From: "David D" <david[at]7tele.com>
To: "XXXYYY discussion list'"
<XXXat]YYY.net>
Date: Mon, 9 Sep 2013 12:56:17 +0200
Subject: Re: [cryptography] New NSA Slides and Details Released last night
via Fantastico (BR)
http://g1.globo.com/fantastico/noticia/2013/09/nsa-documents-show-united-
states-spied-brazilian-oil-giant.html
No millisecond counter:
1:49 US-983 Stormbrew - Fiber connections
1:49 US-983 Stormbrew - "KEY CORPORATE PARTNER WITH ACCESS TO INTERNATIONAL
CABLES, ROUTERS, AND SWITCHES". (# traceroute google.com)
2:07 - "QUERY BY CERTIFICATE META DATA"
2:07 - "Private keys of Diginotar stolen by hacker" FLYING
PIG ...
Launch a MITM attack.
2:08 - mail.ru and server IP: 94.100.104.14
This site has broken out some of the screenshots from the video:
http://leaksource.wordpress.com/2013/09/09/economic-espionage-nsa-
spies-on-brazil-oil-giant-petrobras/
"How the attack was done:" image is most interesting.
http://leaksource.files.wordpress.com/2013/09/nsa-brazil-5.png
Based on this slide, it appears that the bandwidth providers are dumping
the
traffic at core routers directly to the NSA.
Tuesday, September 10, 2013
Monday, September 9, 2013
The Cowboy of the NSA Keith Alexander
The Cowboy of the NSA Keith Alexander
http://www.foreignpolicy.com/articles/2013/09/08/the_cowboy_of_the_nsa_keith_alexander
Foreign Policy Magazine
The Cowboy of the NSA
Inside Gen. Keith Alexander's all-out, barely-legal drive to build the ultimate spy machine.
On Aug. 1, 2005, Lt. Gen. Keith Alexander reported for duty as the 16th director of the National Security Agency, the United States' largest intelligence organization. He seemed perfect for the job. Alexander was a decorated Army intelligence officer and a West Point graduate with master's degrees in systems technology and physics. He had run intelligence operations in combat and had held successive senior-level positions, most recently as the director of an Army intelligence organization and then as the service's overall chief of intelligence. He was both a soldier and a spy, and he had the heart of a tech geek. Many of his peers thought Alexander would make a perfect NSA director. But one prominent person thought otherwise: the prior occupant of that office.
The heartburn first flared up not long after the 2001 terrorist attacks. Alexander was the general in charge of the Army's Intelligence and Security Command (INSCOM) at Fort Belvoir, Virginia. He began insisting that the NSA give him raw, unanalyzed data about suspected terrorists from the agency's massive digital cache, according to three former intelligence officials. Alexander had been building advanced data-mining software and analytic tools, and now he wanted to run them against the NSA's intelligence caches to try to find terrorists who were in the United States or planning attacks on the homeland.
By law, the NSA had to scrub intercepted communications of most references to U.S. citizens before those communications can be shared with other agencies. But Alexander wanted the NSA "to bend the pipe towards him," says one of the former officials, so that he could siphon off metadata, the digital records of phone calls and email traffic that can be used to map out a terrorist organization based on its members' communications patterns.
"Keith wanted his hands on the raw data. And he bridled at the fact that NSA didn't want to release the information until it was properly reviewed and in a report," says a former national security official. "He felt that from a tactical point of view, that was often too late to be useful."
Hayden thought Alexander was out of bounds. INSCOM was supposed to provide battlefield intelligence for troops and special operations forces overseas, not use raw intelligence to find terrorists within U.S. borders. But Alexander had a more expansive view of what military intelligence agencies could do under the law.
"He said at one point that a lot of things aren't clearly legal, but that doesn't make them illegal," says a former military intelligence officer who served under Alexander at INSCOM.
In November 2001, the general in charge of all Army intelligence had informed his personnel, including Alexander, that the military had broad authority to collect and share information about Americans, so long as they were "reasonably believed to be engaged" in terrorist activities, the general wrote in a widely distributed memo.
The general didn't say how exactly to make this determination, but it was all the justification Alexander needed. "Hayden's attitude was 'Yes, we have the technological capability, but should we use it?' Keith's was 'We have the capability, so let's use it,'" says the former intelligence official who worked with both men.
Hayden denied Alexander's request for NSA data. And there was some irony in that decision. At the same time, Hayden was overseeing a highly classified program to monitor Americans' phone records and Internet communications without permission from a court. At least one component of that secret domestic spying program would later prompt senior Justice Department officials to threaten resignation because they thought it was illegal.
But that was a presidentially authorized program run by a top-tier national intelligence agency. Alexander was a midlevel general who seemed to want his own domestic spying operation. Hayden was so troubled that he reported Alexander to his commanding general, a former colleague says. "He didn't use that atomic word -- 'insubordination' -- but he danced around it."
The showdown over bending the NSA's pipes was emblematic of Alexander's approach to intelligence, one he has honed over the course of a 39-year military career and deploys today as the director of the country's most powerful spy agency.
Alexander wants as much data as he can get. And he wants to hang on to it for as long as he can. To prevent the next terrorist attack, he thinks he needs to be able to see entire networks of communications and also go "back in time," as he has said publicly, to study how terrorists and their networks evolve. To find the needle in the haystack, he needs the entire haystack.
"Alexander's strategy is the same as Google's: I need to get all of the data," says a former administration official who worked with the general. "If he becomes the repository for all that data, he thinks the resources and authorities will follow."
That strategy has worked well for Alexander. He has served longer than any director in the NSA's history, and today he stands atop a U.S. surveillance empire in which signals intelligence, the agency's specialty, is the coin of the realm. In 2010, he became the first commander of the newly created U.S. Cyber Command, making him responsible for defending military computer networks against spies, hackers, and foreign armed forces -- and for fielding a new generation of cyberwarriors trained to penetrate adversaries' networks. Fueled by a series of relentless and increasingly revealing leaks from former NSA contractor Edward Snowden, the full scope of Alexander's master plan is coming to light.
Today, the agency is routinely scooping up and storing Americans' phone records. It is screening their emails and text messages, even though the spy agency can't always tell the difference between an innocent American and a foreign terrorist. The NSA uses corporate proxies to monitor up to 75 percent of Internet traffic inside the United States. And it has spent billions of dollars on a secret campaign to foil encryption technologies that individuals, corporations, and governments around the world had long thought protected the privacy of their communications from U.S. intelligence agencies.
The NSA was already a data behemoth when Alexander took over. But under his watch, the breadth, scale, and ambition of its mission have expanded beyond anything ever contemplated by his predecessors. In 2007, the NSA began collecting information from Internet and technology companies under the so-called PRISM program. In essence, it was a pipes-bending operation. The NSA gets access to the companies' raw data--including e-mails, video chats, and messages sent through social media--and analysts then mine it for clues about terrorists and other foreign intelligence subjects. Similar to how Alexander wanted the NSA to feed him with intelligence at INSCOM, now some of the world's biggest technology companies -- including Google, Microsoft, Facebook, and Apple -- are feeding the NSA. But unlike Hayden, the companies cannot refuse Alexander's advances. The PRISM program operates under a legal regime, put in place a few years after Alexander arrived at the NSA, that allows the agency to demand broad categories of information from technology companies.
Never in history has one agency of the U.S. government had the capacity, as well as the legal authority, to collect and store so much electronic information. Leaked NSA documents show the agency sucking up data from approximately 150 collection sites on six continents. The agency estimates that 1.6 percent of all data on the Internet flows through its systems on a given day -- an amount of information about 50 percent larger than what Google processes in the same period.
When Alexander arrived, the NSA was secretly investing in experimental databases to store these oceans of electronic signals and give analysts access to it all in as close to real time as possible. Under his direction, it has helped pioneer new methods of massive storage and retrieval. That has led to a data glut. The agency has collected so much information that it ran out of storage capacity at its 350-acre headquarters at Fort Meade, Maryland, outside Washington, D.C. At a cost of more than $2 billion, it has built a new processing facility in the Utah desert, and it recently broke ground on a complex in Maryland. There is a line item in the NSA's budget just for research on "coping with information overload."
Yet it's still not enough for Alexander, who has proposed installing the NSA's surveillance equipment on the networks of defense contractors, banks, and other organizations deemed essential to the U.S. economy or national security. Never has this intelligence agency -- whose primary mission is espionage, stealing secrets from other governments -- proposed to become the electronic watchman of American businesses.
This kind of radical expansion shouldn't come as a surprise. In fact, it's a hallmark of Alexander's career. During the Iraq war, for example, he pioneered a suite of real-time intelligence analysis tools that aimed to scoop up every phone call, email, and text message in the country in a search for terrorists and insurgents. Military and intelligence officials say it provided valuable insights that helped turn the tide of the war. It was also unprecedented in its scope and scale. He has transferred that architecture to a global scale now, and with his responsibilities at Cyber Command, he is expanding his writ into the world of computer network defense and cyber warfare.
As a result, the NSA has never been more powerful, more pervasive, and more politically imperiled. The same philosophy that turned Alexander into a giant -- acquire as much data from as many sources as possible -- is now threatening to undo him. Alexander today finds himself in the unusual position of having to publicly defend once-secret programs and reassure Americans that the growth of his agency, which employs more than 35,000 people, is not a cause for alarm. In July, the House of Representatives almost approved a law to constrain the NSA's authorities -- the closest Congress has come to reining in the agency since the 9/11 attacks. That narrow defeat for surveillance opponents has set the stage for a Supreme Court ruling on whether metadata -- the information Alexander has most often sought about Americans -- should be afforded protection under the Fourth Amendment's prohibition against "unreasonable searches and seizures," which would make metadata harder for the government to acquire.
Alexander declined Foreign Policy's request for an interview, but in response to questions about his leadership, his respect for civil liberties, and the Snowden leaks, he provided a written statement.
"The missions of NSA and USCYBERCOM are conducted in a manner that is lawful, appropriate, and effective, and under the oversight of all three branches of the U.S. government," Alexander stated. "Our mission is to protect our people and defend the nation within the authorities granted by Congress, the courts and the president. There is an ongoing investigation into the damage sustained by our nation and our allies because of the recent unauthorized disclosure of classified material. Based on what we know to date, we believe these disclosures have caused significant and irreversible harm to the security of the nation."
In lieu of an interview about his career, Alexander's spokesperson recommended a laudatory profile about him that appeared in West Point magazine. It begins: "At key moments throughout its history, the United States has been fortunate to have the right leader -- someone with an ideal combination of rare talent and strong character -- rise to a position of great responsibility in public service. With General Keith B. Alexander ... Americans are again experiencing this auspicious state of affairs."
Lawmakers and the public are increasingly taking a different view. They are skeptical about what Alexander has been doing with all the data he's collecting -- and why he's been willing to push the bounds of the law to get it. If he's going to preserve his empire, he'll have to mount the biggest charm offensive of his career. Fortunately for him, Alexander has spent as much time building a political base of power as a technological one.
* * *
Those who know Alexander say he is introspective, self-effacing, and even folksy. He's fond of corny jokes and puns and likes to play pool, golf, and Bejeweled Blitz, the addictive puzzle game, on which he says he routinely scores more than 1 million points.
Alexander is also as skilled a Washington knife fighter as they come. To get the NSA job, he allied himself with the Pentagon brass, most notably Donald Rumsfeld, who distrusted Hayden and thought he had been trying to buck the Pentagon's control of the NSA. Alexander also called on all the right committee members on Capitol Hill, the overseers and appropriators who hold the NSA's future in their hands.
When he was running the Army's Intelligence and Security Command, Alexander brought many of his future allies down to Fort Belvoir for a tour of his base of operations, a facility known as the Information Dominance Center. It had been designed by a Hollywood set designer to mimic the bridge of the starship Enterprise from Star Trek, complete with chrome panels, computer stations, a huge TV monitor on the forward wall, and doors that made a "whoosh" sound when they slid open and closed. Lawmakers and other important officials took turns sitting in a leather "captain's chair" in the center of the room and watched as Alexander, a lover of science-fiction movies, showed off his data tools on the big screen.
"Everybody wanted to sit in the chair at least once to pretend he was Jean-Luc Picard," says a retired officer in charge of VIP visits.
Alexander wowed members of Congress with his eye-popping command center. And he took time to sit with them in their offices and explain the intricacies of modern technology in simple, plain-spoken language. He demonstrated a command of the subject without intimidating those who had none.
"Alexander is 10 times the political general as David Petraeus," says the former administration official, comparing the NSA director to a man who was once considered a White House contender. "He could charm the paint off a wall."
Alexander has had to muster every ounce of that political savvy since the Snowden leaks started coming in June. In closed-door briefings, members of Congress have accused him of deceiving them about how much information he has been collecting on Americans. Even when lawmakers have screamed at him from across the table, Alexander has remained "unflappable," says a congressional staffer who has sat in on numerous private briefings since the Snowden leaks. Instead of screaming back, he reminds lawmakers about all the terrorism plots that the NSA has claimed to help foil.
"He is well aware that he will be criticized if there's another attack," the staffer says. "He has said many times, 'My job is to protect the American people. And I have to be perfect.'"
There's an implied threat in that statement. If Alexander doesn't get all the information he wants, he cannot do his job. "He never says it explicitly, but the message is, 'You don't want to be the one to make me miss,'" says the former administration official. "You don't want to be the one that denied me these capabilities before the next attack."
Alexander has a distinct advantage over most, if not all, intelligence chiefs in the government today: He actually understands the multibillion-dollar technical systems that he's running.
"When he would talk to our engineers, he would get down in the weeds as far as they were. And he'd understand what they were talking about," says a former NSA official. In that respect, he had a leg up on Hayden, who colleagues say is a good big-picture thinker but lacks the geek gene that Alexander was apparently born with.
"He looked at the technical aspects of the agency more so than any director I've known," says Richard "Dickie" George, who spent 41 years at the NSA and retired as the technical director of the Information Assurance Directorate. "I get the impression he would have been happy being one of those guys working down in the noise," George said, referring to the front-line technicians and analysts working to pluck signals out of the network.
Alexander, 61, has been a techno-spy since the beginning of his military career. After graduating from West Point in 1974, he went to West Germany, where he was initiated in the dark arts of signals intelligence. Alexander spent his time eavesdropping on military communications emanating from East Germany and Czechoslovakia. He was interested in the mechanics that supported this brand of espionage. He rose quickly through the ranks.
"It's rare to get a commander who understands technology," says a former Army officer who served with Alexander in 1995, when Alexander was in charge of the 525th Military Intelligence Brigade at Fort Bragg, North Carolina. "Even then he was into big data. You think of the wizards as the guys who are in their 20s." Alexander was 42 at the time.
