Understanding The Militarized Internet

Understanding The Militarized Internet

cyber-war-landscape-warriors

If twitter is any gauge, a lot of people think this article in Wired about General Keith Alexander is just all kinds of kewl:

General Keith Alexander, a man few even in Washington would likely recognize. Never before has anyone in America’s intelligence sphere come close to his degree of power, the number of people under his command, the expanse of his rule, the length of his reign, or the depth of his secrecy. A four-star Army general, his authority extends across three domains: He is director of the world’s largest intelligence service, the National Security Agency; chief of the Central Security Service; and commander of the US Cyber Command. As such, he has his own secret military, presiding over the Navy’s 10th Fleet, the 24th Air Force, and the Second Army.

Alexander runs the nation’s cyberwar efforts, an empire he has built over the past eight years by insisting that the US’s inherent vulnerability to digital attacks requires him to amass more and more authority over the data zipping around the globe. In his telling, the threat is so mind-bogglingly huge that the nation has little option but to eventually put the entire civilian Internet under his protection, requiring tweets and emails to pass through his filters, and putting the kill switch under the government’s forefinger. “What we see is an increasing level of activity on the networks,” he said at a recent security conference in Canada. “I am concerned that this is going to break a threshold where the private sector can no longer handle it and the government is going to have to step in.”

In its tightly controlled public relations, the NSA has focused attention on the threat of cyberattack against the US—the vulnerability of critical infrastructure like power plants and water systems, the susceptibility of the military’s command and control structure, the dependence of the economy on the Internet’s smooth functioning. Defense against these threats was the paramount mission trumpeted by NSA brass at congressional hearings and hashed over at security conferences.

But there is a flip side to this equation that is rarely mentioned: The military has for years been developing offensive capabilities, giving it the power not just to defend the US but to assail its foes. Using so-called cyber-kinetic attacks, Alexander and his forces now have the capability to physically destroy an adversary’s equipment and infrastructure, and potentially even to kill. Alexander—who declined to be interviewed for this article—has concluded that such cyberweapons are as crucial to 21st-century warfare as nuclear arms were in the 20th.

And he and his cyberwarriors have already launched their first attack. The cyberweapon that came to be known as Stuxnet was created and built by the NSA in partnership with the CIA and Israeli intelligence in the mid-2000s. The first known piece of malware designed to destroy physical equipment, Stuxnet was aimed at Iran’s nuclear facility in Natanz. By surreptitiously taking control of an industrial control link known as a Scada (Supervisory Control and Data Acquisition) system, the sophisticated worm was able to damage about a thousand centrifuges used to enrich nuclear material.

The success of this sabotage came to light only in June 2010, when the malware spread to outside computers. It was spotted by independent security researchers, who identified telltale signs that the worm was the work of thousands of hours of professional development. Despite headlines around the globe, officials in Washington have never openly acknowledged that the US was behind the attack. It wasn’t until 2012 that anonymous sources within the Obama administration took credit for it in interviews with The New York Times.

But Stuxnet is only the beginning. Alexander’s agency has recruited thousands of computer experts, hackers, and engineering PhDs to expand US offensive capabilities in the digital realm. The Pentagon has requested $4.7 billion for “cyberspace operations,” even as the budget of the CIA and other intelligence agencies could fall by $4.4 billion. It is pouring millions into cyberdefense contractors. And more attacks may be planned.

I don’t suppose the American public have any business knowing if their government is launching such attacks. Why would we? What could possibly go wrong?

Inside the government, the general is regarded with a mixture of respect and fear, not unlike J. Edgar Hoover, another security figure whose tenure spanned multiple presidencies. “We jokingly referred to him as Emperor Alexander—with good cause, because whatever Keith wants, Keith gets,” says one former senior CIA official who agreed to speak on condition of anonymity. “We would sit back literally in awe of what he was able to get from Congress, from the White House, and at the expense of everybody else.”

Now 61, Alexander has said he plans to retire in 2014; when he does step down he will leave behind an enduring legacy—a position of far-reaching authority and potentially Strangelovian powers at a time when the distinction between cyberwarfare and conventional warfare is beginning to blur. A recent Pentagon report made that point in dramatic terms. It recommended possible deterrents to a cyberattack on the US. Among the options: launching nuclear weapons.

Like I said, what could possibly go wrong?

