The TAO hackers knew that when Kaspersky updated its popular antivirus software to find and block the NSA malware, it could defeat spying operations around the world. Therefore, TAO hackers moved to replace implants in many countries with new malware they did not believe the Russian company could detect.

In February 2015, Kaspersky published its report on the Equation Group — the company's name for TAO hackers — and updated its antivirus software to extract the NSA malware wherever it had not been replaced. The agency temporarily lost access to a considerable flow of intelligence.

The leaks have reinvigorated a debate over whether the NSA should be permitted to stockpile vulnerabilities it discovers in commercial software to use for spying rather than immediately alerting software makers so the holes can be plugged. The agency claims it has shared with the industry more than 90 percent of flaws it has found, reserving only the most valuable for its own hackers. But if it can't keep those from leaking, as the last year has clearly demonstrated, the resulting damage to businesses and computer users around the world can be monumental. The Trump administration says it will soon announce revisions to the system, making it more transparent.

I am not holding my breath waiting for that to happen. But I do worry that Russia is outpacing us in cybersecurity offensive and defensive measures – and that we have been woefully slow to response to a clear case of "throwing the gauntlet down."

E-mail: snelson@senseient.com Phone: 703-359-0700
Digital Forensics/Information Security/Information Technology
https://www.senseient.com
https://twitter.com/sharonnelsonesq
https://www.linkedin.com/in/sharondnelson
https://amazon.com/author/sharonnelson

Read the whole story
josephwebster
29 days ago
reply
Denver, CO, USA
Share this story
Delete

Op-ed: Maine’s governor wants to ignore the will of voters. He’s not alone.

1 Share

Less than a day after voters in Maine voted to expand Medicaid in their state, Gov. Paul LePage (R) moved quickly to subvert their democratic will, announcing Wednesday that he will not implement the expansion until it is “fully funded by the Legislature.”

This is not the first time that elected officials in the state have blatantly ignored voters in this way. Last year, Mainers approved an innovative reform known as “ranked-choice voting,” as an effort to ensure that their governor wins with a majority of the vote. But the state legislature did not agree with that decision, so it recently voted to delay and potentially repeal the initiative. In fact, it brazenly meddled with every single ballot measure passed by the state’s voters in 2016.


Related:
Maine Gov. Paul LePage vetoes marijuana bill, saying federal future of legalization uncertain
Mainers voted for a 10 percent tax on weed, but lawmakers want more


The news out of Maine is part of an ominous pattern: State legislators across the country resisting the will of the people by gutting or even repealing citizen initiatives. This is a shockingly undemocratic trend at a time when U.S. voters are already deeply unsatisfied with their elected leaders.

The citizen initiative – in which a group of voters brings a proposed law or constitutional amendment to the ballot for the public to approve or reject – exists in 26 states and the District of Columbia. It has long been a critical tool for advancing key issues that are popular with the public but unlikely to make it through legislatures or city councils.

But more and more legislators have been willing to effectively deny their constituents’ political voices. Perhaps the most egregious repeal of a voter-approved initiative in modern history took place this year in South Dakota, where voters passed a suite of ethics and campaign finance reforms aimed at eradicating political corruption endemic to the state’s politics. The state’s legislature quietly declared an “emergency session” and swiftly repealed the citizen-approved measure intended to regulate their own corrupt behavior.

Unfortunately, South Dakotans and Mainers are not alone.

Read the rest of this story at TheCannabist.co.



Read the whole story
josephwebster
36 days ago
reply
Denver, CO, USA
Share this story
Delete

#Halloween music on @Bandcamp: John Carpenter + Disturbing Mood pieces, Melodic Theremin, and Gothic horror by Victoria Lundy + 5 Original Horror Soundscapes

1 Comment

Passing along some Halloween Music you can pick up over on Bandcamp.

John Carpenter on Bandcamp

john-carpenter-bandcamp
I’ve been enjoying John Carpenter’s recent music releases and was happy to see he was also on Bandcamp at https://johncarpentermusic.bandcamp.com/.

So much great music out here! My fav track lately is “A Windy Death” on Lost Themes II.

His album Anthology: Movie Themes 1974-1998 was released yesterday

https://johncarpentermusic.bandcamp.com/album/anthology-movie-themes-1974-1998.

He’s also on tour http://www.theofficialjohncarpenter.com/tour/ – sadly with no dates in the Denver area yet :^(.

Miss American Vampire by Victoria Lundy

Victoria is a friend, frequent collaborator, and a wonderful Thereminist. Her debut solo album Miss American Vampire released on Halloween 2015 is fantastic! https://victorialundy.bandcamp.com/

miss-american-vampire-victoria-lundy

Disturbing mood pieces, melodic theremin, and gothic horror. This recording used Moog Etherwave Pro Theremin, Ableton Live 9, Logic, Native Instruments Absynth, Reaktor and Molekular.

More info at http://www.victorialundymusic.com/.