At the turn of the century, Alexander took the big-data approach to counterterrorism. How well that method worked continues to be a matter of intense debate. Surely discrete interceptions of terrorists' phone calls and emails have helped disrupt plots and prevent attacks. But huge volumes of data don't always help catch potential plotters. Sometimes, the drive for more data just means capturing more ordinary people in the surveillance driftnet.
When he ran INSCOM and was horning in on the NSA's turf, Alexander was fond of building charts that showed how a suspected terrorist was connected to a much broader network of people via his communications or the contacts in his phone or email account.
"He had all these diagrams showing how this guy was connected to that guy and to that guy," says a former NSA official who heard Alexander give briefings on the floor of the Information Dominance Center. "Some of my colleagues and I were skeptical. Later, we had a chance to review the information. It turns out that all [that] those guys were connected to were pizza shops."
A retired military officer who worked with Alexander also describes a "massive network chart" that was purportedly about al Qaeda and its connections in Afghanistan. Upon closer examination, the retired officer says, "We found there was no data behind the links. No verifiable sources. We later found out that a quarter of the guys named on the chart had already been killed in Afghanistan."
Those network charts have become more massive now that Alexander is running the NSA. When analysts try to determine if a particular person is engaged in terrorist activity, they may look at the communications of people who are as many as three steps, or "hops," removed from the original target. This means that even when the NSA is focused on just one individual, the number of people who are being caught up in the agency's electronic nets could easily be in the tens of millions.
According to an internal audit, the agency's surveillance operations have been beset by human error and fooled by moving targets. After the NSA's legal authorities were expanded and the PRISM program was implemented, the agency inadvertently collected Americans' communications thousands of times each year, between 2008 and 2012, in violation of privacy rules and the law.
Yet the NSA still pursued a counterterrorism strategy that relies on ever-bigger data sets. Under Alexander's leadership, one of the agency's signature analysis tools was a digital graph that showed how hundreds, sometimes thousands, of people, places, and events were connected to each other. They were displayed as a tangle of dots and lines. Critics called it the BAG -- for "big ass graph" -- and said it produced very few useful leads. CIA officials in charge of tracking overseas terrorist cells were particularly unimpressed by it. "I don't need this," a senior CIA officer working on the agency's drone program once told an NSA analyst who showed up with a big, nebulous graph. "I just need you to tell me whose ass to put a Hellfire missile on."
Given his pedigree, it's unsurprising that Alexander is a devotee of big data. "It was taken as a given for him, as a career intelligence officer, that more information is better," says another retired military officer. "That was ingrained."
But Alexander was never alone in his obsession. An obscure civilian engineer named James Heath has been a constant companion for a significant portion of Alexander's career. More than any one person, Heath influenced how the general went about building an information empire.
Several former intelligence officials who worked with Heath described him as Alexander's "mad scientist." Another called him the NSA director's "evil genius." For years, Heath, a brilliant but abrasive technologist, has been in charge of making Alexander's most ambitious ideas a reality; many of the controversial data-mining tools that Alexander wanted to use against the NSA's raw intelligence were developed by Heath, for example. "He's smart, crazy, and dangerous. He'll push the technology to the limits to get it to do what he wants," says a former intelligence official.
Heath has followed Alexander from post to post, but he almost always stays in the shadows. Heath recently retired from government service as the senior science advisor to the NSA director -- Alexander's personal tech guru. "The general really looked to him for advice," says George, the former technical director. "Jim didn't mind breaking some eggs to make an omelet. He couldn't do that on his own, but General Alexander could. They brought a sense of needing to get things done. They were a dynamic duo."
Precisely where Alexander met Heath is unclear. They have worked together since at least 1995, when Alexander commanded the 525th Military Intelligence Brigade and Heath was his scientific sidekick. "That's where Heath took his first runs at what he called 'data visualization,' which is now called 'big data,'" says a retired military intelligence officer. Heath was building tools that helped commanders on the field integrate information from different sensors -- reconnaissance planes, satellites, signals intercepts -- and "see" it on their screens. Later, Heath would work with tools that showed how words in a document or pages on the Internet were linked together, displaying those connections in the form of three-dimensional maps and graphs.
At the Information Dominance Center, Heath built a program called the "automatic ingestion manager." It was a search engine for massive sets of data, and in 1999, he started taking it for test runs on the Internet.
In one experiment, the retired officer says, the ingestion manager searched for all web pages linked to the website of the Defense Intelligence Agency (DIA). Those included every page on the DIA's site, and the tool scoured and copied them so aggressively that it was mistaken for a hostile cyberattack. The site's automated defenses kicked in and shut it down.
On another occasion, the searching tool landed on an anti-war website while searching for information about the conflict in Kosovo. "We immediately got a letter from the owner of the site wanting to know why was the military spying on him," the retired officer says. As far as he knows, the owner took no legal action against the Army, and the test run was stopped.
Those experiments with "bleeding-edge" technology, as the denizens of the Information Dominance Center liked to call it, shaped Heath and Alexander's approach to technology in spy craft. And when they ascended to the NSA in 2005, their influence was broad and profound. "These guys have propelled the intelligence community into big data," says the retired officer.
Heath was at Alexander's side for the expansion of Internet surveillance under the PRISM program. Colleagues say it fell largely to him to design technologies that tried to make sense of all the new information the NSA was gobbling up. But Heath had developed a reputation for building expensive systems that never really work as promised and then leaving them half-baked in order to follow Alexander on to some new mission.
"He moved fairly fast and loose with money and spent a lot of it," the retired officer says. "He doubled the size of the Information Dominance Center and then built another facility right next door to it. They didn't need it. It's just what Heath and Alexander wanted to do." The Information Operations Center, as it was called, was underused and spent too much money, says the retired officer. "It's a center in search of a customer."
Heath's reputation followed him to the NSA. In early 2010, weeks after a young al Qaeda terrorist with a bomb sewn into his underwear tried to bring down a U.S. airliner over Detroit on Christmas Day, the director of national intelligence, Dennis Blair, called for a new tool that would help the disparate intelligence agencies better connect the dots about terrorism plots. The NSA, the State Department, and the CIA each had possessed fragments of information about the so-called underwear bomber's intentions, but there had been no dependable mechanism for integrating them all and providing what one former national security official described as "a quick-reaction capability" so that U.S. security agencies would be warned about the bomber before he got on the plane.
Blair put the NSA in charge of building this new capability, and the task eventually fell to Heath. "It was a complete disaster," says the former national security official, who was briefed on the project. "Heath's approach was all based on signals intelligence [the kind the NSA routinely collects] rather than taking into account all the other data coming in from the CIA and other sources. That's typical of Heath. He's got a very narrow viewpoint to solve a problem."
Like other projects of Heath's, the former official says, this one was never fully implemented. As a result, the intelligence community still didn't have a way to stitch together clues from different databases in time to stop the next would-be bomber. Heath -- and Alexander -- moved on to the next big project.
"There's two ways of looking at these guys," the retired military officer says. "Two visionaries who took risks and pushed the intelligence community forward. Or as two guys who blew a monumental amount of money."
As immense as the NSA's mission has become -- patrolling the world's data fields in search of terrorists, spies, and computer hackers -- it is merely one phase of Alexander's plan. The NSA's primary mission is to protect government systems and information. But under his leadership, the agency is also extending its reach into the private sector in unprecedented ways.
Toward the end of George W. Bush's administration, Alexander helped persuade Defense Department officials to set up a computer network defense project to prevent foreign intelligence agencies --mainly China's -- from stealing weapons plans and other national secrets from government contractors' computers.
Under the Defense Industrial Base initiative, also known as the DIB, the NSA provides the companies with intelligence about the cyberthreats it's tracking. In return, the companies report back about what they see on their networks and share intelligence with each other.
Pentagon officials say the program has helped stop some cyber-espionage. But many corporate participants say Alexander's primary motive has not been to share what the NSA knows about hackers. It's to get intelligence from the companies -- to make them the NSA's digital scouts. What is billed as an information-sharing arrangement has sometimes seemed more like a one-way street, leading straight to the NSA's headquarters at Fort Meade.
"We wanted companies to be able to share information with each other," says the former administration official, "to create a picture about the threats against them. The NSA wanted the picture."
After the DIB was up and running, Alexander proposed going further. "He wanted to create a wall around other sensitive institutions in America, to include financial institutions, and to install equipment to monitor their networks," says the former administration official. "He wanted this to be running in every Wall Street bank."
That aspect of the plan has never been fully implemented, largely due to legal concerns. If a company allowed the government to install monitoring equipment on its systems, a court could decide that the company was acting as an agent of the government. And if surveillance were conducted without a warrant or legitimate connection to an investigation, the company could be accused of violating the Fourth Amendment. Warrantless surveillance can be unconstitutional regardless of whether the NSA or Google or Goldman Sachs is doing it.
"That's a subtle point, and that subtlety was often lost on NSA," says the former administration official. "Alexander has ignored that Fourth Amendment concern."
The DIB experiment was a first step toward Alexander's taking more control over the country's cyberdefenses, and it was illustrative of his assertive approach to the problem. "He was always challenging us on the defensive side to be more aware and to try and find and counter the threat," says Tony Sager, who was the chief operating officer for the NSA's Information Assurance Directorate, which protects classified government information and computers. "He wanted to know, 'Who are the bad guys? How do we go after them?'"
While it's a given that the NSA cannot monitor the entire Internet on its own and that it needs intelligence from companies, Alexander has questioned whether companies have the capacity to protect themselves. "What we see is an increasing level of activity on the networks," he said recently at a security conference in Canada. "I am concerned that this is going to break a threshold where the private sector can no longer handle it and the government is going to have to step in."
* * *
Now, for the first time in Alexander's career, Congress and the general public are expressing deep misgivings about sharing information with the NSA or letting it install surveillance equipment. A Rasmussen poll of likely voters taken in June found that 68 percent believe it's likely the government is listening to their communications, despite repeated assurances from Alexander and President Barack Obama that the NSA is only collecting anonymous metadata about Americans' phone calls. In another Rasmussen poll, 57 percent of respondents said they think it's likely that the government will use NSA intelligence "to harass political opponents."
Some who know Alexander say he doesn't appreciate the depth of public mistrust and cynicism about the NSA's mission. "People in the intelligence community in general, and certainly Alexander, don't understand the strategic value of having a largely unified country and a long-term trust in the intelligence business," says a former intelligence official, who has worked with Alexander. Another adds, "There's a feeling within the NSA that they're all patriotic citizens interested in protecting privacy, but they lose sight of the fact that people don't trust the government."
Even Alexander's strongest critics don't doubt his good intentions. "He's not a nefarious guy," says the former administration official. "I really do feel like he believes he's doing this for the right reasons." Two of the retired military officers who have worked with him say Alexander was seared by the bombing of the USS Cole in 2000 and later the 9/11 attacks, a pair of major intelligence failures that occurred while he was serving in senior-level positions in military intelligence. They said he vowed to do all he could to prevent another attack that could take the lives of Americans and military service members.
But those who've worked closely with Alexander say he has become blinded by the power of technology. "He believes they have enough technical safeguards in place at the NSA to protect civil liberties and perform their mission," the former administration official says. "They do have a very robust capability -- probably better than any other agency. But he doesn't get that this power can still be abused. Americans want introspection. Transparency is a good thing. He doesn't understand that. In his mind it's 'You should trust me, and in exchange, I give you protection.'"
On July 30 in Las Vegas, Alexander sat down for dinner with a group of civil liberties activists and Internet security researchers. He was in town to give a keynote address the next day at the Black Hat security conference. The mood at the table was chilly, according to people who were in attendance. In 2012, Alexander had won plaudits for his speech at Black Hat's sister conference, Def Con, in which he'd implored the assembled community of experts to join him in their mutual cause: protecting the Internet as a safe space for speech, communications, and commerce. Now, however, nearly two months after the first leaks from Snowden, the people around the table wondered whether they could still trust the NSA director.
His dinner companions questioned Alexander about the NSA's legal authority to conduct massive electronic surveillance. Two guests had recently written a New York Times op-ed calling the NSA's activities "criminal." Alexander was quick to debate the finer points of the law and defend his agency's programs -- at least the ones that have been revealed -- as closely monitored and focused solely on terrorists' information.
But he also tried to convince his audience that they should help keep the NSA's surveillance system running. In so many words, Alexander told them: The terrorists only have to succeed once to kill thousands of people. And if they do, all of the rules we have in place to protect people's privacy will go out the window.
Alexander cast himself as the ultimate defender of civil liberties, as a man who needs to spy on some people in order to protect everyone. He knows that in the wake of another major terrorist attack on U.S. soil, the NSA will be unleashed to find the perpetrators and stop the next assault. Random searches of metadata, broad surveillance of purely domestic communications, warrantless seizure of stored communications -- presumably these and other extraordinary measures would be on the table. Alexander may not have spelled out just what the NSA would do after another homeland strike, but the message was clear: We don't want to find out.
Alexander was asking his dinner companions to trust him. But his credibility has been badly damaged. Alexander was heckled at his speech the next day at Black Hat. He had been slated to talk at Def Con too, but the organizers rescinded their invitation after the Snowden leaks. And even among Alexander's cohort, trust is flagging.
"You'll never find evidence that Keith sits in his office at lunch listening to tapes of U.S. conversations," says a former NSA official. "But I think he has a little bit of naiveté about this controversy. He thinks, 'What's the problem? I wouldn't abuse this power. Aren't we all honorable people?' People get into these insular worlds out there at NSA. I think Keith fits right in."
One of the retired military officers, who worked with Alexander on several big-data projects, said he was shaken by revelations that the agency is collecting all Americans' phone records and examining enormous amounts of Internet traffic. "I've not changed my opinion on the right balance between security versus privacy, but what the NSA is doing bothers me," he says. "It's the massive amount of information they're collecting. I know they're not listening to everyone's phone calls. No one has time for that. But speaking as an analyst who has used metadata, I do not sleep well at night knowing these guys can see everything. That trust has been lost."
http://www.foreignpolicy.com/articles/2013/09/08/the_cowboy_of_the_nsa_keith_alexander
Foreign Policy Magazine
The Cowboy of the NSA
Inside Gen. Keith Alexander's all-out, barely-legal drive to build the ultimate spy machine.
Shane Harris is a senior writer for Foreign Policy and author of The Watchers: The Rise of America's Surveillance State.
On Aug. 1, 2005, Lt. Gen. Keith Alexander reported for duty as the 16th director of the National Security Agency, the United States' largest intelligence organization. He seemed perfect for the job. Alexander was a decorated Army intelligence officer and a West Point graduate with master's degrees in systems technology and physics. He had run intelligence operations in combat and had held successive senior-level positions, most recently as the director of an Army intelligence organization and then as the service's overall chief of intelligence. He was both a soldier and a spy, and he had the heart of a tech geek. Many of his peers thought Alexander would make a perfect NSA director. But one prominent person thought otherwise: the prior occupant of that office.