When the Guardian revealed this program the other day there was a spirited debate about whether this, unlike the other programs, was something we should welcome and expect. My problem with it wasn’t that the government was creating plans to defend against attacks on US cyber-infrastructure or even war plans in case such a thing happened. What I found questionable was the idea that this was conceived as  21st Century offensive war planning, and and in ways that do not necessarily fall within the traditional “national security” boundaries.

When it comes to cyber issues, I’m afraid we are seeing a confluence of commerce and security that everyone should stop and think about for a minute. How are these people defining the “national interest” and on whose behalf are they planning to launch cyberwar? What are the consequences of doing such a thing and who decides that it must be done?

And what do we think about paying huge amounts of taxpayer dollars to contractors like this?

Defense contractors have been eager to prove that they understand Alexander’s worldview. “Our Raytheon cyberwarriors play offense and defense,” says one help-wanted site. Consulting and engineering firms such as Invertix and Parsons are among dozens posting online want ads for “computer network exploitation specialists.” And many other companies, some unidentified, are seeking computer and network attackers. “Firm is seeking computer network attack specialists for long-term government contract in King George County, VA,” one recent ad read. Another, from Sunera, a Tampa, Florida, company, said it was hunting for “attack and penetration consultants.”

One of the most secretive of these contractors is Endgame Systems, a startup backed by VCs including Kleiner Perkins Caufield & Byers, Bessemer Venture Partners, and Paladin Capital Group. Established in Atlanta in 2008, Endgame is transparently antitransparent. “We’ve been very careful not to have a public face on our company,” former vice president John M. Farrell wrote to a business associate in an email that appeared in a WikiLeaks dump. “We don’t ever want to see our name in a press release,” added founder Christopher Rouland. True to form, the company declined Wired’s interview requests.
[…]
Bonesaw also contains targeting data on US allies, and it is soon to be upgraded with a new version codenamed Velocity, according to C4ISR Journal. It will allow Endgame’s clients to observe in real time as hardware and software connected to the Internet around the world is added, removed, or changed. But such access doesn’t come cheap. One leaked report indicated that annual subscriptions could run as high as $2.5 million for 25 zero-day exploits.

The buying and using of such a subscription by nation-states could be seen as an act of war. “If you are engaged in reconnaissance on an adversary’s systems, you are laying the electronic battlefield and preparing to use it,” wrote Mike Jacobs, a former NSA director for information assurance, in a McAfee report on cyberwarfare. “In my opinion, these activities constitute acts of war, or at least a prelude to future acts of war.” The question is, who else is on the secretive company’s client list? Because there is as of yet no oversight or regulation of the cyberweapons trade, companies in the cyber-industrial complex are free to sell to whomever they wish. “It should be illegal,” says the former senior intelligence official involved in cyber­warfare. “I knew about Endgame when I was in intelligence. The intelligence community didn’t like it, but they’re the largest consumer of that business.”

There are some serious implications to all of this that need to be hashed out by the American people. Of course we need to have defenses against cyber attacks. I don’t think anyone in the country thinks otherwise. But this looks like it could be a monumental financial boondoggle that is in great danger of running amok and causing some very serious problems. Frankly, this scares me much more than the threat that some would-be is going to get a hold of some beauty supplies and blow himself up.

Islamic terrorism is not and never has been an existential threat. This, I’m not so sure about. We should at least have a little chat about it before we let Cyber Buck Turgidson and his friends run wild.

by Digby

 

April 9, 2013 – Decrypted Matrix Radio: DoJ Cries Espionage, Spying MobileApps, Wikileaks Kissinger Cables, Katt Williams Illuminati, Bird Flu Bio-Weapon, Anonymous Attacks Israel

April 9, 2013 – Decrypted Matrix Radio: DoJ Cries Espionage, Spying MobileApps, Wikileaks Kissinger Cables, Katt Williams Illuminati, Bird Flu Bio-Weapon, Anonymous Attacks Israel

Obama’s 7th Espionage Act Case Against a Non-Spy

Study: Mobile phone apps view private data more than necessary

Wikileaks – The Kissinger Cables

Katt Williams: “We Are Against the Illuminati at Our Own Detriment”

Chinese Colonel Says Latest Bird Flu Virus Is U.S. Biological Weapon

Big Pharma made $711 billion overcharging seniors and disabled

Anonymous blitzes Israel in new cyber attack over War Crimes and Human Rights Violations

4-9

Every Week Night 12-1am EST (9-10pm PST)

