Category: Security

Let Him Pay for His Own Damn Security………

It looks like the taxpayers of New York City will on the hook for $1½ million a year for a security detail:

After he retires as NYPD commissioner, Ray Kelly is going to have a lot of company.

According to Murray Weiss of DNAinfo New York, the NYPD Intelligence Division has recommended Kelly, upon retiring, be provided with a 10-man, 24/7 security detail — an increase from the six-man detail Kelly had requested earlier. The detail will cost taxpayers more than $1.5 million per year and will include three sergeants, one lieutenant and six detectives.

After six months, the department will reassess Kelly’s security needs.

By Ray Kelly’s own standards, this is completely unnecessary, since he made the city safe by engaging in racial profiling and intimidation.

Big Brother in Oakland, California

Following protests at the Port of Oakland, the Port set up a surveillance network on their facilities, law enforcement proceeded to expand the network to cover most of the city:

With this city repeatedly roiled by civil protests and the public’s attention sharply focused on government surveillance, local officials are pushing forward with a federally funded project to link surveillance cameras, license-plate readers, gunshot detectors, Twitter feeds, alarm notifications and other data into a unified “situational awareness” tool for law enforcement.

The Domain Awareness Center, a joint project between the Port of Oakland and city, started as a nationwide initiative to secure ports by networking sensors and cameras in and around the facilities. The busy port is one of seven U.S. maritime facilities that the Department of Homeland Security considers at highest risk of a terrorist attack.

Since its inception in 2009, the project has ballooned into a surveillance program for the entire city. Some officials already have proposed linking the center to a regional Department of Homeland Security intelligence-gathering operation or adding feeds from surveillance cameras around the Oakland stadium and arena complex.

As Digby pithily observes, “We just can’t have enough surveillance centers what with all the protests … er terrorists.”

If you build it, law enforcement will use in ways that it was not originally intended for.

Might I Suggest Bruce Schneier?

It appears that the White House is looking at appointing the first civilian ever to head the NSA, but they have concerns that, “Finding the right civilian candidate with the technical understanding and familiarity with intelligence gathering would be a difficult task.”

Bruce Schneier has a sterling pedigree, and a long history of calling out wasteful security theater and the surveillance state.

Not going to happen. Obama is not going to cross the state security apparatus, but I can dream.

Shoot Me Now!

Well, this sucks:

President Obama held a private meeting with top national security journalists on Thursday afternoon following his national security policy address at the National Defense University in Washington, POLITICO has learned.

Present at the meeting were Thomas Friedman, the New York Times columnist; Gerald Seib, the Wall Street Journal’s Washington bureau chief; Fred Hiatt, the editorial page editor of the Washington Post; David Igantius, the Washington Post columnist; Jeffrey Goldberg, the Atlantic correspondent and Bloomberg View columnist; and Joe Klein, the Time Magazine columnist.

Seriously.

This is like a rogues gallery of people who are wrong about everything.

Quote of the Day

On suggestions by a CEO of a company that makes its money from making all of us scared and paranoid:

It sounds to me like the Boston marathon attendees fell down on their job to prevent the attack.

Complete and utter paranoid nonsense

You have no obligation to be a free and voluntary force of Stasi informants.

Nor does the government have the ability to prevent every possible mishap.

What can be done is to care for the injured and assist, if possible, in finding those responsible.

Even more importantly, to live free of fear and suspicion of others.

Otherwise, the terrorists and their counterparts like Phrantceena Halres will have won.

—Patrick Durusau on the assertions of so called security experts that we all need to be paranoid and terrified

FYI,Halrez is, “founder, chairman and CEO Total Protection Services International, a security services company focused exclusively on high threat/close proximity safety and security services.”

So she is in the “scaring the sh%$# out of us” business.

We Look Like Scared, Fearful, Losers Because We Are Scared, Fearful, Losers.

I cannot believe that I am quoting Iraq War booster Fareed Zakaria, but his take on the new invasive US state security apparatus:

While we will leave the battlefields of the greater Middle East, we are firmly committed to the war on terror at home. What do I mean by that? Well, look at the expansion of federal bureaucracies to tackle this war.

Since September 11, 2001, the U.S. government has created or reconfigured at least 263 organizations to tackle some aspect of the war on terror. Thirty-three new building complexes have been built for the intelligence bureaucracies alone, occupying 17 million square feet – the equivalent of 22 U.S. Capitols or three Pentagons. The largest bureaucracy after the Pentagon and the Department of Veterans Affairs is now the Department of Homeland Security, which has a workforce of 230,000 people.