Air Force Gen. Michael Hayden had been running the NSA since 1999, through
the 9/11 terrorist attacks and into a new era that found the global eavesdropping
agency increasingly focused on Americans' communications inside the United
States. At times, Hayden had found himself swimming in the murkiest depths
of the law, overseeing programs that other senior officials in government
thought violated the Constitution. Now Hayden of all people was worried that
Alexander didn't understand the legal sensitivities of that new mission.
"Alexander tended to be a bit of a cowboy: 'Let's not worry about the law.
Let's just figure out how to get the job done,'" says a former intelligence
official who has worked with both men. "That caused General Hayden some
heartburn."
The heartburn first flared up not long after the 2001 terrorist attacks. Alexander was the general in charge of the Army's Intelligence and Security Command (INSCOM) at Fort Belvoir, Virginia. He began insisting that the NSA give him raw, unanalyzed data about suspected terrorists from the agency's massive digital cache, according to three former intelligence officials. Alexander had been building advanced data-mining software and analytic tools, and now he wanted to run them against the NSA's intelligence caches to try to find terrorists who were in the United States or planning attacks on the homeland.
By law, the NSA had to scrub intercepted communications of most references to U.S. citizens before those communications can be shared with other agencies. But Alexander wanted the NSA "to bend the pipe towards him," says one of the former officials, so that he could siphon off metadata, the digital records of phone calls and email traffic that can be used to map out a terrorist organization based on its members' communications patterns.
"Keith wanted his hands on the raw data. And he bridled at the fact that NSA didn't want to release the information until it was properly reviewed and in a report," says a former national security official. "He felt that from a tactical point of view, that was often too late to be useful."
Hayden thought Alexander was out of bounds. INSCOM was supposed to provide battlefield intelligence for troops and special operations forces overseas, not use raw intelligence to find terrorists within U.S. borders. But Alexander had a more expansive view of what military intelligence agencies could do under the law.
"He said at one point that a lot of things aren't clearly legal, but that doesn't make them illegal," says a former military intelligence officer who served under Alexander at INSCOM.
In November 2001, the general in charge of all Army intelligence had informed his personnel, including Alexander, that the military had broad authority to collect and share information about Americans, so long as they were "reasonably believed to be engaged" in terrorist activities, the general wrote in a widely distributed memo.
The general didn't say how exactly to make this determination, but it was all the justification Alexander needed. "Hayden's attitude was 'Yes, we have the technological capability, but should we use it?' Keith's was 'We have the capability, so let's use it,'" says the former intelligence official who worked with both men.
Hayden denied Alexander's request for NSA data. And there was some irony in that decision. At the same time, Hayden was overseeing a highly classified program to monitor Americans' phone records and Internet communications without permission from a court. At least one component of that secret domestic spying program would later prompt senior Justice Department officials to threaten resignation because they thought it was illegal.
But that was a presidentially authorized program run by a top-tier national intelligence agency. Alexander was a midlevel general who seemed to want his own domestic spying operation. Hayden was so troubled that he reported Alexander to his commanding general, a former colleague says. "He didn't use that atomic word -- 'insubordination' -- but he danced around it."
The showdown over bending the NSA's pipes was emblematic of Alexander's approach to intelligence, one he has honed over the course of a 39-year military career and deploys today as the director of the country's most powerful spy agency.
Alexander wants as much data as he can get. And he wants to hang on to it for as long as he can. To prevent the next terrorist attack, he thinks he needs to be able to see entire networks of communications and also go "back in time," as he has said publicly, to study how terrorists and their networks evolve. To find the needle in the haystack, he needs the entire haystack.
"Alexander's strategy is the same as Google's: I need to get all of the data," says a former administration official who worked with the general. "If he becomes the repository for all that data, he thinks the resources and authorities will follow."
That strategy has worked well for Alexander. He has served longer than any director in the NSA's history, and today he stands atop a U.S. surveillance empire in which signals intelligence, the agency's specialty, is the coin of the realm. In 2010, he became the first commander of the newly created U.S. Cyber Command, making him responsible for defending military computer networks against spies, hackers, and foreign armed forces -- and for fielding a new generation of cyberwarriors trained to penetrate adversaries' networks. Fueled by a series of relentless and increasingly revealing leaks from former NSA contractor Edward Snowden, the full scope of Alexander's master plan is coming to light.
Today, the agency is routinely scooping up and storing Americans' phone records. It is screening their emails and text messages, even though the spy agency can't always tell the difference between an innocent American and a foreign terrorist. The NSA uses corporate proxies to monitor up to 75 percent of Internet traffic inside the United States. And it has spent billions of dollars on a secret campaign to foil encryption technologies that individuals, corporations, and governments around the world had long thought protected the privacy of their communications from U.S. intelligence agencies.
The NSA was already a data behemoth when Alexander took over. But under his watch, the breadth, scale, and ambition of its mission have expanded beyond anything ever contemplated by his predecessors. In 2007, the NSA began collecting information from Internet and technology companies under the so-called PRISM program. In essence, it was a pipes-bending operation. The NSA gets access to the companies' raw data--including e-mails, video chats, and messages sent through social media--and analysts then mine it for clues about terrorists and other foreign intelligence subjects. Similar to how Alexander wanted the NSA to feed him with intelligence at INSCOM, now some of the world's biggest technology companies -- including Google, Microsoft, Facebook, and Apple -- are feeding the NSA. But unlike Hayden, the companies cannot refuse Alexander's advances. The PRISM program operates under a legal regime, put in place a few years after Alexander arrived at the NSA, that allows the agency to demand broad categories of information from technology companies.
Never in history has one agency of the U.S. government had the capacity, as well as the legal authority, to collect and store so much electronic information. Leaked NSA documents show the agency sucking up data from approximately 150 collection sites on six continents. The agency estimates that 1.6 percent of all data on the Internet flows through its systems on a given day -- an amount of information about 50 percent larger than what Google processes in the same period.
When Alexander arrived, the NSA was secretly investing in experimental databases to store these oceans of electronic signals and give analysts access to it all in as close to real time as possible. Under his direction, it has helped pioneer new methods of massive storage and retrieval. That has led to a data glut. The agency has collected so much information that it ran out of storage capacity at its 350-acre headquarters at Fort Meade, Maryland, outside Washington, D.C. At a cost of more than $2 billion, it has built a new processing facility in the Utah desert, and it recently broke ground on a complex in Maryland. There is a line item in the NSA's budget just for research on "coping with information overload."
Yet it's still not enough for Alexander, who has proposed installing the NSA's surveillance equipment on the networks of defense contractors, banks, and other organizations deemed essential to the U.S. economy or national security. Never has this intelligence agency -- whose primary mission is espionage, stealing secrets from other governments -- proposed to become the electronic watchman of American businesses.
This kind of radical expansion shouldn't come as a surprise. In fact, it's a hallmark of Alexander's career. During the Iraq war, for example, he pioneered a suite of real-time intelligence analysis tools that aimed to scoop up every phone call, email, and text message in the country in a search for terrorists and insurgents. Military and intelligence officials say it provided valuable insights that helped turn the tide of the war. It was also unprecedented in its scope and scale. He has transferred that architecture to a global scale now, and with his responsibilities at Cyber Command, he is expanding his writ into the world of computer network defense and cyber warfare.
As a result, the NSA has never been more powerful, more pervasive, and more politically imperiled. The same philosophy that turned Alexander into a giant -- acquire as much data from as many sources as possible -- is now threatening to undo him. Alexander today finds himself in the unusual position of having to publicly defend once-secret programs and reassure Americans that the growth of his agency, which employs more than 35,000 people, is not a cause for alarm. In July, the House of Representatives almost approved a law to constrain the NSA's authorities -- the closest Congress has come to reining in the agency since the 9/11 attacks. That narrow defeat for surveillance opponents has set the stage for a Supreme Court ruling on whether metadata -- the information Alexander has most often sought about Americans -- should be afforded protection under the Fourth Amendment's prohibition against "unreasonable searches and seizures," which would make metadata harder for the government to acquire.
Alexander declined Foreign Policy's request for an interview, but in response to questions about his leadership, his respect for civil liberties, and the Snowden leaks, he provided a written statement.
"The missions of NSA and USCYBERCOM are conducted in a manner that is lawful, appropriate, and effective, and under the oversight of all three branches of the U.S. government," Alexander stated. "Our mission is to protect our people and defend the nation within the authorities granted by Congress, the courts and the president. There is an ongoing investigation into the damage sustained by our nation and our allies because of the recent unauthorized disclosure of classified material. Based on what we know to date, we believe these disclosures have caused significant and irreversible harm to the security of the nation."
In lieu of an interview about his career, Alexander's spokesperson recommended a laudatory profile about him that appeared in West Point magazine. It begins: "At key moments throughout its history, the United States has been fortunate to have the right leader -- someone with an ideal combination of rare talent and strong character -- rise to a position of great responsibility in public service. With General Keith B. Alexander ... Americans are again experiencing this auspicious state of affairs."
Lawmakers and the public are increasingly taking a different view. They are skeptical about what Alexander has been doing with all the data he's collecting -- and why he's been willing to push the bounds of the law to get it. If he's going to preserve his empire, he'll have to mount the biggest charm offensive of his career. Fortunately for him, Alexander has spent as much time building a political base of power as a technological one.
* * *
Those who know Alexander say he is introspective, self-effacing, and even folksy. He's fond of corny jokes and puns and likes to play pool, golf, and Bejeweled Blitz, the addictive puzzle game, on which he says he routinely scores more than 1 million points.
Alexander is also as skilled a Washington knife fighter as they come. To get the NSA job, he allied himself with the Pentagon brass, most notably Donald Rumsfeld, who distrusted Hayden and thought he had been trying to buck the Pentagon's control of the NSA. Alexander also called on all the right committee members on Capitol Hill, the overseers and appropriators who hold the NSA's future in their hands.
When he was running the Army's Intelligence and Security Command, Alexander brought many of his future allies down to Fort Belvoir for a tour of his base of operations, a facility known as the Information Dominance Center. It had been designed by a Hollywood set designer to mimic the bridge of the starship Enterprise from Star Trek, complete with chrome panels, computer stations, a huge TV monitor on the forward wall, and doors that made a "whoosh" sound when they slid open and closed. Lawmakers and other important officials took turns sitting in a leather "captain's chair" in the center of the room and watched as Alexander, a lover of science-fiction movies, showed off his data tools on the big screen.
"Everybody wanted to sit in the chair at least once to pretend he was Jean-Luc Picard," says a retired officer in charge of VIP visits.
Alexander wowed members of Congress with his eye-popping command center. And he took time to sit with them in their offices and explain the intricacies of modern technology in simple, plain-spoken language. He demonstrated a command of the subject without intimidating those who had none.
"Alexander is 10 times the political general as David Petraeus," says the former administration official, comparing the NSA director to a man who was once considered a White House contender. "He could charm the paint off a wall."
Alexander has had to muster every ounce of that political savvy since the Snowden leaks started coming in June. In closed-door briefings, members of Congress have accused him of deceiving them about how much information he has been collecting on Americans. Even when lawmakers have screamed at him from across the table, Alexander has remained "unflappable," says a congressional staffer who has sat in on numerous private briefings since the Snowden leaks. Instead of screaming back, he reminds lawmakers about all the terrorism plots that the NSA has claimed to help foil.
"He is well aware that he will be criticized if there's another attack," the staffer says. "He has said many times, 'My job is to protect the American people. And I have to be perfect.'"
There's an implied threat in that statement. If Alexander doesn't get all the information he wants, he cannot do his job. "He never says it explicitly, but the message is, 'You don't want to be the one to make me miss,'" says the former administration official. "You don't want to be the one that denied me these capabilities before the next attack."
Alexander has a distinct advantage over most, if not all, intelligence chiefs in the government today: He actually understands the multibillion-dollar technical systems that he's running.
"When he would talk to our engineers, he would get down in the weeds as far as they were. And he'd understand what they were talking about," says a former NSA official. In that respect, he had a leg up on Hayden, who colleagues say is a good big-picture thinker but lacks the geek gene that Alexander was apparently born with.
"He looked at the technical aspects of the agency more so than any director I've known," says Richard "Dickie" George, who spent 41 years at the NSA and retired as the technical director of the Information Assurance Directorate. "I get the impression he would have been happy being one of those guys working down in the noise," George said, referring to the front-line technicians and analysts working to pluck signals out of the network.
Alexander, 61, has been a techno-spy since the beginning of his military career. After graduating from West Point in 1974, he went to West Germany, where he was initiated in the dark arts of signals intelligence. Alexander spent his time eavesdropping on military communications emanating from East Germany and Czechoslovakia. He was interested in the mechanics that supported this brand of espionage. He rose quickly through the ranks.
"It's rare to get a commander who understands technology," says a former Army officer who served with Alexander in 1995, when Alexander was in charge of the 525th Military Intelligence Brigade at Fort Bragg, North Carolina. "Even then he was into big data. You think of the wizards as the guys who are in their 20s." Alexander was 42 at the time.
At the turn of the century, Alexander took the big-data approach to counterterrorism. How well that method worked continues to be a matter of intense debate. Surely discrete interceptions of terrorists' phone calls and emails have helped disrupt plots and prevent attacks. But huge volumes of data don't always help catch potential plotters. Sometimes, the drive for more data just means capturing more ordinary people in the surveillance driftnet.
When he ran INSCOM and was horning in on the NSA's turf, Alexander was fond of building charts that showed how a suspected terrorist was connected to a much broader network of people via his communications or the contacts in his phone or email account.
"He had all these diagrams showing how this guy was connected to that guy and to that guy," says a former NSA official who heard Alexander give briefings on the floor of the Information Dominance Center. "Some of my colleagues and I were skeptical. Later, we had a chance to review the information. It turns out that all [that] those guys were connected to were pizza shops."
A retired military officer who worked with Alexander also describes a "massive network chart" that was purportedly about al Qaeda and its connections in Afghanistan. Upon closer examination, the retired officer says, "We found there was no data behind the links. No verifiable sources. We later found out that a quarter of the guys named on the chart had already been killed in Afghanistan."
Those network charts have become more massive now that Alexander is running the NSA. When analysts try to determine if a particular person is engaged in terrorist activity, they may look at the communications of people who are as many as three steps, or "hops," removed from the original target. This means that even when the NSA is focused on just one individual, the number of people who are being caught up in the agency's electronic nets could easily be in the tens of millions.
According to an internal audit, the agency's surveillance operations have been beset by human error and fooled by moving targets. After the NSA's legal authorities were expanded and the PRISM program was implemented, the agency inadvertently collected Americans' communications thousands of times each year, between 2008 and 2012, in violation of privacy rules and the law.
