Showing posts with label US Cyber Command. Show all posts
Showing posts with label US Cyber Command. Show all posts

Friday, March 22, 2013

The Ugly Truth Behind Obama’s Cyber-War

Net Intrusion
by ALFREDO LOPEZ


Last week, a top U.S. government intelligence official named James Clapper warned Congress that the threat of somebody using the Internet to attack the United States is “even more pressing than an attack by global terrorist networks”. At about the same time, Keith Alexander, the head of the National Security Agency, announced that the government is forming 13 teams to conduct an international “cyber offensive” to pre-empt or answer “Internet attacks” on this country.

This, as they say, means war.

Clapper issued his melodramatic assessment during an appearance before the Senate Intelligence Committee. As Director of National Intelligence, he testified jointly with the heads of the CIA and FBI as part of their annual “Threat To the Nation” assessment report.

While undoubtedly important, these “threat assessment” appearances are usually a substitute for sleeping pills. The panel of Intelligence honchos parades out a list of “threats” ranked by a combination of potential harm and probability of attack. Since they began giving this report (shortly after 9/11), “Islamic fundamentalist terrorist networks” have consistently ranked number one. Hence the sleep-provoking predictability of it all.

But Clapper’s ranking of “cyber terrorism” as the number one threat would wake up Rip Van Winkle.

“Attacks, which might involve cyber and financial weapons, can be deniable and unattributable,” he intoned. “Destruction can be invisible, latent and progressive.” After probably provoking a skipped heartbeat in a Senator or two, he added that he didn’t think any major attack of this type was imminent or even feasible at this point.

So why use such “end of the world” rhetoric to make a unfeasible threat number one?

The answer perhaps was to be found in the House of Representatives where, on that same day, Gen. Alexander was testifying before the Armed Services Committee about, you got it, “cyber-war”.

Besides being head of the NSA, Alexander directs the United States Cyber Command. I’m not joking. Since 2010, the United States military has had a “Cyber Command”, comprised of a large network of “teams” some of whose purpose is to plan and implement what he called “an offensive strategy”.

Up to now, the Obama Adminstration’s stated policy has been to prioritize protection and defense of its own Internet and data systems and, unsurprisingly, those of U.S. corporations. Now we realize that the President has been cooking another dish on the back burner. When these military leaders talk about “offensive strategy”, they mean war and in warfare, the rules change and warriors see democracy as a stumbling block at least and a potential threat at worst.
Is there a “cyber threat”? Sure, just like there’s a “personal security threat” at your front door. You live among other humans and a few of them sometimes rob people. The Internet is a neighborhood of two billion people in constant communication. To do what it was developed to do, it has to be an open, world-wide communications system and so people can exploit that by harming your website or stealing your data if you don’t protect these things adequately. Developing protections is part of what technologists in every setting, including government services, do every day and they do it well, minimizing the incidence of an on-line hack.

That’s contemporary society. You lock the door to your house, turn on your car alarm on and protect your computer’s data. Most of the time it’s unnecessary but you do it for those rare occasions that it might be called for.

You do not, however, break into a thief’s home, kill him or her and wipe out everyone in the house. That’s what President Obama is proposing. No longer is this Administration interested in just “protection of data”; it now plans to pre-emptively attack data operations and Internet systems in other countries. The non-euphemistic term for this kind of “offensive strategy” is hacking and hacking takes two forms: data theft and disruption of service. In other words, the government plans to do what it throws people in jail for doing.

Clearly, this isn’t only about data theft or service disruption. It’s entwined with the political conflicts Washington has with other countries like China and Iran. The Internet is now another battlefield and this offensive strategy gives our government another weapon in its ceaseless war on the world.

While this weapon might sound benign, almost game-like, compared to other military adventures, it is actually a vicious and punishing strategy promising a festival of unavoidable collateral damage.

A “cyber offensive” can target just about anything in a country (like the computers running an Iranian power plant) and, depending on how the Internet systems are inter-connected, almost automatically cut service to people, schools, hospitals, security services and governments themselves. This is the digital version of nuclear warfare, horrific for its impact and its fundamental immorality.

When the announcements were made, the mainstream media flew into a frenzy of evaluation and analysis. Is this cyber threat real, commentators asked? Most of them found that, at this point, it isn’t. But that’s not the point and it isn’t the real threat.

The carefully planned and coordinated Clapper/Alexander testimony provides a pretext for the array of repressive Internet-governing laws, strategies and programs the Administration already has in place. Their purpose is a ratcheting control of the Internet by the government, a redefinition of our constitutional rights and the eviscerating of our, and the world’s, freedoms. Now, with this “cyber war” scenario, these measures can be more easily defended and made permanent.