The rise of this national security state has entailed a vast expansion in the government’s powers that now touch every aspect of American life, even when seemingly unrelated to terrorism. Some 30,000 people, for example, are now employed exclusively to listen in on phone conversations and other communications within the United States.

In the past, the U.S. government has built up for wars, assumed emergency authority and sometimes abused that power, yet always demobilized after the war. But this is, of course, a war without end.

………

We don’t look like people who have won a war. We look like scared, fearful, losers.

(emphasis mine)

Osama bin Laden did not win, he’s dead, but we lost, and we did it to ourselves.

H5N1 Gene Studies Finally Published

The US state security apparatus was trying to suppress these studies, because ……… zOMG Terrorists!!!!!! ………, but the research the likelihood of it making a jump to human transmission has been published anyway:

Avian H5N1 influenza viruses in the wild may be one small step away from spreading effectively between mammals. That is the sobering message from a controversial study by Yoshihiro Kawaoka at the University of Wisconsin–Madison, published online by Nature1 after months of debate about how to release the findings publicly.

“After wanting to read it for so long, it was like eating again after fasting,” says Vincent Racaniello, a virologist at Columbia University in New York. “And it does not disappoint.”

H5N1, commonly known as bird flu, is highly pathogenic and often lethal in humans, but it cannot spread efficiently between people and cases seem to be rare. To find out if H5N1 could evolve easy transmissibility between humans, Kawaoka and his team mutated its haemagglutinin (HA) gene, which produces the protein that the virus uses to stick itself to host cells. Because flu viruses in the wild can also gain new properties by swapping genes, the researchers combined this gene with seven others from a highly transmissible flu virus, the H1N1 strain that caused a pandemic in 2009.

Kawaoka found that the hybrid virus could spread between ferrets in separate cages after acquiring just four mutations. Three of these allow the HA protein to stick to receptor molecules on mammalian cells, and the fourth stabilizes the protein. “Before we initiated this experiment, we knew that receptor specificity is important,” says Kawaoka. “We didn’t know what else was needed.”

Worryingly, some Middle Eastern H5N1 strains can already recognize human receptors2. Kawaoka’s work suggests that they could be just one stabilizing mutation away from being able to spread between humans. Discovering “that HA needs to be stable to be transmissible through the air between mammals” is a key finding, says influenza virologist Wendy Barclay at Imperial College London.

We knew that H5N1 was only few mutations away from H2H since well before as soon as the security Mafia’s heads started to explode in an orgy of security theater.

The post 911 security apparatus doing more harm than good.

Full Disclosure, I Served in the UMass SGA Senate With Him

They are finally getting around to sentencing Tony Rudy, one of the final defendants in the Abramoff matter, 6 years after he pled guilty.

The weird thing is that the prosecution and defense have agreed to have the agreed upon facts sealed for national security reasons:

Nearly six years after he pleaded guilty in the Jack Abramoff scandal, a former aide to House Majority Leader Tom DeLay will likely be sentenced in the near future. But because of a joint motion granted by the federal judge hearing the case against Tony Rudy, the public wouldn’t see the filing listing agreed upon facts in the case.

The reason? National security.

The feds and Rudy’s defense team wrote that the disclosure of “sensitive information related to national security matters” likely “would compromise and negatively impact ongoing intelligence efforts.” They said the sensitive information had “no relationship to the Department of Justice’s investigation of Jack Abramoff or related persons.”

The folks at TPM got a comment from Abramoff about this, and he was pretty stunned by this.

My guess is that he probably did some work for a Persian Gulf monarchy, and the State Department wants it buried, but we’re likely to find out through a leak in the next few months.

Am I the Only One to Call False Flag?

Symantec with an assist from the FBI, is now alleging that a group of hackers stole the source code for pcAnywhere and attempted to shake them down for $50,000.

OK, I get that. But what I doubt is the claim, coming from either the software firm, or the boyz in the Hoover building, that the miscreants are, “group of hackers associated with Anonymous and AntiSec.”*

As MP at the Stellar Parthenon BBS observes, “Anyone claiming to be raising funds in any way on behalf of Anonymous is about as kosher as bacon-wrapped shrimp.”

I have no doubt that Symantec got hacked. I’ve suffered with their software at a number of work places, but my sense is that any mention Anonymous is something that the FBI spent a lot of time manufacturing.

After all, it looks much better in a personnel file at annual review time.

*Tin foil hat. When I originally read the first article, there were constant mentions to anonymous, and now they are all gone.

An Interesting Solution to the Problem of Phishing and Hacking:

A web master has come to the conclusion that the first step in managing this sort of activity is to, “block all traffic from China:

I run quite a few few websites and blogs and my solution to this problem was first to BLOCK all traffic from China, I allow nothing, nada, zip from China based IPs. From my personal experience 100% of China’s internet traffic is hacking attempts, email SPAM and phishing. I have never encountered a single China access that could be considered positive.