Yet the NSA still pursued a counterterrorism strategy that relies on ever-bigger data sets. Under Alexander's leadership, one of the agency's signature analysis tools was a digital graph that showed how hundreds, sometimes thousands, of people, places, and events were connected to each other. They were displayed as a tangle of dots and lines. Critics called it the BAG -- for "big ass graph" -- and said it produced very few useful leads. CIA officials in charge of tracking overseas terrorist cells were particularly unimpressed by it. "I don't need this," a senior CIA officer working on the agency's drone program once told an NSA analyst who showed up with a big, nebulous graph. "I just need you to tell me whose ass to put a Hellfire missile on."
Given his pedigree, it's unsurprising that Alexander is a devotee of big data. "It was taken as a given for him, as a career intelligence officer, that more information is better," says another retired military officer. "That was ingrained."
But Alexander was never alone in his obsession. An obscure civilian engineer named James Heath has been a constant companion for a significant portion of Alexander's career. More than any one person, Heath influenced how the general went about building an information empire.
Several former intelligence officials who worked with Heath described him as Alexander's "mad scientist." Another called him the NSA director's "evil genius." For years, Heath, a brilliant but abrasive technologist, has been in charge of making Alexander's most ambitious ideas a reality; many of the controversial data-mining tools that Alexander wanted to use against the NSA's raw intelligence were developed by Heath, for example. "He's smart, crazy, and dangerous. He'll push the technology to the limits to get it to do what he wants," says a former intelligence official.
Heath has followed Alexander from post to post, but he almost always stays in the shadows. Heath recently retired from government service as the senior science advisor to the NSA director -- Alexander's personal tech guru. "The general really looked to him for advice," says George, the former technical director. "Jim didn't mind breaking some eggs to make an omelet. He couldn't do that on his own, but General Alexander could. They brought a sense of needing to get things done. They were a dynamic duo."
Precisely where Alexander met Heath is unclear. They have worked together since at least 1995, when Alexander commanded the 525th Military Intelligence Brigade and Heath was his scientific sidekick. "That's where Heath took his first runs at what he called 'data visualization,' which is now called 'big data,'" says a retired military intelligence officer. Heath was building tools that helped commanders on the field integrate information from different sensors -- reconnaissance planes, satellites, signals intercepts -- and "see" it on their screens. Later, Heath would work with tools that showed how words in a document or pages on the Internet were linked together, displaying those connections in the form of three-dimensional maps and graphs.
At the Information Dominance Center, Heath built a program called the "automatic ingestion manager." It was a search engine for massive sets of data, and in 1999, he started taking it for test runs on the Internet.
In one experiment, the retired officer says, the ingestion manager searched for all web pages linked to the website of the Defense Intelligence Agency (DIA). Those included every page on the DIA's site, and the tool scoured and copied them so aggressively that it was mistaken for a hostile cyberattack. The site's automated defenses kicked in and shut it down.
On another occasion, the searching tool landed on an anti-war website while searching for information about the conflict in Kosovo. "We immediately got a letter from the owner of the site wanting to know why was the military spying on him," the retired officer says. As far as he knows, the owner took no legal action against the Army, and the test run was stopped.
Those experiments with "bleeding-edge" technology, as the denizens of the Information Dominance Center liked to call it, shaped Heath and Alexander's approach to technology in spy craft. And when they ascended to the NSA in 2005, their influence was broad and profound. "These guys have propelled the intelligence community into big data," says the retired officer.
Heath was at Alexander's side for the expansion of Internet surveillance under the PRISM program. Colleagues say it fell largely to him to design technologies that tried to make sense of all the new information the NSA was gobbling up. But Heath had developed a reputation for building expensive systems that never really work as promised and then leaving them half-baked in order to follow Alexander on to some new mission.
"He moved fairly fast and loose with money and spent a lot of it," the retired officer says. "He doubled the size of the Information Dominance Center and then built another facility right next door to it. They didn't need it. It's just what Heath and Alexander wanted to do." The Information Operations Center, as it was called, was underused and spent too much money, says the retired officer. "It's a center in search of a customer."
Heath's reputation followed him to the NSA. In early 2010, weeks after a young al Qaeda terrorist with a bomb sewn into his underwear tried to bring down a U.S. airliner over Detroit on Christmas Day, the director of national intelligence, Dennis Blair, called for a new tool that would help the disparate intelligence agencies better connect the dots about terrorism plots. The NSA, the State Department, and the CIA each had possessed fragments of information about the so-called underwear bomber's intentions, but there had been no dependable mechanism for integrating them all and providing what one former national security official described as "a quick-reaction capability" so that U.S. security agencies would be warned about the bomber before he got on the plane.
Blair put the NSA in charge of building this new capability, and the task eventually fell to Heath. "It was a complete disaster," says the former national security official, who was briefed on the project. "Heath's approach was all based on signals intelligence [the kind the NSA routinely collects] rather than taking into account all the other data coming in from the CIA and other sources. That's typical of Heath. He's got a very narrow viewpoint to solve a problem."
Like other projects of Heath's, the former official says, this one was never fully implemented. As a result, the intelligence community still didn't have a way to stitch together clues from different databases in time to stop the next would-be bomber. Heath -- and Alexander -- moved on to the next big project.
"There's two ways of looking at these guys," the retired military officer says. "Two visionaries who took risks and pushed the intelligence community forward. Or as two guys who blew a monumental amount of money."
As immense as the NSA's mission has become -- patrolling the world's data fields in search of terrorists, spies, and computer hackers -- it is merely one phase of Alexander's plan. The NSA's primary mission is to protect government systems and information. But under his leadership, the agency is also extending its reach into the private sector in unprecedented ways.
Toward the end of George W. Bush's administration, Alexander helped persuade Defense Department officials to set up a computer network defense project to prevent foreign intelligence agencies --mainly China's -- from stealing weapons plans and other national secrets from government contractors' computers.
Under the Defense Industrial Base initiative, also known as the DIB, the NSA provides the companies with intelligence about the cyberthreats it's tracking. In return, the companies report back about what they see on their networks and share intelligence with each other.
Pentagon officials say the program has helped stop some cyber-espionage. But many corporate participants say Alexander's primary motive has not been to share what the NSA knows about hackers. It's to get intelligence from the companies -- to make them the NSA's digital scouts. What is billed as an information-sharing arrangement has sometimes seemed more like a one-way street, leading straight to the NSA's headquarters at Fort Meade.
"We wanted companies to be able to share information with each other," says the former administration official, "to create a picture about the threats against them. The NSA wanted the picture."
After the DIB was up and running, Alexander proposed going further. "He wanted to create a wall around other sensitive institutions in America, to include financial institutions, and to install equipment to monitor their networks," says the former administration official. "He wanted this to be running in every Wall Street bank."
That aspect of the plan has never been fully implemented, largely due to legal concerns. If a company allowed the government to install monitoring equipment on its systems, a court could decide that the company was acting as an agent of the government. And if surveillance were conducted without a warrant or legitimate connection to an investigation, the company could be accused of violating the Fourth Amendment. Warrantless surveillance can be unconstitutional regardless of whether the NSA or Google or Goldman Sachs is doing it.
"That's a subtle point, and that subtlety was often lost on NSA," says the former administration official. "Alexander has ignored that Fourth Amendment concern."
The DIB experiment was a first step toward Alexander's taking more control over the country's cyberdefenses, and it was illustrative of his assertive approach to the problem. "He was always challenging us on the defensive side to be more aware and to try and find and counter the threat," says Tony Sager, who was the chief operating officer for the NSA's Information Assurance Directorate, which protects classified government information and computers. "He wanted to know, 'Who are the bad guys? How do we go after them?'"
While it's a given that the NSA cannot monitor the entire Internet on its own and that it needs intelligence from companies, Alexander has questioned whether companies have the capacity to protect themselves. "What we see is an increasing level of activity on the networks," he said recently at a security conference in Canada. "I am concerned that this is going to break a threshold where the private sector can no longer handle it and the government is going to have to step in."
* * *
Now, for the first time in Alexander's career, Congress and the general public are expressing deep misgivings about sharing information with the NSA or letting it install surveillance equipment. A Rasmussen poll of likely voters taken in June found that 68 percent believe it's likely the government is listening to their communications, despite repeated assurances from Alexander and President Barack Obama that the NSA is only collecting anonymous metadata about Americans' phone calls. In another Rasmussen poll, 57 percent of respondents said they think it's likely that the government will use NSA intelligence "to harass political opponents."
Some who know Alexander say he doesn't appreciate the depth of public mistrust and cynicism about the NSA's mission. "People in the intelligence community in general, and certainly Alexander, don't understand the strategic value of having a largely unified country and a long-term trust in the intelligence business," says a former intelligence official, who has worked with Alexander. Another adds, "There's a feeling within the NSA that they're all patriotic citizens interested in protecting privacy, but they lose sight of the fact that people don't trust the government."
Even Alexander's strongest critics don't doubt his good intentions. "He's not a nefarious guy," says the former administration official. "I really do feel like he believes he's doing this for the right reasons." Two of the retired military officers who have worked with him say Alexander was seared by the bombing of the USS Cole in 2000 and later the 9/11 attacks, a pair of major intelligence failures that occurred while he was serving in senior-level positions in military intelligence. They said he vowed to do all he could to prevent another attack that could take the lives of Americans and military service members.
But those who've worked closely with Alexander say he has become blinded by the power of technology. "He believes they have enough technical safeguards in place at the NSA to protect civil liberties and perform their mission," the former administration official says. "They do have a very robust capability -- probably better than any other agency. But he doesn't get that this power can still be abused. Americans want introspection. Transparency is a good thing. He doesn't understand that. In his mind it's 'You should trust me, and in exchange, I give you protection.'"
On July 30 in Las Vegas, Alexander sat down for dinner with a group of civil liberties activists and Internet security researchers. He was in town to give a keynote address the next day at the Black Hat security conference. The mood at the table was chilly, according to people who were in attendance. In 2012, Alexander had won plaudits for his speech at Black Hat's sister conference, Def Con, in which he'd implored the assembled community of experts to join him in their mutual cause: protecting the Internet as a safe space for speech, communications, and commerce. Now, however, nearly two months after the first leaks from Snowden, the people around the table wondered whether they could still trust the NSA director.
His dinner companions questioned Alexander about the NSA's legal authority to conduct massive electronic surveillance. Two guests had recently written a New York Times op-ed calling the NSA's activities "criminal." Alexander was quick to debate the finer points of the law and defend his agency's programs -- at least the ones that have been revealed -- as closely monitored and focused solely on terrorists' information.
But he also tried to convince his audience that they should help keep the NSA's surveillance system running. In so many words, Alexander told them: The terrorists only have to succeed once to kill thousands of people. And if they do, all of the rules we have in place to protect people's privacy will go out the window.
Alexander cast himself as the ultimate defender of civil liberties, as a man who needs to spy on some people in order to protect everyone. He knows that in the wake of another major terrorist attack on U.S. soil, the NSA will be unleashed to find the perpetrators and stop the next assault. Random searches of metadata, broad surveillance of purely domestic communications, warrantless seizure of stored communications -- presumably these and other extraordinary measures would be on the table. Alexander may not have spelled out just what the NSA would do after another homeland strike, but the message was clear: We don't want to find out.
Alexander was asking his dinner companions to trust him. But his credibility has been badly damaged. Alexander was heckled at his speech the next day at Black Hat. He had been slated to talk at Def Con too, but the organizers rescinded their invitation after the Snowden leaks. And even among Alexander's cohort, trust is flagging.
"You'll never find evidence that Keith sits in his office at lunch listening to tapes of U.S. conversations," says a former NSA official. "But I think he has a little bit of naiveté about this controversy. He thinks, 'What's the problem? I wouldn't abuse this power. Aren't we all honorable people?' People get into these insular worlds out there at NSA. I think Keith fits right in."
One of the retired military officers, who worked with Alexander on several big-data projects, said he was shaken by revelations that the agency is collecting all Americans' phone records and examining enormous amounts of Internet traffic. "I've not changed my opinion on the right balance between security versus privacy, but what the NSA is doing bothers me," he says. "It's the massive amount of information they're collecting. I know they're not listening to everyone's phone calls. No one has time for that. But speaking as an analyst who has used metadata, I do not sleep well at night knowing these guys can see everything. That trust has been lost."
How the NSA Accesses Smartphone Data
How the NSA Accesses Smartphone Data
The US intelligence agency NSA
has been taking advantage of the smartphone boom. It has developed the
ability to hack into iPhones, android devices and even the BlackBerry,
previously believed to be particularly secure.
Michael Hayden has an interesting story to tell about the iPhone. He
and his wife were in an Apple store in Virginia, Hayden, the former head
of the United States National Security Agency (NSA), said at a
conference in Washington recently. A salesman approached and raved about
the iPhone, saying that there were already "400,000 apps" for the
device. Hayden, amused, turned to his wife and quietly asked: "This kid
doesn't know who I am, does he? Four-hundred-thousand apps means 400,000
possibilities for attacks."
Hayden was apparently exaggerating only slightly. According to internal
NSA documents from the Edward Snowden archive that SPIEGEL has been
granted access to, the US intelligence service doesn't just bug embassies and access data from undersea cables
to gain information. The NSA is also extremely interested in that new
form of communication which has experienced such breathtaking success in
recent years: smartphones.
In Germany, more than 50 percent of all mobile phone users now
possess a smartphone; in the UK, the share is two-thirds. About 130
million people in the US have such a device. The mini-computers have
become personal communication centers, digital assistants and life
coaches, and they often know more about their users than most users
suspect.
For an agency like the NSA, the data storage units are a goldmine, combining in a single device almost all the information that would interest an intelligence agency: social contacts, details about the user's behavior and location, interests (through search terms, for example), photos and sometimes credit card numbers and passwords.
New Channels
Smartphones, in short, are a wonderful technical innovation, but also a terrific opportunity to spy on people, opening doors that even such a powerful organization as the NSA couldn't look behind until now.
From the standpoint of the computer experts at NSA headquarters in Fort Meade, Maryland, the colossal success of smartphones posed an enormous challenge at first. They opened so many new channels, that it seemed as if the NSA agents wouldn't be able to see the forest for the trees.
According to an internal NSA report from 2010 titled, "Exploring Current Trends, Targets and Techniques," the spread of smartphones was happening "extremely rapidly" -- developments that "certainly complicate traditional target analysis."
The NSA tackled the issue at the same speed with which the devices changed user behavior. According to the documents, it set up task forces for the leading smartphone manufacturers and operating systems. Specialized teams began intensively studying Apple's iPhone and its iOS operating system, as well as Google's Android mobile operating system. Another team worked on ways to attack BlackBerry, which had been seen as an impregnable fortress until then.
The material contains no indications of large-scale spying on smartphone users, and yet the documents leave no doubt that if the intelligence service defines a smartphone as a target, it will find a way to gain access to its information.
Still, it is awkward enough that the NSA is targeting devices made by US companies such as Apple and Google. The BlackBerry case is no less sensitive, since the company is based in Canada, one of the partner countries in the NSA's "Five Eyes" alliance. The members of this select group have agreed not to engage in any spying activities against one another.