We can group those laws and programs into three categories.

1 - ”Extreme Data Collection”

The Obama Administration is building a huge data center in Bluffdale, Utah whose role is to capture and store all data everyone in this country (and most of the world) transmits. You read that right.

“Flowing through its servers and routers and stored in near-bottomless databases will be all forms of communication,” wrote James Bamford in Wired Magazine, “including the complete contents of private emails, cell phone calls, and Google searches, as well as all sorts of personal data trails — parking receipts, travel itineraries, bookstore purchases, and other digital ‘pocket litter.’”

While having your entire on-line life tracked and stored in Utah is pretty creepy, the more pressing issue is how government officials plan to use this data and how they are collecting it. To mine its value, they need to order it to make searches, filtering and lists possible. You need a strategy and while Obama officials have been pretty open about what they’re building, they are closed-mouth about what they intend to do with it.

We know they are working hard on developing code-breaking technology which would allow them to read data which is super-encrypted, the last wall of privacy and protection we have. We also know that, to get this data, they have a remarkable system of surveillance that includes direct capture (capturing data from your on-line sessions), satellite surveillance and the tapping (through easily available data captures) of major information gatherers like Google and Yahoo. The fact that they plan to open this center in September, 2013 means that the intense surveillance and data gathering is in place. You are now never alone.

This is the kind of information on “the enemy” they need in a cyber-war but this information is about us and so the question pertains: who is the enemy here?

2 - “Internet Usage Restriction”

If you’re conducting a war, you can’t have people running around the battlefield trading information and distributing it because, after all, you need secrecy. But collecting and distributing information is entirely what the Internet is about.

No reasonable person expects the entire shut-down of the Internet but the curtailment of on-line expression is now happening and getting worse, re-defining the meaning of free speech and making it an embattled concept.

Under the law, for instance, any corporation or individual can claim you are violating their copyright and demand you remove offending material from a website. You can challenge and litigate that but it doesn’t really matter because, under the Digital Millenium Copyright Act your web hosting service faces huge penalties if they keep the site on-line and the copyright violation is proven. So, to avoid the legal fees and the risk, they’ll just wipe your website. This happens all the time.

If the hosting service stands strong — as some progressive providers do — the people claiming the violation will just go “upstream” to the company that provides your web hosting service’s connection to the Internet and, to avoid legal problems, that “upstream provider” will just unplug the server. Servers host many websites, sometimes in the hundreds, and other services and so not only do you lose your site but everyone else on the server has theirs taken off-line. And this happens without even going in front of a judge.

Sure, there is still robustly exercised “freedom of speech” on the Internet. But the laws are in place to curtail it and, if the government wants, it can (and will) curtail. It’s a modern-day version of benevolent dictatorship which can, as history demonstrates, become pretty darn malevolent pretty fast.

3 — “Selective Repression”

There are hundreds of criminal cases against Internet activists world-wide right now and scores in the United States. The ones most of us are most familiar with, those involving Aaron Swartz and Bradley Manning, are only the tip of the frightening iceberg.

A day after the testimony before Congress, for example, federal authorities announced the case of a techie named Matthew Keys . Keys, who worked for a tv station in Los Angeles owned by the Tribune Company, is accused of leaking a username and password to an activist from the well-known hacker organization Anonymous. Authorities say the Anonymous activist used that user/password combo to satirically alter a headline on the website of the Tribune-owned Los Angeles Times.

Keys is now charged with conspiracy to transmit information to damage a protected computer; transmitting information to damage a protected computer and attempted transmission of information to damage a protected computer. Each count carries a 10 year jail sentence, three years of supervised release and a fine of $250,000. For giving someone who changed a headline a username and password!

Last year, we at May First/People Link were raided by the FBI which literally stole a server from one of our server installations in New York City. They were investigating terroristic emails from some lunatic to people at the University of Pittsburgh and the dozens of servers this bozo used included one of ours. We have some anonymous servers which means there are no records of who used them, no traces…no information about the person sending the email; it’s to protect whistle-blowers and others needing total anonymity.

The FBI knew this but they stole the server anyway and then, about a week later, put it back. They never informed us of any of this. We found out because one of our techies went into the server installation and found one of the servers gone and installed a hidden camera which caught the agents when they returned the machine.