Blocking China has solved about 80~90% of the problem. The second thing is to block specific domains and IPs from Russia, Romania, Brazil, Taiwan, Korea, Poland and may other ex Soviet Satellites. I can’t block all access to these countries because there is about 90% of legitimate traffic and the 10% left are probably compromised computers being used as proxies/bots for China.

I tried to find the original source for this and a quick google indicates that there are a significant number of web masters who are beginning to consider this as a first step for web security on their sites.

Obviously, I am not a webmaster, but I’m wondering just how wide spread this phenomenon is.

Trust the TSA, Episode XLVIX

It turns out that their airport scanners cause cancer:

On Sept. 23, 1998, a panel of radiation safety experts gathered at a Hilton hotel in Maryland to evaluate a new device that could detect hidden weapons and contraband. The machine, known as the Secure 1000, beamed X-rays at people to see underneath their clothing.

One after another, the experts convened by the Food and Drug Administration raised questions about the machine because it violated a longstanding principle in radiation safety — that humans shouldn’t be X-rayed unless there is a medical benefit.

“I think this is really a slippery slope,” said Jill Lipoti, who was the director of New Jersey’s radiation protection program. The device was already deployed in prisons; what was next, she and others asked — courthouses, schools, airports? “I am concerned … with expanding this type of product for the traveling public,” said another panelist, Stanley Savic, the vice president for safety at a large electronics company. “I think that would take this thing to an entirely different level of public health risk.”

…………

Research suggests that anywhere from six to 100 U.S. airline passengers each year could get cancer from the machines. Still, the TSA has repeatedly defined the scanners as “safe,” glossing over the accepted scientific view that even low doses of ionizing radiation — the kind beamed directly at the body by the X-ray scanners — increase the risk of cancer.

“Even though it’s a very small risk, when you expose that number of people, there’s a potential for some of them to get cancer,” said Kathleen Kaufman, the former radiation management director in Los Angeles County, who brought the prison X-rays to the FDA panel’s attention.

…………

As for the TSA, it skipped a public comment period required before deploying the scanners. Then, in defending them, it relied on a small body of unpublished research to insist the machines were safe, and ignored contrary opinions from U.S. and European authorities that recommended precautions, especially for pregnant women. Finally, the manufacturer, Rapiscan Systems, unleashed an intense and sophisticated lobbying campaign, ultimately winning large contracts.

(emphasis mine)

You have to love the Security Theater Industrial Complex.

This ain’t about keeping us safe, it’s about extracting money from the 99% for the benefit of the 1% by creating an atmosphere of unreasoning fear.

When Michael Hayden Says That You Over Classify…

You have gone way beyond an even remotely sane assessment of the need for secrecy:

Ex-head of the National Security Agency and CIA and retired U.S. Air Force Gen. Michael Hayden said federal agencies need to open up to public and private industry to address cyber threats

As cyber security climbs its way up the priority list after 2011’s string of attacks against government and corporate systems, U.S. government agencies and companies struggle to find a happy medium between excessive secrecy and too much disclosure regarding the handling of such issues.

Going one way or the other can have severe repercussions. Excessive secrecy can stifle cyber defense, as too much focus could be placed on an issue that was already resolved elsewhere. If you keep it secret, someone who might know how to fix it cannot do so. Too much disclosure, on the other hand, gives hackers what they need to work around security systems.

This is kind of like Sweeney Todd saying that you are too rough when you give a shave.

Well, At Least It’s Not My Employer

Lockheed had to locked down its network after it was massively hacked:

By all accounts, Lockheed Martin’s swift detection of the attack helped avert potential disaster. “The good news here is that the contractor was able to detect an intrusion then did the right things to deal with it,” Cringely said. “A breach like this is very subtle and not easy to spot.” Furthermore, he said, the same day that Lockheed Martin detected the attack, all remote access for employees was disabled, and the company told all telecommuters to work from company offices for at least a week. Then on Wednesday, the company informed all remote workers that they’d receive new RSA SecurID tokens and told all 133,000 employees to reset their network passwords.

In a statement released Sunday, EMC said it was “premature to speculate” on the details of the attack. But if attackers did use information stolen from RSA to hack into the SecurID system used by Lockheed Martin, then EMC could be forced to finally reveal, publicly, any risks that the use of its system might now pose to the 40 million users of SecurID hardware token customers and 250 million users of its SecurID software.

I’m a contractor, so even if my employer were hacked in this manner, it would not effect me, since that don’t give mercenaries like me remote access to their networks.