Exploiting 'Nomophobia'
In this case, at any rate, the no-spy policy doesn't seem to apply. In the documents relating to smartphones that SPIEGEL was able to view, there are no indications that the companies cooperated with the NSA voluntarily.
When contacted, BlackBerry officials said that it is not the company's job to comment on alleged surveillance by governments. "Our public statements and principles have long underscored that there is no 'back door' pipeline to our platform," the company said in a statement. Google issued a statement claiming: "We have no knowledge of working groups like these and do not provide any government with access to our systems." The NSA did not respond to questions from SPIEGEL by the time the magazine went to print.
In exploiting the smartphone, the intelligence agency takes advantage of the carefree approach many users take to the device. According to one NSA presentation, smartphone users demonstrate "nomophobia," or "no mobile phobia." The only thing many users worry about is losing reception. A detailed NSA presentation titled, "Does your target have a smartphone?" shows how extensive the surveillance methods against users of Apple's popular iPhone already are.
In three consecutive transparencies, the authors of the presentation draw a comparison with "1984," George Orwell's classic novel about a surveillance state, revealing the agency's current view of smartphones and their users. "Who knew in 1984 that this would be Big Brother …" the authors ask, in reference to a photo of Apple co-founder Steve Jobs. And commenting on photos of enthusiastic Apple customers and iPhone users, the NSA writes: "… and the zombies would be paying customers?"
In fact, given the targets it defines, the NSA can select a broad spectrum of user data from Apple's most lucrative product, at least if one is to believe the agency's account.
The results the intelligence agency documents on the basis of several examples are impressive. They include an image of the son of a former defense secretary with his arm around a young woman, a photo he took with his iPhone. A series of images depicts young men and women in crisis zones, including an armed man in the mountains of Afghanistan, an Afghan with friends and a suspect in Thailand.
No Access Necessary
All the images were apparently taken with smartphones. A photo taken in January 2012 is especially risqué: It shows a former senior government official of a foreign country who, according to the NSA, is relaxing on his couch in front of a TV set and taking pictures of himself -- with his iPhone. To protect the person's privacy, SPIEGEL has chosen not to reveal his name or any other details.
The access to such material varies, but much of it passes through an NSA department responsible for customized surveillance operations against high-interest targets. One of the US agents' tools is the use of backup files established by smartphones. According to one NSA document, these files contain the kind of information that is of particular interest to analysts, such as lists of contacts, call logs and drafts of text messages. To sort out such data, the analysts don't even require access to the iPhone itself, the document indicates. The department merely needs to infiltrate the target's computer, with which the smartphone is synchronized, in advance. Under the heading "iPhone capability," the NSA specialists list the kinds of data they can analyze in these cases. The document notes that there are small NSA programs, known as "scripts," that can perform surveillance on 38 different features of the iPhone 3 and 4 operating systems. They include the mapping feature, voicemail and photos, as well as the Google Earth, Facebook and Yahoo Messenger applications.
The NSA analysts are especially enthusiastic about the geolocation data stored in smartphones and many of their apps, data that enables them to determine a user's whereabouts at a given time.
According to one presentation, it was even possible to track a person's whereabouts over extended periods of time, until Apple eliminated this "error" with version 4.3.3 of its mobile operating system and restricted the memory to seven days.
Still, the "location services" used by many iPhone apps, ranging from the camera to maps to Facebook, are useful to the NSA. In the US intelligence documents, the analysts note that the "convenience" for users ensures that most readily consent when applications ask them whether they can use their current location.
Cracking the Blackberry
The NSA and its partner agency, Britain's GCHQ, focused with similar intensity on another electronic toy: the BlackBerry.
This is particularly interesting given that the Canadian company's product is marketed to a specific target group: companies that buy the devices for their employees. In fact, the device, with its small keypad, is seen as more of a manager's tool than something suspected terrorists would use to discuss potential attacks.
The NSA also shares this assessment, noting that Nokia devices were long favored in extremist forums, with Apple following in third place and BlackBerry ranking a distant ninth.
According to several documents, the NSA spent years trying to crack BlackBerry communications, which enjoy a high degree of protection, and maintains a special "BlackBerry Working Group" specifically for this purpose. But the industry's rapid development cycles keep the specialists assigned to the group on their toes, as a GCHQ document marked "UK Secret" indicates.
According to the document, problems with the processing of BlackBerry data were suddenly encountered in May and June 2009, problems the agents attributed to a data compression method newly introduced by the manufacturer.
In July and August, the GCHQ team assigned to the case discovered that BlackBerry had previously acquired a smaller company. At the same time, the intelligence agency had begun studying the new BlackBerry code. In March 2010, the problem was finally, according to the internal account. "Champagne!" the analysts remarked, patting themselves on the back.
Security Concerns
The internal documents indicate that this was not the only success against Blackberry, a company that markets its devices as being surveillance-proof -- and one that has recently lost substantial market share due to strategic mistakes, as the NSA also notes with interest. According to one of the internal documents, in a section marked "Trends," the share of US government employees who used BlackBerry devices fell from 77 to less than 50 percent between August 2009 and May 2012.
The NSA concludes that ordinary consumer devices are increasingly replacing the only certified government smartphone, leading the analysts to voice their concerns about security. They apparently assume that they are the only agents worldwide capable of secretly tapping into BlackBerrys.
As far back as 2009, the NSA specialists noted that they could "see and read" text messages sent from BlackBerrys, and could also "collect and process BIS mails." BIS stands for BlackBerry Internet Service, which operates outside corporate networks, and which, in contrast to the data passing through internal BlackBerry services (BES), only compresses but does not encrypt data.
But even this highest level of security would seem not to be immune to NSA access, at least according to a presentation titled, "Your target is using a BlackBerry? Now what?" The presentation notes that the acquisition of encrypted BES communications requires a "sustained" operation by the NSA's Tailored Access Operation department in order to "fully prosecute your target." An email from a Mexican government agency, which appears in the presentation under the title "BES collection," reveals that this is applied successfully in practice.
Relying on BlackBerry
In June 2012, the documents show that the NSA was able to expand its arsenal against BlackBerry. Now they were also listing voice telephony among their "current capabilities," namely the two conventional mobile wireless standards in Europe and the United States, "GSM" and "CDMA."
But the internal group of experts, who had come together for a "BlackBerry round table" discussion, was still not satisfied. According to the documents, the question of which "additional enrichments would you like to see" with regards to BlackBerry was also discussed.
Even if everything in the materials viewed by SPIEGEL suggests the
targeted use of these NSA surveillance options, the companies involved
are not likely to be impressed.
BlackBerry is faltering and is currently open to takeover bids.
Security remains one of its top selling points with its most recent
models, such as the Q10. If it now becomes apparent that the NSA is
capable of spying on both Apple and BlackBerry devices in a targeted
manner, it could have far-reaching consequences.
Those consequences extend to the German government. Not long ago, the government in Berlin awarded a major contract for secure mobile communications within federal agencies. The winner was BlackBerry.
ANZEIGE
For an agency like the NSA, the data storage units are a goldmine, combining in a single device almost all the information that would interest an intelligence agency: social contacts, details about the user's behavior and location, interests (through search terms, for example), photos and sometimes credit card numbers and passwords.
New Channels
Smartphones, in short, are a wonderful technical innovation, but also a terrific opportunity to spy on people, opening doors that even such a powerful organization as the NSA couldn't look behind until now.
From the standpoint of the computer experts at NSA headquarters in Fort Meade, Maryland, the colossal success of smartphones posed an enormous challenge at first. They opened so many new channels, that it seemed as if the NSA agents wouldn't be able to see the forest for the trees.
According to an internal NSA report from 2010 titled, "Exploring Current Trends, Targets and Techniques," the spread of smartphones was happening "extremely rapidly" -- developments that "certainly complicate traditional target analysis."
The NSA tackled the issue at the same speed with which the devices changed user behavior. According to the documents, it set up task forces for the leading smartphone manufacturers and operating systems. Specialized teams began intensively studying Apple's iPhone and its iOS operating system, as well as Google's Android mobile operating system. Another team worked on ways to attack BlackBerry, which had been seen as an impregnable fortress until then.
The material contains no indications of large-scale spying on smartphone users, and yet the documents leave no doubt that if the intelligence service defines a smartphone as a target, it will find a way to gain access to its information.
Still, it is awkward enough that the NSA is targeting devices made by US companies such as Apple and Google. The BlackBerry case is no less sensitive, since the company is based in Canada, one of the partner countries in the NSA's "Five Eyes" alliance. The members of this select group have agreed not to engage in any spying activities against one another.
Exploiting 'Nomophobia'
In this case, at any rate, the no-spy policy doesn't seem to apply. In the documents relating to smartphones that SPIEGEL was able to view, there are no indications that the companies cooperated with the NSA voluntarily.
When contacted, BlackBerry officials said that it is not the company's job to comment on alleged surveillance by governments. "Our public statements and principles have long underscored that there is no 'back door' pipeline to our platform," the company said in a statement. Google issued a statement claiming: "We have no knowledge of working groups like these and do not provide any government with access to our systems." The NSA did not respond to questions from SPIEGEL by the time the magazine went to print.
In exploiting the smartphone, the intelligence agency takes advantage of the carefree approach many users take to the device. According to one NSA presentation, smartphone users demonstrate "nomophobia," or "no mobile phobia." The only thing many users worry about is losing reception. A detailed NSA presentation titled, "Does your target have a smartphone?" shows how extensive the surveillance methods against users of Apple's popular iPhone already are.
In three consecutive transparencies, the authors of the presentation draw a comparison with "1984," George Orwell's classic novel about a surveillance state, revealing the agency's current view of smartphones and their users. "Who knew in 1984 that this would be Big Brother …" the authors ask, in reference to a photo of Apple co-founder Steve Jobs. And commenting on photos of enthusiastic Apple customers and iPhone users, the NSA writes: "… and the zombies would be paying customers?"
In fact, given the targets it defines, the NSA can select a broad spectrum of user data from Apple's most lucrative product, at least if one is to believe the agency's account.
The results the intelligence agency documents on the basis of several examples are impressive. They include an image of the son of a former defense secretary with his arm around a young woman, a photo he took with his iPhone. A series of images depicts young men and women in crisis zones, including an armed man in the mountains of Afghanistan, an Afghan with friends and a suspect in Thailand.
No Access Necessary
All the images were apparently taken with smartphones. A photo taken in January 2012 is especially risqué: It shows a former senior government official of a foreign country who, according to the NSA, is relaxing on his couch in front of a TV set and taking pictures of himself -- with his iPhone. To protect the person's privacy, SPIEGEL has chosen not to reveal his name or any other details.
The access to such material varies, but much of it passes through an NSA department responsible for customized surveillance operations against high-interest targets. One of the US agents' tools is the use of backup files established by smartphones. According to one NSA document, these files contain the kind of information that is of particular interest to analysts, such as lists of contacts, call logs and drafts of text messages. To sort out such data, the analysts don't even require access to the iPhone itself, the document indicates. The department merely needs to infiltrate the target's computer, with which the smartphone is synchronized, in advance. Under the heading "iPhone capability," the NSA specialists list the kinds of data they can analyze in these cases. The document notes that there are small NSA programs, known as "scripts," that can perform surveillance on 38 different features of the iPhone 3 and 4 operating systems. They include the mapping feature, voicemail and photos, as well as the Google Earth, Facebook and Yahoo Messenger applications.
The NSA analysts are especially enthusiastic about the geolocation data stored in smartphones and many of their apps, data that enables them to determine a user's whereabouts at a given time.
According to one presentation, it was even possible to track a person's whereabouts over extended periods of time, until Apple eliminated this "error" with version 4.3.3 of its mobile operating system and restricted the memory to seven days.
Still, the "location services" used by many iPhone apps, ranging from the camera to maps to Facebook, are useful to the NSA. In the US intelligence documents, the analysts note that the "convenience" for users ensures that most readily consent when applications ask them whether they can use their current location.
Cracking the Blackberry
The NSA and its partner agency, Britain's GCHQ, focused with similar intensity on another electronic toy: the BlackBerry.
This is particularly interesting given that the Canadian company's product is marketed to a specific target group: companies that buy the devices for their employees. In fact, the device, with its small keypad, is seen as more of a manager's tool than something suspected terrorists would use to discuss potential attacks.
The NSA also shares this assessment, noting that Nokia devices were long favored in extremist forums, with Apple following in third place and BlackBerry ranking a distant ninth.
According to several documents, the NSA spent years trying to crack BlackBerry communications, which enjoy a high degree of protection, and maintains a special "BlackBerry Working Group" specifically for this purpose. But the industry's rapid development cycles keep the specialists assigned to the group on their toes, as a GCHQ document marked "UK Secret" indicates.
According to the document, problems with the processing of BlackBerry data were suddenly encountered in May and June 2009, problems the agents attributed to a data compression method newly introduced by the manufacturer.
In July and August, the GCHQ team assigned to the case discovered that BlackBerry had previously acquired a smaller company. At the same time, the intelligence agency had begun studying the new BlackBerry code. In March 2010, the problem was finally, according to the internal account. "Champagne!" the analysts remarked, patting themselves on the back.
Security Concerns
The internal documents indicate that this was not the only success against Blackberry, a company that markets its devices as being surveillance-proof -- and one that has recently lost substantial market share due to strategic mistakes, as the NSA also notes with interest. According to one of the internal documents, in a section marked "Trends," the share of US government employees who used BlackBerry devices fell from 77 to less than 50 percent between August 2009 and May 2012.
The NSA concludes that ordinary consumer devices are increasingly replacing the only certified government smartphone, leading the analysts to voice their concerns about security. They apparently assume that they are the only agents worldwide capable of secretly tapping into BlackBerrys.
As far back as 2009, the NSA specialists noted that they could "see and read" text messages sent from BlackBerrys, and could also "collect and process BIS mails." BIS stands for BlackBerry Internet Service, which operates outside corporate networks, and which, in contrast to the data passing through internal BlackBerry services (BES), only compresses but does not encrypt data.
But even this highest level of security would seem not to be immune to NSA access, at least according to a presentation titled, "Your target is using a BlackBerry? Now what?" The presentation notes that the acquisition of encrypted BES communications requires a "sustained" operation by the NSA's Tailored Access Operation department in order to "fully prosecute your target." An email from a Mexican government agency, which appears in the presentation under the title "BES collection," reveals that this is applied successfully in practice.
Relying on BlackBerry
In June 2012, the documents show that the NSA was able to expand its arsenal against BlackBerry. Now they were also listing voice telephony among their "current capabilities," namely the two conventional mobile wireless standards in Europe and the United States, "GSM" and "CDMA."
But the internal group of experts, who had come together for a "BlackBerry round table" discussion, was still not satisfied. According to the documents, the question of which "additional enrichments would you like to see" with regards to BlackBerry was also discussed.