If all these developments seem disturbing to you, that’s justified. These repressive and intrustive measures target the very essence and purpose of the Internet. Created as a way for people to communicate with each other world-wide, this marvel of human interaction is now being turned into a field across which countries shoot programming bombs at each other while repressing and even punishing ordinary people’s communication: dividing us, perpetuating the feeling of loneliness that’s a constant in today’s societies and crippling the struggles for change that combat the division and loneliness and depend on the Internet to do it.

The Internet’s true purpose is to bring the world’s people closer to each other. The Obama Administration is doing just the opposite. It would advisable for those of us who have consistently opposed and fought against wars of all kinds to view this “cyber war” as an equally dangerous and destructive threat.

Wednesday, April 4, 2012

Even worse than SOPA: New CISPA cybersecurity bill will censor the Web

Published: 04 April, 2012 - RT
An onrush of condemnation and criticism kept the SOPA and PIPA acts from passing earlier this year, but US lawmakers have already authored another authoritarian bill that could give them free reign to creep the Web in the name of cybersecurity.

As congressmen in Washington consider how to handle the ongoing issue of cyberattacks, some legislators have lent their support to a new act that, if passed, would let the government pry into the personal correspondence of anyone of their choosing.

H.R. 3523, a piece of legislation dubbed the Cyber Intelligence Sharing and Protection Act (or CISPA for short), has been created under the guise of being a necessary implement in America’s war against cyberattacks. But the vague verbiage contained within the pages of the paper could allow Congress to circumvent existing exemptions to online privacy laws and essentially monitor, censor and stop any online communication that it considers disruptive to the government or private parties. Critics have already come after CISPA for the capabilities that it will give to seemingly any federal entity that claims it is threatened by online interactions, but unlike the Stop Online Privacy Act and the Protect IP Acts that were discarded on the Capitol Building floor after incredibly successful online campaigns to crush them, widespread recognition of what the latest would-be law will do has yet to surface to the same degree.

Kendall Burman of the Center for Democracy and Technology tells RT that Congress is currently considering a number of cybersecurity bills that could eventually be voted into law, but for the group that largely advocates an open Internet, she warns that provisions within CISPA are reason to worry over what the realities could be if it ends up on the desk of President Barack Obama. So far CISPA has been introduced, referred and reported by the House Permanent Select Committee on Intelligence and expects to go before a vote in the first half of Congress within the coming weeks.

“We have a number of concerns with something like this bill that creates sort of a vast hole in the privacy law to allow government to receive these kinds of information,” explains Burman, who acknowledges that the bill, as written, allows the US government to involve itself into any online correspondence, current exemptions notwithstanding, if it believes there is reason to suspect cyber crime. As with other authoritarian attempts at censorship that have come through Congress in recent times, of course, the wording within the CISPA allows for the government to interpret the law in such a number of degrees that any online communication or interaction could be suspect and thus unknowingly monitored.

In a press release penned last month by the CDT, the group warned then that CISPA allows Internet Service Providers to “funnel private communications and related information back to the government without adequate privacy protections and controls.

The bill does not specify which agencies ISPs could disclose customer data to, but the structure and incentives in the bill raise a very real possibility that the National Security Agency or the DOD’s Cybercommand would be the primary recipient,” reads the warning.

The Electronic Frontier Foundation, another online advocacy group, has also sharply condemned CISPA for what it means for the future of the Internet. “It effectively creates a ‘cybersecurity'’ exemption to all existing laws,” explains the EFF, who add in a statement of their own that “There are almost no restrictions on what can be collected and how it can be used, provided a company can claim it was motivated by ‘cybersecurity purposes.’”

What does that mean? Both the EFF and CDT say an awfully lot. Some of the biggest corporations in the country, including service providers such as Google, Facebook, Twitter or AT&T, could copy confidential information and send them off to the Pentagon if pressured, as long as the government believes they have reason to suspect wrongdoing. In a summation of their own, the Congressional Research Service, a nonpartisan arm of the Library of Congress, explains that “efforts to degrade, disrupt or destroy” either “a system or network of a government or private entity” is reason enough for Washington to reach in and read any online communiqué of their choice.

The authors of CISPA say the bill has been made “To provide for the sharing of certain cyber threat intelligence and cyber threat information between the intelligence community and cybersecurity entities,” but not before noting that the legislation could be used “and for other purposes,” as well — which, of course, are not defined.

“Cyber security, when done right and done narrowly, could benefit everyone,” Burman tells RT. “But it needs to be done in an incremental way with an arrow approach, and the heavy hand that lawmakers are taking with these current bills . . . it brings real serious concerns.”