No Ghosts. Just Fear.

no-ghosts-just-fear-mark-mosher-cover-1400

I released No Ghosts. Just Fear. Back in 2012  https://markmosher.bandcamp.com/album/no-ghosts-just-fear. Note this, and my entire catalog on Bandcamp are now “name your price”.

The dark ambient sounds and music within these arrangements was created and performed on various virtual instruments. In some cases original audio recordings were used as sources then re-shaped with granular synthesis to turn these recordings into playable expressive instruments with huge sonic range and motion.

Happy Halloween,

Mark Mosher
Composer, Synthesist, Electronic Musician, Multimedia Artist
Boulder, CO
MarkMosherMusic.com
ModulateThis.com

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


Filed under: halloween music, Sound Design Tagged: Gothic Music, Halloween, Horror Music, Horror Soundscapes, John Carpenter, mark mosher, synthesizer, synthesizers, Theremin, victoria lundy









Read the whole story
josephwebster
45 days ago
reply
I have most of this stuff and can confirm that it's excellent and spooky as hell.
Denver, CO, USA
Share this story
Delete

Fats Domino, 89, One of Rock ’n’ Roll’s First Stars, Is Dead

1 Comment and 2 Shares
Mr. Domino, known for his two-fisted boogie-woogie piano and nonchalant vocals, had more than three dozen hits in the 1950s and ’60s.

Read the whole story
josephwebster
51 days ago
reply
RIP Fats
Denver, CO, USA
christophersw
51 days ago
reply
Baltimore, MD
Share this story
Delete

PricewaterhouseCoopers Announces Opening of US Law Firm

1 Share

As the American Bar Association Journal reported last month, the Big Four accounting firms have legal divisions operating overseas that are on a par with the largest law firms in the world according to a report by ALM intelligence. Not long after that report was issued, PricewaterhouseCoopers announced that it would open a law firm in Washington, D.C. In the US, almost all jurisdictions have ethics rules that bar nonlawyer ownership and management of law firms, along with fee-sharing with non-lawyers. DC does not ban multidisciplinary practices owned by nonlawyers.

Law firm leaders are aware of the Big Four threat. 66% of partners surveyed said they were concerned about alternative legal service providers and accounting firms and 64% said accounting firms moving into the legal vertical was a bigger threat than the expansion of in-house legal departments, e-discovery vendors and legal process outsourcing companies.

The report notes that the Sarbanes-Oxley law, passed after the collapse of Enron in 2001, prevents auditing firms from providing a range of core legal services in the United States. But regulators allow accounting firms to offer nonauditing services, including legal services, to companies for which they don't serve as auditors, the ALM report says.

A chilling wind may be blowing soon – I think the law firm leaders justifiably feel a frisson of fear.

E-mail: snelson@senseient.com Phone: 703-359-0700
Digital Forensics/Information Security/Information Technology
https://www.senseient.com
https://twitter.com/sharonnelsonesq
https://www.linkedin.com/in/sharondnelson
https://amazon.com/author/sharonnelson

Read the whole story
josephwebster
62 days ago
reply
Denver, CO, USA
Share this story
Delete

2017: It’s the greatest time to be alive and simultaneously the worst

2 Shares

How did we get here?

Bob Lefsetz writes the Lefsetz Letter, an email newsletter about music and culture, where this was originally published. Subscribe here.

IT'S THE AGE OF THE INDIVIDUAL

It's all about you, your brand, you're on your own and it's your obligation to establish your status. Used to be you were a member of the faceless masses. Now you're defined online yet retain your anonymity, since in a world of competing identities no one stands out, and when someone does, you wonder why you can't be them. But the truth is there are great swaths of people who are unaware of your hero, seemingly no one dominates, there's no backbone to our culture, it's a swarming mass of unconnected dots, so you just retreat to your mobile and post away about your life, believing it will lend definition, but it doesn't.

MASTERY IS IMPOSSIBLE

You used to know every album, every TV show, every movie. Now there's so much it's incomprehensible. Everybody's talking about their favorites and you feel left out. You want to dig deep and feel a member of the club but who has time to see 13 episodes of this and 39 of that. Meanwhile, those who have not gotten the memo keep telling you they know what's going on and you're inadequate when the truth is no one knows and they're inadequate too.

POSSESSIONS HAVE LOST THEIR MEANING

This is something the older generations cannot accept, just like their forebears could not accept the tumult of the sixties, when the baby boomers disconnected from them. Used to be you were defined by what you owned, that determined status. Now youngsters want to own little and have everything on demand, they want to be foot loose and fancy free. If you're rooted to your big home and your fancy car you're over the hill. Especially when they release a new version of everything soon and what you own is obsolete. That's right, you installed a 5.1 or 9.1 or 13.1 (no that doesn't exist yet, but it will!) system in your house and then find out it's obsolete because it's not voice-controlled and your TV is too small and only 1080 and you get overwhelmed and accept where you are. The hamsters run the wheel trying to keep up, but nobody can keep up. It's really about you and your circle, your own little life, but that would remove you from competition, and life is a sweepstakes, where you're ranked by your credit score, your Instagram followers, and if you're on Twitter, Facebook and Snapchat too, you've got no time to spare, social media is a videogame, even more powerful and addictive than anything emanating from a console, the goal is to post and post until your statistics triumph but just when you've climbed the mountain they change the game with a new platform and you have to start scoring again. It's tedious, and it doesn't keep you warm at night.