Those consequences extend to the German government. Not long ago, the government in Berlin awarded a major contract for secure mobile communications within federal agencies. The winner was BlackBerry.
Wednesday, September 4, 2013
Screen shots of Brazilian Fanstastico TV show on NSA spying Brazil and Mexico presidents, aired 1 September 2013.
Screen shots of Brazilian Fanstastico TV show on NSA spying Brazil and Mexico
presidents, aired 1 September 2013.
http://www.youtube.com/watch?v=XlkHBB3-DhY
Shots are not in same sequence as the TV show.
http://www.youtube.com/watch?v=XlkHBB3-DhY
Shots are not in same sequence as the TV show.
| Following hands at computer are not Greenwald's. |
Monday, September 2, 2013
231 US Cyberspy Operations in 2011
September 2013
231 US Cyberspy Operations in 2011
http://www.washingtonpost.com/world/national-security/us-spy-agencies-mounted-
231-offensive-cyber-operations-in-2011-documents-show/2013/08/30/d090a6ae-
119e-11e3-b4cb-fd7ce041d814_story.html
U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show
By Barton Gellman and Ellen Nakashima, Published: August 30
U.S. intelligence services carried out 231 offensive cyber-operations in 2011, the leading edge of a clandestine campaign that embraces the Internet as a theater of spying, sabotage and war, according to top-secret documents obtained by The Washington Post.
That disclosure, in a classified intelligence budget provided by NSA leaker Edward Snowden, provides new evidence that the Obama administration’s growing ranks of cyberwarriors infiltrate and disrupt foreign computer networks.
Additionally, under an extensive effort code-named GENIE, U.S. computer specialists break into foreign networks so that they can be put under surreptitious U.S. control. Budget documents say the $652 million project has placed “covert implants,” sophisticated malware transmitted from far away, in computers, routers and firewalls on tens of thousands of machines every year, with plans to expand those numbers into the millions.
The documents provided by Snowden and interviews with former U.S. officials describe a campaign of computer intrusions that is far broader and more aggressive than previously understood. The Obama administration treats all such cyber-operations as clandestine and declines to acknowledge them.
The scope and scale of offensive operations represent an evolution in policy, which in the past sought to preserve an international norm against acts of aggression in cyberspace, in part because U.S. economic and military power depend so heavily on computers.
“The policy debate has moved so that offensive options are more prominent now,” said former deputy defense secretary William J. Lynn III, who has not seen the budget document and was speaking generally. “I think there’s more of a case made now that offensive cyberoptions can be an important element in deterring certain adversaries.”
Of the 231 offensive operations conducted in 2011, the budget said, nearly three-quarters were against top-priority targets, which former officials say includes adversaries such as Iran, Russia, China and North Korea and activities such as nuclear proliferation. The document provided few other details about the operations.
Stuxnet, a computer worm reportedly developed by the United States and Israel that destroyed Iranian nuclear centrifuges in attacks in 2009 and 2010, is often cited as the most dramatic use of a cyberweapon. Experts said no other known cyberattacks carried out by the United States match the physical damage inflicted in that case.
U.S. agencies define offensive cyber-operations as activities intended “to manipulate, disrupt, deny, degrade, or destroy information resident in computers or computer networks, or the computers and networks themselves,” according to a presidential directive issued in October 2012.
Most offensive operations have immediate effects only on data or the proper functioning of an adversary’s machine: slowing its network connection, filling its screen with static or scrambling the results of basic calculations. Any of those could have powerful effects if they caused an adversary to botch the timing of an attack, lose control of a computer or miscalculate locations.
U.S. intelligence services are making routine use around the world of government-built malware that differs little in function from the “advanced persistent threats” that U.S. officials attribute to China. The principal difference, U.S. officials told The Post, is that China steals U.S. corporate secrets for financial gain.
“The Department of Defense does engage” in computer network exploitation, according to an e-mailed statement from an NSA spokesman, whose agency is part of the Defense Department. “The department does ***not*** engage in economic espionage in any domain, including cyber.”
‘Millions of implants’
The administration’s cyber-operations sometimes involve what one budget document calls “field operations” abroad, commonly with the help of CIA operatives or clandestine military forces, “to physically place hardware implants or software modifications.”
Much more often, an implant is coded entirely in software by an NSA group called Tailored Access Operations (TAO). As its name suggests, TAO builds attack tools that are custom-fitted to their targets.
The NSA unit’s software engineers would rather tap into networks than individual computers because there are usually many devices on each network. Tailored Access Operations has software templates to break into common brands and models of “routers, switches and firewalls from multiple product vendor lines,” according to one document describing its work.
The implants that TAO creates are intended to persist through software and equipment upgrades, to copy stored data, “harvest” communications and tunnel into other connected networks. This year TAO is working on implants that “can identify select voice conversations of interest within a target network and exfiltrate select cuts,” or excerpts, according to one budget document. In some cases, a single compromised device opens the door to hundreds or thousands of others.
Sometimes an implant’s purpose is to create a back door for future access. “You pry open the window somewhere and leave it so when you come back the owner doesn’t know it’s unlocked, but you can get back in when you want to,” said one intelligence official, who was speaking generally about the topic and was not privy to the budget. The official spoke on the condition of anonymity to discuss sensitive technology.
Under U.S. cyberdoctrine, these operations are known as “exploitation,” not “attack,” but they are essential precursors both to attack and defense.
By the end of this year, GENIE is projected to control at least 85,000 implants in strategically chosen machines around the world. That is quadruple the number — 21,252 — available in 2008, according to the U.S. intelligence budget.
The NSA appears to be planning a rapid expansion of those numbers, which were limited until recently by the need for human operators to take remote control of compromised machines. Even with a staff of 1,870 people, GENIE made full use of only 8,448 of the 68,975 machines with active implants in 2011.
For GENIE’s next phase, according to an authoritative reference document, the NSA has brought online an automated system, code-named TURBINE, that is capable of managing “potentially millions of implants” for intelligence gathering “and active attack.”
‘The ROC’
When it comes time to fight the cyberwar against the best of the NSA’s global competitors, the TAO calls in its elite operators, who work at the agency’s Fort Meade headquarters and in regional operations centers in Georgia, Texas, Colorado and Hawaii[*]. The NSA’s organizational chart has the main office as S321. Nearly everyone calls it “the ROC,” pronounced “rock”: the Remote Operations Center.
“To the NSA as a whole, the ROC is where the hackers live,” said a former operator from another section who has worked closely with the exploitation teams. “It’s basically the one-stop shop for any kind of active operation that’s not defensive.”
Once the hackers find a hole in an adversary’s defense, “[t]argeted systems are compromised electronically, typically providing access to system functions as well as data. System logs and processes are modified to cloak the intrusion, facilitate future access, and accomplish other operational goals,” according to a 570-page budget blueprint for what the government calls its Consolidated Cryptologic Program, which includes the NSA.
Teams from the FBI, the CIA and U.S. Cyber Command work alongside the ROC, with overlapping missions and legal authorities. So do the operators from the NSA’s National Threat Operations Center, whose mission is focused primarily on cyberdefense. That was Snowden’s job as a Booz Allen Hamilton contractor, and it required him to learn the NSA’s best hacking techniques.
According to one key document, the ROC teams give Cyber Command “specific target related technical and operational material (identification/recognition), tools and techniques that allow the employment of U.S. national and tactical specific computer network attack mechanisms.”
The intelligence community’s cybermissions include defense of military and other classified computer networks against foreign attack, a task that absorbs roughly one-third of a total cyber operations budget of $1.02 billion in fiscal 2013, according to the Cryptologic Program budget. The ROC’s breaking-and-entering mission, supported by the GENIE infrastructure, spends nearly twice as much: $651.7 million.
Most GENIE operations aim for “exploitation” of foreign systems, a term defined in the intelligence budget summary as “surreptitious virtual or physical access to create and sustain a presence inside targeted systems or facilities.” The document adds: “System logs and processes are modified to cloak the intrusion, facilitate future access, and accomplish other operational goals.”
The NSA designs most of its own implants, but it devoted $25.1 million this year to “additional covert purchases of software vulnerabilities” from private malware vendors, a growing gray-market industry based largely in Europe.
‘Most challenging targets’
The budget documents cast U.S. attacks as integral to cyberdefense — describing them in some cases as “active defense.”
“If you’re neutralizing someone’s nuclear command and control, that’s a huge attack,” said one former defense official. The greater the physical effect, officials said, the less likely it is that an intrusion can remain hidden.
“The United States is moving toward the use of tools short of traditional weapons that are unattributable — that cannot be easily tied to the attacker — to convince an adversary to change their behavior at a strategic level,” said another former senior U.S. official, who also spoke on the condition of anonymity to discuss sensitive operations.
China and Russia are regarded as the most formidable cyberthreats, and it is not always easy to tell who works for whom. China’s offensive operations are centered in the Technical Reconnaissance Bureau of the People’s Liberation Army, but U.S. intelligence has come to believe that those state-employed hackers by day return to work at night for personal profit, stealing valuable U.S. defense industry secrets and selling them.
Iran is a distant third in capability but is thought to be more strongly motivated to retaliate for Stuxnet with an operation that would not only steal information but erase it and attempt to damage U.S. hardware.
The “most challenging targets” to penetrate are the same in cyber-operations as for all other forms of data collection described in the intelligence budget: Iran, North Korea, China and Russia. GENIE and ROC operators place special focus on locating suspected terrorists “in Afghanistan, Pakistan, Yemen, Iraq, Somalia, and other extremist safe havens,” according to one list of priorities.
The growth of Tailored Access Operations at the NSA has been accompanied by a major expansion of the CIA’s Information Operations Center, or IOC.
The CIA unit employs hundreds of people at facilities in Northern Virginia and has become one of the CIA’s largest divisions. Its primary focus has shifted in recent years from counterterrorism to cybersecurity, according to the budget document.
The military’s cyber-operations, including U.S. Cyber Command, have drawn much of the public’s attention, but the IOC undertakes some of the most notable offensive operations, including the recruitment of several new intelligence sources, the document said.
Military cyber-operations personnel grouse that the actions they can take are constrained by the legal authorities that govern them. The presidential policy directive on cyber-operations issued in October made clear that military cyber-operations that result in the disruption or destruction or even manipulation of computers must be approved by the president. But the directive, the existence of which was first reported last fall by The Post and leaked in June by Snowden, largely does not apply to the intelligence community.
Given the “vast volumes of data” pulled in by the NSA, storage has become a pressing question. The NSA is nearing completion of a massive new data center in Utah. A second one will be built at Fort Meade “to keep pace with cyber processing demands,” the budget document said.
According to the document, a high-performance computing center in Utah will manage “storage, analysis, and intelligence production.” This will allow intelligence agencies “to evaluate similarities among intrusions that could indicate the presence of a coordinated cyber attack, whether from an organized criminal enterprise or a nation-state.”
231 US Cyberspy Operations in 2011
http://www.washingtonpost.com/world/national-security/us-spy-agencies-mounted-
231-offensive-cyber-operations-in-2011-documents-show/2013/08/30/d090a6ae-
119e-11e3-b4cb-fd7ce041d814_story.html
U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show
By Barton Gellman and Ellen Nakashima, Published: August 30
U.S. intelligence services carried out 231 offensive cyber-operations in 2011, the leading edge of a clandestine campaign that embraces the Internet as a theater of spying, sabotage and war, according to top-secret documents obtained by The Washington Post.
That disclosure, in a classified intelligence budget provided by NSA leaker Edward Snowden, provides new evidence that the Obama administration’s growing ranks of cyberwarriors infiltrate and disrupt foreign computer networks.
Additionally, under an extensive effort code-named GENIE, U.S. computer specialists break into foreign networks so that they can be put under surreptitious U.S. control. Budget documents say the $652 million project has placed “covert implants,” sophisticated malware transmitted from far away, in computers, routers and firewalls on tens of thousands of machines every year, with plans to expand those numbers into the millions.
The documents provided by Snowden and interviews with former U.S. officials describe a campaign of computer intrusions that is far broader and more aggressive than previously understood. The Obama administration treats all such cyber-operations as clandestine and declines to acknowledge them.
The scope and scale of offensive operations represent an evolution in policy, which in the past sought to preserve an international norm against acts of aggression in cyberspace, in part because U.S. economic and military power depend so heavily on computers.
“The policy debate has moved so that offensive options are more prominent now,” said former deputy defense secretary William J. Lynn III, who has not seen the budget document and was speaking generally. “I think there’s more of a case made now that offensive cyberoptions can be an important element in deterring certain adversaries.”
Of the 231 offensive operations conducted in 2011, the budget said, nearly three-quarters were against top-priority targets, which former officials say includes adversaries such as Iran, Russia, China and North Korea and activities such as nuclear proliferation. The document provided few other details about the operations.
Stuxnet, a computer worm reportedly developed by the United States and Israel that destroyed Iranian nuclear centrifuges in attacks in 2009 and 2010, is often cited as the most dramatic use of a cyberweapon. Experts said no other known cyberattacks carried out by the United States match the physical damage inflicted in that case.
U.S. agencies define offensive cyber-operations as activities intended “to manipulate, disrupt, deny, degrade, or destroy information resident in computers or computer networks, or the computers and networks themselves,” according to a presidential directive issued in October 2012.
Most offensive operations have immediate effects only on data or the proper functioning of an adversary’s machine: slowing its network connection, filling its screen with static or scrambling the results of basic calculations. Any of those could have powerful effects if they caused an adversary to botch the timing of an attack, lose control of a computer or miscalculate locations.
U.S. intelligence services are making routine use around the world of government-built malware that differs little in function from the “advanced persistent threats” that U.S. officials attribute to China. The principal difference, U.S. officials told The Post, is that China steals U.S. corporate secrets for financial gain.
“The Department of Defense does engage” in computer network exploitation, according to an e-mailed statement from an NSA spokesman, whose agency is part of the Defense Department. “The department does ***not*** engage in economic espionage in any domain, including cyber.”
‘Millions of implants’
The administration’s cyber-operations sometimes involve what one budget document calls “field operations” abroad, commonly with the help of CIA operatives or clandestine military forces, “to physically place hardware implants or software modifications.”
Much more often, an implant is coded entirely in software by an NSA group called Tailored Access Operations (TAO). As its name suggests, TAO builds attack tools that are custom-fitted to their targets.
The NSA unit’s software engineers would rather tap into networks than individual computers because there are usually many devices on each network. Tailored Access Operations has software templates to break into common brands and models of “routers, switches and firewalls from multiple product vendor lines,” according to one document describing its work.
The implants that TAO creates are intended to persist through software and equipment upgrades, to copy stored data, “harvest” communications and tunnel into other connected networks. This year TAO is working on implants that “can identify select voice conversations of interest within a target network and exfiltrate select cuts,” or excerpts, according to one budget document. In some cases, a single compromised device opens the door to hundreds or thousands of others.