So far CISPA has garnered support from over 100 representatives in the House who are favoring this cybersecurity legislation without taking into considerations what it could do to the everyday user of the Internet. And while the backlash created by opponents of SOPA and PIPA has not materialized to the same degree yet, Burman warns Congress that it could be only a matter of time before concerned Americans step up to have their say.

“One of the lessons we learned in the reaction to SOPA and PIPA is that when Congress tries to legislate on things that are going to affect Internet users’ experience, the Internet users are going to pay attention,” says Burman. H.R. 3523, she cautions, “Definitely could affect in a very serious way the internet experience.” Luckily, adds Burman, “People are starting to notice.” Given the speed that the latest censorship bill could sneak through Congress, however, anyone concerned over the future of the Internet should be on the lookout for CISPA as it continues to be considered on Capitol Hill.

Saturday, July 16, 2011

Pentagon Declares the Internet a Domain of War

Thursday, July 14, 2011 by The Hill (Washington, DC)
by John T. Bennett

The Pentagon released a long-promised cybersecurity plan Thursday that declares the Internet a domain of war.

The plan notably does not spell out how the U.S. military would use the Web for offensive strikes.

The Defense Department’s first-ever plan for cyberspace calls on the DoD to expand its ability to thwart attacks from other nations and groups, beef up its cyber workforce and expand collaboration with the private sector.

Like major corporations and the rest of the federal government, the military “depends on cyberspace to function,” the DoD plan says. The U.S. military uses cyberspace for everything from carrying out military operations to sharing intelligence data internally to managing personnel.

“The department and the nation have vulnerabilities in cyberspace,” the document states. “Our reliance on cyberspace stands in stark contrast to the inadequacy of our cybersecurity.”

Other nations “are working to exploit DoD unclassified and classified networks, and some foreign intelligence organizations have already acquired the capacity to disrupt elements of DoD’s information infrastructure,” the plan states. “Moreover, non-state actors increasingly threaten to penetrate and disrupt DoD networks and systems.”

Groups are capable of this largely because “small-scale technologies” that have “an impact disproportionate to their size” are relatively inexpensive and readily available.

The Pentagon plans to focus heavily on three areas under the new strategy: the theft or exploitation of data; attempts to deny or disrupt access to U.S. military networks; and any attempts to “destroy or degrade networks or connected systems.”

One problem highlighted in the strategy is a baked-in threat: “The majority of information technology products used in the United States are manufactured and assembled overseas.”

DoD laid out a multi-pronged approach to address those issues.

As foreshadowed by Pentagon officials’ comments in recent years, the plan etches in stone that cyberspace is now an “operational domain” for the military, just as land, air, sea and space have been for decades.

“This allows DOD to organize, train and equip for cyberspace” as in those other areas, the plan states. It also noting the 2010 establishment of U.S. Cyber Command to oversee all DOD work in the cyber realm.

The second leg of the plan is to employ new defensive ways of operating in cyberspace, first by enhancing the DoD’s “cyber hygiene.” That term covers ensuring data on military networks remains secure, using the Internet wisely, and designing systems and networks to guard against cyber strikes.

The military will continue its “active cyber defense” approach of “using sensors, software, and intelligence to detect and stop malicious activity before it can affect DOD networks and systems.” It also will look for new “approaches and paradigms” that will include “development and integration … of mobile media and secure cloud computing.”

The plan underscores efforts long underway at the Pentagon to work with other government agencies and the private sector. It also says the Pentagon will continue strong cyber R&D spending, even in a time of declining national security budgets.

Notably, it calls the Department of Homeland Security the lead for “interagency efforts to identify and mitigate cyber vulnerabilities in the nation’s critical infrastructure.” Some experts have warned against DOD overstepping on domestic cyber matters.

The Pentagon also announced a new pilot program with industry designed to encourage companies to “voluntarily [opt] into increased sharing of information about malicious or unauthorized cyber activity.”

The strategy calls for a larger DoD cyber workforce.

One challenge, Pentagon experts say, will be attracting top IT talent because the private sector can pay much larger salaries — especially in times of shrinking Defense budgets. To that end, “DOD will focus on the establishment of dynamic programs to attract talent early,” the plan states.

On IT acquisition, the plan lays out several changes, including: faster delivery of systems; moving to incremental development and upgrading instead of waiting to buy “large, complex systems”; and improved security measures.

Finally, the strategy states an intention to work more closely with “small- and medium-sized business” and “entrepreneurs in Silicon Valley and other U.S. technology innovation hubs.”