ONLINE STATISTICS ARE FAKED

This is the conundrum. You judge someone by their numbers but are they real?

EVERYONE CHEATS

Bill Clinton made it legitimate. Everybody lies to get out of a hole. So you do too. Lawyers took a hit during Watergate and the profession has never regained its status. Truth is for pussies, wimps, everybody's trumpeting falsehoods, it's a cultural cancer. And the person standing up for the truth is more interested in the personal accolades than the cause.

YOU'VE GOT TO SERVE SOMEBODY

No one is disentangled. Bob Dylan had it right. Lisa Bloom is defending Harvey Weinstein whom she has a deal with, because being a lawyer is not enough, you have to be rich and famous and part of the entertainment club.

IF YOU'RE NOT WORKING ON YOUR STATUS, YOU'RE LOSING IT

You've got to be in front of the public every damn day or you're forgotten. Take a couple of years off to lick your wounds and inspire yourself and good luck coming back.

LIFE IS SPORTS

There are two teams, right and left, it's totally tribal, and you're either on one or the other, no one picks one from column A and two from column B.

GROUPTHINK IS PARAMOUNT

You don't want to go against the crowd, against your team, otherwise you'll be ostracized. A nuanced appraisal which shows the situation is complicated just sets you up for hatred from your supposed brethren. The scourge of our society is silence. It's not the law that's got us shutting up, but peer pressure.

FORGIVENESS IS RARE

Commit a faux pas and you're history, taken out of the game, eaten by the lions, hopefully you've got enough money to sustain, because you're not gonna earn any more in your chosen field.

THE MORE EDUCATED YOU ARE, THE MORE SUSCEPTIBLE YOU ARE TO QUACK MEDICAL THEORIES

The elites believe they know better, but they feel powerless like the poor. But they assert their power by believing in quack remedies and refusing to get their children vaccinated.

THE ELITES HAVE CONTEMPT FOR THE POOR AND HAVE NO IDEA HOW THEY LIVE THEIR LIVES

They worked hard to make it, you should too.

So in a world where everything is available at our fingertips, we feel overwhelmed, we feel inadequate, we don't know what our place is in society. We want to fit in, and we don't want to sacrifice our identity to do it. But everywhere we go people are talking about what we don't know and we feel powerless to effect change and all we keep reading is about titans who triumphed who say it was easy leaving out how aggressive they were and what corners they cut.

So the irony is those complaining the loudest are the problem. The newspapers saying they're underpaid. It won't be long before you'll pay for all news, Google is changing its policy, one article will no longer be free. And record companies have buried all the gems from the Napster era. All the alternative and live takes, the unreleased stuff, it's not on Spotify and it's not on YouTube, it's underground once again, meanwhile, the industry is making more money, via streaming.

And the movie industry does not care about you, just China, which invests in it, and the rest of the world which pays to see its high concept movies. How can it be no one you know goes to the movies yet they still get so much ink?

And since everyone needs to be and is entitled to be famous, rankings are abhorred. We cannot separate the wheat from the chaff. So there's an endless buffet of items from McDonald's as well as Spago. You just end up eating at the same place. And eating is another incomprehensible endeavor, you've got to know every food truck and every chef and have an unlimited budget to partake.

Meanwhile, the rich are getting richer and you're still complaining.

So, it's the greatest time to be alive and simultaneously the worst. No one can be bored anymore, the history of entertainment is at your fingertips and you can communicate with everybody you've ever known instantly. But you're lacking meaning in life, while charlatans tell you they have the answer, whether it be the religious right or the bogus left. So you're left with yourself, which brings us back to the beginning, you're fighting for your space on the planet yet keep being told you don't matter, and feeling meaningless to boot. How did we get here?

One thing's for sure, we're never going back. Ignore the Luddites complaining about the negative consequences of screen time, they think if they yell loud enough the past will come back, but it won't.

And the tech titans lack moral responsibility.

So it really does come down to you, and humanity. Give up the race to consume. Give up the attempt to be all-knowing. Information is important, but soft knowledge eclipses it. Relationships, philosophy, those haven't been changed by the technological revolution, but they've been backwatered by industrialists who want to sell you something.

We are in a personal crisis. A moral crisis. We're unsure how to lead our lives. We want someone to make sense of it all, to point us where to go, so we can be part of the universe, feel connected, because too much of this so-called connection online is leaving us unfulfilled. We've got the bounty, but we're empty inside.

When you get the answer, tell me.

Bob Lefsetz writes the Lefsetz Letter, an email newsletter about music and culture, where this was originally published. Subscribe here or follow Bob on Twitter at @Lefsetz.


Read the whole story
josephwebster
67 days ago
reply
Denver, CO, USA
JayM
67 days ago
reply
Atlanta, GA
Share this story
Delete
Next Page of Stories