Sometimes an implant’s purpose is to create a back door for future access. “You pry open the window somewhere and leave it so when you come back the owner doesn’t know it’s unlocked, but you can get back in when you want to,” said one intelligence official, who was speaking generally about the topic and was not privy to the budget. The official spoke on the condition of anonymity to discuss sensitive technology.
Under U.S. cyberdoctrine, these operations are known as “exploitation,” not “attack,” but they are essential precursors both to attack and defense.
By the end of this year, GENIE is projected to control at least 85,000 implants in strategically chosen machines around the world. That is quadruple the number — 21,252 — available in 2008, according to the U.S. intelligence budget.
The NSA appears to be planning a rapid expansion of those numbers, which were limited until recently by the need for human operators to take remote control of compromised machines. Even with a staff of 1,870 people, GENIE made full use of only 8,448 of the 68,975 machines with active implants in 2011.
For GENIE’s next phase, according to an authoritative reference document, the NSA has brought online an automated system, code-named TURBINE, that is capable of managing “potentially millions of implants” for intelligence gathering “and active attack.”
‘The ROC’
When it comes time to fight the cyberwar against the best of the NSA’s global competitors, the TAO calls in its elite operators, who work at the agency’s Fort Meade headquarters and in regional operations centers in Georgia, Texas, Colorado and Hawaii[*]. The NSA’s organizational chart has the main office as S321. Nearly everyone calls it “the ROC,” pronounced “rock”: the Remote Operations Center.
“To the NSA as a whole, the ROC is where the hackers live,” said a former operator from another section who has worked closely with the exploitation teams. “It’s basically the one-stop shop for any kind of active operation that’s not defensive.”
Once the hackers find a hole in an adversary’s defense, “[t]argeted systems are compromised electronically, typically providing access to system functions as well as data. System logs and processes are modified to cloak the intrusion, facilitate future access, and accomplish other operational goals,” according to a 570-page budget blueprint for what the government calls its Consolidated Cryptologic Program, which includes the NSA.
Teams from the FBI, the CIA and U.S. Cyber Command work alongside the ROC, with overlapping missions and legal authorities. So do the operators from the NSA’s National Threat Operations Center, whose mission is focused primarily on cyberdefense. That was Snowden’s job as a Booz Allen Hamilton contractor, and it required him to learn the NSA’s best hacking techniques.
According to one key document, the ROC teams give Cyber Command “specific target related technical and operational material (identification/recognition), tools and techniques that allow the employment of U.S. national and tactical specific computer network attack mechanisms.”
The intelligence community’s cybermissions include defense of military and other classified computer networks against foreign attack, a task that absorbs roughly one-third of a total cyber operations budget of $1.02 billion in fiscal 2013, according to the Cryptologic Program budget. The ROC’s breaking-and-entering mission, supported by the GENIE infrastructure, spends nearly twice as much: $651.7 million.
Most GENIE operations aim for “exploitation” of foreign systems, a term defined in the intelligence budget summary as “surreptitious virtual or physical access to create and sustain a presence inside targeted systems or facilities.” The document adds: “System logs and processes are modified to cloak the intrusion, facilitate future access, and accomplish other operational goals.”
The NSA designs most of its own implants, but it devoted $25.1 million this year to “additional covert purchases of software vulnerabilities” from private malware vendors, a growing gray-market industry based largely in Europe.
‘Most challenging targets’
The budget documents cast U.S. attacks as integral to cyberdefense — describing them in some cases as “active defense.”
“If you’re neutralizing someone’s nuclear command and control, that’s a huge attack,” said one former defense official. The greater the physical effect, officials said, the less likely it is that an intrusion can remain hidden.
“The United States is moving toward the use of tools short of traditional weapons that are unattributable — that cannot be easily tied to the attacker — to convince an adversary to change their behavior at a strategic level,” said another former senior U.S. official, who also spoke on the condition of anonymity to discuss sensitive operations.
China and Russia are regarded as the most formidable cyberthreats, and it is not always easy to tell who works for whom. China’s offensive operations are centered in the Technical Reconnaissance Bureau of the People’s Liberation Army, but U.S. intelligence has come to believe that those state-employed hackers by day return to work at night for personal profit, stealing valuable U.S. defense industry secrets and selling them.
Iran is a distant third in capability but is thought to be more strongly motivated to retaliate for Stuxnet with an operation that would not only steal information but erase it and attempt to damage U.S. hardware.
The “most challenging targets” to penetrate are the same in cyber-operations as for all other forms of data collection described in the intelligence budget: Iran, North Korea, China and Russia. GENIE and ROC operators place special focus on locating suspected terrorists “in Afghanistan, Pakistan, Yemen, Iraq, Somalia, and other extremist safe havens,” according to one list of priorities.
The growth of Tailored Access Operations at the NSA has been accompanied by a major expansion of the CIA’s Information Operations Center, or IOC.
The CIA unit employs hundreds of people at facilities in Northern Virginia and has become one of the CIA’s largest divisions. Its primary focus has shifted in recent years from counterterrorism to cybersecurity, according to the budget document.
The military’s cyber-operations, including U.S. Cyber Command, have drawn much of the public’s attention, but the IOC undertakes some of the most notable offensive operations, including the recruitment of several new intelligence sources, the document said.
Military cyber-operations personnel grouse that the actions they can take are constrained by the legal authorities that govern them. The presidential policy directive on cyber-operations issued in October made clear that military cyber-operations that result in the disruption or destruction or even manipulation of computers must be approved by the president. But the directive, the existence of which was first reported last fall by The Post and leaked in June by Snowden, largely does not apply to the intelligence community.
Given the “vast volumes of data” pulled in by the NSA, storage has become a pressing question. The NSA is nearing completion of a massive new data center in Utah. A second one will be built at Fort Meade “to keep pace with cyber processing demands,” the budget document said.
According to the document, a high-performance computing center in Utah will manage “storage, analysis, and intelligence production.” This will allow intelligence agencies “to evaluate similarities among intrusions that could indicate the presence of a coordinated cyber attack, whether from an organized criminal enterprise or a nation-state.”
| Eyeballs of the NSA Regional Security Operations Centers (RSOCs) |
| Fort Meade
Regional SIGINT Operations Center Fort Meade, MD
|
| Georgia
Regional Security Operations Center Fort Gordon, GA
|
| Medina
Regional Security Operations Center San Antonio, TX
|
| National
Reconnaisance Office complex Aurora, CO
|
| Hawaii
Regional Security Operations Center, Kunia, HI (Undeground. Entrance lower left.) |
NSA Spying Brazil
NSA Spying Brazil
http://g1.globo.com/fantastico/noticia/2013/09/documentos-revelam-esquema-de-
agencia-dos-eua-para-espionar-dilma-rousseff.html
O Globo (Brazil)
Fantastic
Issue of the day 01/09/2013
01/09/2013 23h07 - Updated 01/09/2013 23h32
Spying documents reveal U.S. agency spied Dilma
Fantastic features an exclusive story revealing: how the greatest spy system in the world has its eye on Brazil.
We will tell you, step by step, as the National Security Agency of the United States can monitor the communications center of power in Brasilia. Including President Dilma Rousseff.
The report is by Bridi Sonia and Glenn Greenwald.
The documents classified secret, are part of a presentation to the internal personnel of the National Security Agency of the United States. A code indicates this.
They show the president of Brazil, Dilma Rousseff, and what would be his top aides, as a direct target of the NSA spying.
The journalist Glenn Greenwald, co-author of this report, was the one who received the papers from the hands of Edward Snowden, former NSA analyst who left the United States with the leading spy agency documents, with the intention to spread the American espionage system throughout the world.
Fantastic: When did you get these documents from Edward Snowden?
Glenn Greenwald: It was the first week of June, when I was with him in Hong Kong. He gave me these documents with all other documents in the original package.
The package had thousands of secret documents. Glenn reviewed these papers with Snowden during a week in Hong Kong. Shortly after Snowden fled to Russia, where he spent 38 days in the transit area of the airport in Moscow, until the country accepted his application for asylum.
During the production of this report, Fantastic spoke with Snowden through a chat program protected from eavesdropping. Hidden somewhere in the Russian territory, he said that due to a requirement of the local government he can not comment on the content of the papers, but says that the consequences and repercussions of the documents affect the world, including Brazil.
Fantastic: How can we evaluate the document and whether there have been transactions that were consummated and not just projects?
Glenn Greenwald: It was very clear from these documents that NSA had already done the spying because they are not discussing that it is only something they are planning. They are celebrating the success of the espionage.
Documents obtained exclusively by Fantastic show that espionage was done against communications with President Dilma top aides indicated by these points. It also spied communications between advisors and third parties.
The secret presentation is called: "Smart Filtering data: case study of Mexico and Brazil."
According to the presentation, the program enables finding, whenever you want, a needle in a haystack.
The haystack, in this case, is the immense volume of information that U.S. intelligence has access to every day, spying phone networks, internet servers, e-mail and social networks. The needle is who they choose.
In the document, dated June 2012, there are two targets: the president of Mexico, Enrique Peña Nieto, then candidate leading in the polls for the presidency, and the president of Brazil, Dilma Rousseff.
It works like this: the selected targets are monitored by phone numbers, emails and IP, the computer identification. The same for the interlocutors chosen in the case, advisors. What they call 'leap', is all communication between the targets and the assessors. A hop and a half, when advisors talk to them. Two jumps when they talk to other people.
To spy the then Mexican candidate Peña Nieto, the S2C, the NSA international security service for Latin America, mounted an intensive operation.
For this, it used two programs. One is called "Mainway", which collects the large volume of information passing through networks.
Text messages by telephone of the candidate were also intercepted, using the "Association", which gathers information circulating on social networks.
Then the messages go to another filter, "Dishfire" which searches for certain keywords.
Listed under the "interesting messages" is proof that the content of messages was retrieved.
Two passages are quoted. In one of them, even the presidential candidate of Mexico, Peña Nieto, in discussion with some of his ministers, who would take possession only six months after the election.
Following comes the explanation of how espionage was executed against President Dilma. "Goal" is the goal of the operation: "to improve understanding of the methods of communication and the interlocutors of the President of Brazil, Dilma Rousseff, and his top aides."
What they call "seeds" are the email addresses and phone numbers monitored. One of the programs used by the NSA is called "DNI selectors", which according to another document leaked by Snowden, capture everything the user does on the internet, including the content of e-mails and websites visited.
A following graph [not published] shows the entire communications network of the president with his aides. Each dot represents a person. But the enlarged image shows that captions or names of those who had intercepted communications were deleted for presentation.
In the document there are no examples of calls or messages between the president and his ministers, as happened when the now president of Mexico was mentioned.
But on the last page the document says that the espionge method used is a "simple and effective filter that allows for data that are not available otherwise. And that can be repeated." Can be repeated, seems to mean that it was carried out.
And more. It concludes by saying that the union of two NSA sectors had success against top targets: Brazil and Mexico. Top targets, they know the danger of espionage and to protect your communication. Again, if it was successful because they were real examples.
In July, a report in the O Globo newspaper, also shown in Fantastic, as revealed by leaked documents from Snowden, the United States intercepted communications of millions of Brazilians.
At the time, the U.S. Ambassador to Brazil Thomas Shannon, denied that the contents of the calls and emails from Brazilian citizens were being spied on. He admitted only that the NSA accesses called metadata, which is the total technical connections, passing through Brazil.
It is unclear whether the interception of calls President Dilma was made only by access to communication networks, or whether there was involvement of spies in Brazilian territory.
James Bramford, expert who wrote three books on the NSA, spoke with the Fantastic in Washington.
He says that the NSA has spies in U.S. embassies and consulates around the world.
"We have a large embassy in Brasilia and a consulate in Rio de Janeiro. The NSA operates in these buildings. Antennas in the embassies can intercept microwave signals and cell phones," James Bramford says.
Also in Hong Kong, when he met Glenn Greenwald, Edward Snowden spoke of documents involving espionage against President Dilma.
He said: "the tactics of the U.S. government since September 11 is to say that everything is justified by terrorism. Scaring people to accept these measures as necessary. But most of the spying they do does not have anything to do with national security, it is to obtain an unfair advantage over other nations in their industrial and commerce economic agreements. "
Last month the magazine published exclusively a document proving that American intelligence is also commercial.
This is a letter written by the current U.S. Ambassador to Brazil, Thomas Shannon, in 2009, when he was with the secretary of state.
He thanks the NSA for the information passed to American diplomacy before the Fifth Summit of the Americas, a meeting between the heads of state of the continent to discuss the region's commercial and diplomatic affairs.
In the letter, Thomas Shannon wrote: "more than 100 reports we received from the agency gave us a deep understanding of the plans and intentions of other summit participants and allowed our diplomats to be well prepared to advise President Obama on how to deal with controversial issues."
"On trade issues, we know what others are thinking before the multilateral meetings, how to play poker by knowing which cards everyone has at the table," James Bramford says.
Another document obtained exclusively by Fantastic says that an entire division of the NSA is dedicated to international policy and commercial activities, with a sector in charge of Western Europe, Japan, Mexico and Brazil.
A third-secret document lists the geopolitical challenges of the United States for the years 2014-2019.
The emergence of Brazil and Turkey on the global stage is classified as a risk to regional stability. And Brazil appears again, along with other countries, as a question in the American diplomatic scene: would our country be friend, enemy or problem? Also mentioned are Egypt, India, Iran, Turkey, Mexico, and other countries.
"When the country is more independent, stronger, like Brazil. Competing with the United States, with American companies. And because of that, the U.S. government is thinking differently about Brazil," Glenn says.
Why did Edward Snowden makes public those documents?
"He told me, 'Look, I think the American's privacy is very important, but I also think the privacy of foreign people in Latin America, the Brazilians are also very important. Of equal importance. And I do not want to protect the privacy of U.S. only. I want to protect the privacy of all people '," Glenn says.
This week the newspaper "Washington Post" published the secret budget of U.S. intelligence services, equivalent to U.S. $126 billion.
http://g1.globo.com/fantastico/noticia/2013/09/documentos-revelam-esquema-de-
agencia-dos-eua-para-espionar-dilma-rousseff.html
O Globo (Brazil)
Fantastic
Issue of the day 01/09/2013
01/09/2013 23h07 - Updated 01/09/2013 23h32
Spying documents reveal U.S. agency spied Dilma
Fantastic features an exclusive story revealing: how the greatest spy system in the world has its eye on Brazil.
We will tell you, step by step, as the National Security Agency of the United States can monitor the communications center of power in Brasilia. Including President Dilma Rousseff.
The report is by Bridi Sonia and Glenn Greenwald.
The documents classified secret, are part of a presentation to the internal personnel of the National Security Agency of the United States. A code indicates this.
They show the president of Brazil, Dilma Rousseff, and what would be his top aides, as a direct target of the NSA spying.