– Click Image to Listen LIVE –

August 3, 2012 – DCMX Radio: Re-cap Week’s Alternative News, Intro to CyberWar: Viruses, Hacking, & Black Security Breaches, Protecting Your Computer, Securing Your Internet Connection & Maintaining Privacy Online

August 3, 2012 – DCMX Radio: Re-cap Week’s Alternative News, Intro to CyberWar: Viruses, Hacking, & Black Security Breaches, Protecting Your Computer, Securing Your Internet Connection & Maintaining Privacy Online

Cyber Security Industry Explosion, Intelligence Spying, Data-mining, Black-Hats, White-Hats, Gray-Hats abound. Alphabet Agencies, Corrupt Globalist Corporations exploiting your info. Micro Tutorial on Protecting Your Computer, Securing Your Internet Connection, Maintaining ‘some’ Privacy Online


Every Week Night 12-1am EST (9-10pm PST)

– Click Image to Listen LIVE –

Appeals Court: No Forced Decryption

Appeals Court: No Forced Decryption

Privilege Against Self-Incrimination Applies to Act of Decrypting Data

San Francisco – A federal appeals court has found a Florida man’s constitutional rights were violated when he was imprisoned for refusing to decrypt data on several devices. This is the first time an appellate court has ruled the 5th Amendment protects against forced decryption – a major victory for constitutional rights in the digital age.

In this case, titled United States v. Doe, FBI agents seized two laptops and five external hard drives from a man they were investigating but were unable to access encrypted data they believed was stored on the devices via an encryption program called TrueCrypt. When a grand jury ordered the man to produce the unencrypted contents of the drives, he invoked his Fifth Amendment privilege against self-incrimination and refused to do so. The court held him in contempt and sent him to jail.

The Electronic Frontier Foundation (EFF) filed an amicus brief under seal, arguing that the man had a valid Fifth Amendment privilege against self-incrimination, and that the government’s attempt to force him to decrypt the data was unconstitutional. The 11th U.S. Circuit Court of Appeals agreed, ruling that the act of decrypting data is testimonial and therefore protected by the Fifth Amendment. Furthermore, the government’s limited offer of immunity in this case was insufficient to protect his constitutional right, because it did not extend to the government’s use of the decrypted data as evidence against him in a prosecution.

“The government’s attempt to force this man to decrypt his data put him in the Catch-22 the 5th Amendment was designed to prevent – having to choose between self-incrimination or risking contempt of court,” said EFF Senior Staff Attorney Marcia Hofmann. “We’re pleased the appeals court recognized the important constitutional issues at stake here, and we hope this ruling will discourage the government from using abusive grand jury subpoenas to try to expose data people choose to protect with encryption. ”

A similar court battle is ongoing in Colorado, where a woman named Ramona Fricosu has been ordered by the court to decrypt the contents of a laptop seized in an investigation into fraudulent real estate transactions. EFF also filed a friend of the court brief in that case, arguing that Fricosu was being forced to become a witness against herself. An appeals court recently rejected her appeal, and she has been ordered to decrypt the information this month.

“As we move into an increasingly digital world, we’re seeing more and more questions about how our constitutional rights play out with regards to the technology we use every day,” said EFF Staff Attorney Hanni Fakhoury. “This is a case where the appeals court got it right – protecting the 5th Amendment privilege against self-incrimination.”

John Doe was represented by Chet Kaufman of the Federal Public Defender’s Office in Tallahassee.

For the full court ruling:
https://www.eff.org/document/opinion

Contacts:

Marcia Hofmann
Senior Staff Attorney
Electronic Frontier Foundation
[email protected]

Hanni Fakhoury
Staff Attorney
Electronic Frontier Foundation
[email protected]

US Cyber Command achieves ‘full operational capability,’ international cyberbullies be warned

US Cyber Command achieves ‘full operational capability,’ international cyberbullies be warned

By posted Nov 5th 2010 8:52AM

A sword, a lightning bolt, a key, a globe, and a bird. These are the symbols of your United States Cyber Command, which you’ll be proud to know has “achieved full operational capability.” FOC is when a military organization basically has what it needs and knows how to use it, but we’re guessing our new cyber-commandos will be a little nervous at first, like a prom date just presented with a room key, or a Modern Warfare player with a new weapon attachment. Surely the USCC will get into its stride real soon, enabling it to “operate and defend our networks effectively.” You know what that means: feel free to be a little extra offensive when trolling on foreign soil today. Uncle Sam has your back.

 

http://www.engadget.com/2010/11/05/us-cyber-command-achieves-full-operational-capability-interna/