The journalist Glenn Greenwald, co-author of this report, was the one who received the papers from the hands of Edward Snowden, former NSA analyst who left the United States with the leading spy agency documents, with the intention to spread the American espionage system throughout the world.
Fantastic: When did you get these documents from Edward Snowden?
Glenn Greenwald: It was the first week of June, when I was with him in Hong Kong. He gave me these documents with all other documents in the original package.
The package had thousands of secret documents. Glenn reviewed these papers with Snowden during a week in Hong Kong. Shortly after Snowden fled to Russia, where he spent 38 days in the transit area of the airport in Moscow, until the country accepted his application for asylum.
During the production of this report, Fantastic spoke with Snowden through a chat program protected from eavesdropping. Hidden somewhere in the Russian territory, he said that due to a requirement of the local government he can not comment on the content of the papers, but says that the consequences and repercussions of the documents affect the world, including Brazil.
Fantastic: How can we evaluate the document and whether there have been transactions that were consummated and not just projects?
Glenn Greenwald: It was very clear from these documents that NSA had already done the spying because they are not discussing that it is only something they are planning. They are celebrating the success of the espionage.
Documents obtained exclusively by Fantastic show that espionage was done against communications with President Dilma top aides indicated by these points. It also spied communications between advisors and third parties.
The secret presentation is called: "Smart Filtering data: case study of Mexico and Brazil."
According to the presentation, the program enables finding, whenever you want, a needle in a haystack.
The haystack, in this case, is the immense volume of information that U.S. intelligence has access to every day, spying phone networks, internet servers, e-mail and social networks. The needle is who they choose.
In the document, dated June 2012, there are two targets: the president of Mexico, Enrique Peña Nieto, then candidate leading in the polls for the presidency, and the president of Brazil, Dilma Rousseff.
It works like this: the selected targets are monitored by phone numbers, emails and IP, the computer identification. The same for the interlocutors chosen in the case, advisors. What they call 'leap', is all communication between the targets and the assessors. A hop and a half, when advisors talk to them. Two jumps when they talk to other people.
To spy the then Mexican candidate Peña Nieto, the S2C, the NSA international security service for Latin America, mounted an intensive operation.
For this, it used two programs. One is called "Mainway", which collects the large volume of information passing through networks.
Text messages by telephone of the candidate were also intercepted, using the "Association", which gathers information circulating on social networks.
Then the messages go to another filter, "Dishfire" which searches for certain keywords.
Listed under the "interesting messages" is proof that the content of messages was retrieved.
Two passages are quoted. In one of them, even the presidential candidate of Mexico, Peña Nieto, in discussion with some of his ministers, who would take possession only six months after the election.
Following comes the explanation of how espionage was executed against President Dilma. "Goal" is the goal of the operation: "to improve understanding of the methods of communication and the interlocutors of the President of Brazil, Dilma Rousseff, and his top aides."
What they call "seeds" are the email addresses and phone numbers monitored. One of the programs used by the NSA is called "DNI selectors", which according to another document leaked by Snowden, capture everything the user does on the internet, including the content of e-mails and websites visited.
A following graph [not published] shows the entire communications network of the president with his aides. Each dot represents a person. But the enlarged image shows that captions or names of those who had intercepted communications were deleted for presentation.
In the document there are no examples of calls or messages between the president and his ministers, as happened when the now president of Mexico was mentioned.
But on the last page the document says that the espionge method used is a "simple and effective filter that allows for data that are not available otherwise. And that can be repeated." Can be repeated, seems to mean that it was carried out.
And more. It concludes by saying that the union of two NSA sectors had success against top targets: Brazil and Mexico. Top targets, they know the danger of espionage and to protect your communication. Again, if it was successful because they were real examples.
In July, a report in the O Globo newspaper, also shown in Fantastic, as revealed by leaked documents from Snowden, the United States intercepted communications of millions of Brazilians.
At the time, the U.S. Ambassador to Brazil Thomas Shannon, denied that the contents of the calls and emails from Brazilian citizens were being spied on. He admitted only that the NSA accesses called metadata, which is the total technical connections, passing through Brazil.
It is unclear whether the interception of calls President Dilma was made only by access to communication networks, or whether there was involvement of spies in Brazilian territory.
James Bramford, expert who wrote three books on the NSA, spoke with the Fantastic in Washington.
He says that the NSA has spies in U.S. embassies and consulates around the world.
"We have a large embassy in Brasilia and a consulate in Rio de Janeiro. The NSA operates in these buildings. Antennas in the embassies can intercept microwave signals and cell phones," James Bramford says.
Also in Hong Kong, when he met Glenn Greenwald, Edward Snowden spoke of documents involving espionage against President Dilma.
He said: "the tactics of the U.S. government since September 11 is to say that everything is justified by terrorism. Scaring people to accept these measures as necessary. But most of the spying they do does not have anything to do with national security, it is to obtain an unfair advantage over other nations in their industrial and commerce economic agreements. "
Last month the magazine published exclusively a document proving that American intelligence is also commercial.
This is a letter written by the current U.S. Ambassador to Brazil, Thomas Shannon, in 2009, when he was with the secretary of state.
He thanks the NSA for the information passed to American diplomacy before the Fifth Summit of the Americas, a meeting between the heads of state of the continent to discuss the region's commercial and diplomatic affairs.
In the letter, Thomas Shannon wrote: "more than 100 reports we received from the agency gave us a deep understanding of the plans and intentions of other summit participants and allowed our diplomats to be well prepared to advise President Obama on how to deal with controversial issues."
"On trade issues, we know what others are thinking before the multilateral meetings, how to play poker by knowing which cards everyone has at the table," James Bramford says.
Another document obtained exclusively by Fantastic says that an entire division of the NSA is dedicated to international policy and commercial activities, with a sector in charge of Western Europe, Japan, Mexico and Brazil.
A third-secret document lists the geopolitical challenges of the United States for the years 2014-2019.
The emergence of Brazil and Turkey on the global stage is classified as a risk to regional stability. And Brazil appears again, along with other countries, as a question in the American diplomatic scene: would our country be friend, enemy or problem? Also mentioned are Egypt, India, Iran, Turkey, Mexico, and other countries.
"When the country is more independent, stronger, like Brazil. Competing with the United States, with American companies. And because of that, the U.S. government is thinking differently about Brazil," Glenn says.
Why did Edward Snowden makes public those documents?
"He told me, 'Look, I think the American's privacy is very important, but I also think the privacy of foreign people in Latin America, the Brazilians are also very important. Of equal importance. And I do not want to protect the privacy of U.S. only. I want to protect the privacy of all people '," Glenn says.
This week the newspaper "Washington Post" published the secret budget of U.S. intelligence services, equivalent to U.S. $126 billion.
Tuesday, August 20, 2013
How DID Peter Maas Got Laura Poitras to Open Up
How Peter Maas Got Laura Poitras to Open Up
August 19, 2013, 6:07
Peter Maass on How DID He Got the Very Secret Laura Poitras to Open Up
Peter Maass, a contributor to the magazine, wrote this week’s cover story on Laura Poitras and Glenn Greenwald, the two journalists to whom Edward Snowden leaked material concerning N.S.A. surveillance programs. Maass is the author of several books, most recently “Crude World: The Violent Twilight of Oil,’’ and is working on a new book about surveillance and privacy.
Everyone wants to talk to Snowden, and, failing that, everyone wants to talk to the two people talking to Snowden. How did you get Greenwald and Poitras to agree to the story?
It goes back a number of years. Laura’s second film in a trilogy about American power, “The Oath,” had just come out. A friend of mine who is a documentary maker recommended it to me and my wife. I was familiar with Laura’s work but was amazed by the documentary. It was visually beautiful and imaginative while at the same time being information-dense and telling a good story. I knew that she was still being stopped at airports while working on a project about surveillance, so I got in touch. A year and a half ago we met several times for coffee or lunch, and I said, “You know, I’d like to do a story about you.” This was long before Snowden entered her life. She was a little bit reluctant, because any spotlight on her makes it more difficult for her to do her work. But she agreed. I got into another couple of stories first. Then the Snowden thing happened, and I sent her another e-mail asking if she’d be amenable to doing the profile now. Since she already knew me and my work, and probably also because I’d been interested in her before, she agreed to let me do the story.
She and Greenwald weren’t worried about disclosing their location in Rio to you, or having you watch them work with secret files?
It was understood that I wouldn’t write anything that would jeopardize their security. I also knew they wouldn’t show me their documents or tell me every detail about how they got them from Snowden or what they planned to do with them. Snowden has been charged with espionage. They could be still be charged with something. They don’t want to make public the types of information, beyond the documents themselves, that could be used to build a case against him or them. Basic things like where Glenn’s house is in Rio I don’t mention in the story, just in case. I think it’s safe to assume the U.S. government knows where Glenn lives, but other governments and private individuals probably don’t. And we did have some explicit conversations about what they preferred I not include.
Did their need for secrecy hinder your reporting?
When I first arrived on a Saturday morning, Laura had sent me an e-mail with the name of the hotel where she was meeting with Glenn and the other two Guardian reporters who were visiting to help with stories. I went straight there from the airport and watched the four of them working on stories and on computer-security issues. It was like an embed. I’ve done military embeds in Iraq. It was either explicitly stated in Iraq, or just really clear, that you didn’t write about operational matters — tactics, perimeter security, patrol plans — that could jeopardize the present or future security of the troops you were with. The military doesn’t show you everything, but it is there in the room, and they are not necessarily able or trying to hide everything. They depend somewhat on your discretion. Both were classified environments.
Did you use encrypted messages in reporting this story?
I exchanged both encrypted and nonencrypted messages with Poitras. If something was not supersensitive, we used normal e-mail. I thought about not bringing my smartphone to Rio, but then I ended up bringing it. When I was with Laura and Glenn, I for the most part left my smartphone in a secure place that was not on my person. If it was on me, it was usually off. I didn’t bring my own laptop to Rio. I brought a clean computer. I thought that maybe as I came back, someone might want to take a look at what was on my computer. Then when I returned to New York and Laura returned to Berlin, I had more questions for her. So there were two levels of security: We used an encrypted chat program and anonymizing software.
Through an encrypted chat via Laura, you got a chance to ask Snowden some questions. What sense did you get of him?
I didn’t know whether he would answer any of my questions, and neither did Laura. So I thought the best thing would be to keep them focused on the topic of my story. I didn’t learn more about him personally, but what was most interesting and what has gotten a lot of reaction was his surprise about the lack of encryption that journalists use and journalists’ lack of awareness of how their communications are so easy for organizations, including the N.S.A., to capture. He expressed his disappointment that in the beginning Glenn was not only not encryption savvy but wouldn’t take the steps to become encryption savvy until Laura went to him and said, “Hey, this is for real.” Snowden knew very well what the N.S.A. was capturing, so it was useful to hear directly from him that encryption is a crucial step.
August 19, 2013, 6:07
Peter Maass on How DID He Got the Very Secret Laura Poitras to Open Up
Peter Maass, a contributor to the magazine, wrote this week’s cover story on Laura Poitras and Glenn Greenwald, the two journalists to whom Edward Snowden leaked material concerning N.S.A. surveillance programs. Maass is the author of several books, most recently “Crude World: The Violent Twilight of Oil,’’ and is working on a new book about surveillance and privacy.
Everyone wants to talk to Snowden, and, failing that, everyone wants to talk to the two people talking to Snowden. How did you get Greenwald and Poitras to agree to the story?
It goes back a number of years. Laura’s second film in a trilogy about American power, “The Oath,” had just come out. A friend of mine who is a documentary maker recommended it to me and my wife. I was familiar with Laura’s work but was amazed by the documentary. It was visually beautiful and imaginative while at the same time being information-dense and telling a good story. I knew that she was still being stopped at airports while working on a project about surveillance, so I got in touch. A year and a half ago we met several times for coffee or lunch, and I said, “You know, I’d like to do a story about you.” This was long before Snowden entered her life. She was a little bit reluctant, because any spotlight on her makes it more difficult for her to do her work. But she agreed. I got into another couple of stories first. Then the Snowden thing happened, and I sent her another e-mail asking if she’d be amenable to doing the profile now. Since she already knew me and my work, and probably also because I’d been interested in her before, she agreed to let me do the story.
She and Greenwald weren’t worried about disclosing their location in Rio to you, or having you watch them work with secret files?
It was understood that I wouldn’t write anything that would jeopardize their security. I also knew they wouldn’t show me their documents or tell me every detail about how they got them from Snowden or what they planned to do with them. Snowden has been charged with espionage. They could be still be charged with something. They don’t want to make public the types of information, beyond the documents themselves, that could be used to build a case against him or them. Basic things like where Glenn’s house is in Rio I don’t mention in the story, just in case. I think it’s safe to assume the U.S. government knows where Glenn lives, but other governments and private individuals probably don’t. And we did have some explicit conversations about what they preferred I not include.
Did their need for secrecy hinder your reporting?
When I first arrived on a Saturday morning, Laura had sent me an e-mail with the name of the hotel where she was meeting with Glenn and the other two Guardian reporters who were visiting to help with stories. I went straight there from the airport and watched the four of them working on stories and on computer-security issues. It was like an embed. I’ve done military embeds in Iraq. It was either explicitly stated in Iraq, or just really clear, that you didn’t write about operational matters — tactics, perimeter security, patrol plans — that could jeopardize the present or future security of the troops you were with. The military doesn’t show you everything, but it is there in the room, and they are not necessarily able or trying to hide everything. They depend somewhat on your discretion. Both were classified environments.
Did you use encrypted messages in reporting this story?
I exchanged both encrypted and nonencrypted messages with Poitras. If something was not supersensitive, we used normal e-mail. I thought about not bringing my smartphone to Rio, but then I ended up bringing it. When I was with Laura and Glenn, I for the most part left my smartphone in a secure place that was not on my person. If it was on me, it was usually off. I didn’t bring my own laptop to Rio. I brought a clean computer. I thought that maybe as I came back, someone might want to take a look at what was on my computer. Then when I returned to New York and Laura returned to Berlin, I had more questions for her. So there were two levels of security: We used an encrypted chat program and anonymizing software.
Through an encrypted chat via Laura, you got a chance to ask Snowden some questions. What sense did you get of him?
I didn’t know whether he would answer any of my questions, and neither did Laura. So I thought the best thing would be to keep them focused on the topic of my story. I didn’t learn more about him personally, but what was most interesting and what has gotten a lot of reaction was his surprise about the lack of encryption that journalists use and journalists’ lack of awareness of how their communications are so easy for organizations, including the N.S.A., to capture. He expressed his disappointment that in the beginning Glenn was not only not encryption savvy but wouldn’t take the steps to become encryption savvy until Laura went to him and said, “Hey, this is for real.” Snowden knew very well what the N.S.A. was capturing, so it was useful to hear directly from him that encryption is a crucial step.
Subscribe to:
Posts (Atom)