Of course, they should have locked down their system months ago, when RSA, the company that supplies the keys for their VPN systems, and a lot of other companies out there, was hacked.

This is What You Get When You Fist F%$# a Cobra …

Click for full size


Complete PWN463!

I while back, I mentioned 4Chan, I should add the inventive group of people known as Anonymous who ofttimes frequent 4Chan:

Anonymous, the online collective that launched DDoS attacks on Visa, PayPal and others in support of whistle-blowing site WikiLeaks, has brought down the web site of a firm helping the FBI to unmask its members.

Security services firm HBGary Federal had been helping the Feds to track down the individuals behind a number of distributed denial of service (DDoS) attacks on companies including Amazon, PayPal, Visa, MasterCard, Swiss bank PostFinance and Bank of America, after the firms suspended services to WikiLeaks.

In a sophisticated attack, Anonymous members hacked into HBGary’s website and posted an image containing a message explaining their actions. In addition, they downloaded over 60,000 messages from the company’s email servers and posted them on The Pirate Bay.

The Twitter account of HBGary’s CEO, Aaron Barr, was also compromised and used to tweet a number of offensive messages, as well as his home address, social security number and mobile phone number.

(Link to torrent mine, and I make no claims as to the safety or veracity of the data.  I have not downloaded the data myself)

Yeah, and it has also been reported that they deleted HBGary’s backups.

Not only did they pick a fight with Anonymous, but it also appears that they are complete posers as well, who were leaching publicly available names from Facebook and IRC, and trying to sell this to the FBI.

Well, not any more, because, according to the letter that was the HBGary home page (above) they sent the data to the FBI themselves.

What a bunch of complete wankers, Aaron Barr and company that is, I have nothing but the utmost respect for Anonymous.

And so Anonymous is added to my list of People I Do Not Want to Piss Off, and HBGary is added to the likes or Razorfish, to my list of people who I would never trust with anything more complex than a mechanical pencil.

Because We Want to Be Just Like Hosni Mubarak’s Egypt

Susan Collins and Joseph “The Human Stain” Lieberman, want there to be kill switch for the Internet in the United States that can be invoked at will without judicial review:

A controversial bill handing President Obama power over privately owned computer systems during a “national cyberemergency,” and prohibiting any review by the court system, will return this year.

Internet companies should not be alarmed by the legislation, first introduced last summer by Sens. Joseph Lieberman (I-Conn.) and Susan Collins (R-Maine), a Senate aide said last week. Lieberman, an independent who caucuses with Democrats, is chairman of the Senate Homeland Security and Governmental Affairs Committee.

“We’re not trying to mandate any requirements for the entire Internet, the entire Internet backbone,” said Brandon Milhorn, Republican staff director and counsel for the committee.

…………

The revised version includes new language saying that the federal government’s designation of vital Internet or other computer systems “shall not be subject to judicial review.” Another addition expanded the definition of critical infrastructure to include “provider of information technology,” and a third authorized the submission of “classified” reports on security vulnerabilities.

The idea of creating what some critics have called an Internet “kill switch” that the president could flip in an emergency is not exactly new.

Just imagine Dick Cheney’s finger on the button.

“Not subject to judicial review,” that’s a wet dream for the former VP.

Obscurity is not Security

But this isn’t stopping banks from trying to suppress security research showing that their cards are insecure, as opposed to manning up and fixing the problem:

Cambridge computer scientists have become embroiled in angry exchanges with Britain’s banks and credit card lenders, accusing them of bullying and trying to “censor” a PhD student who was exposing flaws in chip-and-pin machines.

A leading Cambridge academic has now written to bankers’ representatives demanding that they stop pressing for the removal of a student’s doctorate work from the web.

Professor Ross Anderson, from Cambridge University’s Computer Laboratory, has previously researched glitches in chip-and-pin banking that allow withdrawals to be made from accounts without needing to know the holder’s PIN. As part of his thesis work, one of his students, Omar Choudary, exposed how easy it was to make such a withdrawal.

Then the UK Cards Association, a trade body representing leading banking organisations, approached the university asking it to remove the thesis from his website, which is accessible through a university site.

So, the knowledge is out there, and it is public, it has actually been discussed on the BBC, and the banks want to pretend that it never happened.

This is why you cannot rely on market mechanisms for this kind of stuff.

Assange Jailed

Note that he has not been charged, and the warrant is for an interview, a British magistrate has ordered Julian Assange held without bail after he turned himself in voluntarily.

Tell me that the fix is not in here.

Of course, the fact that hundreds, perhaps thousands of people, have his ITEOD* file, and some number probably greater than 10 people have the code to decrypt those unredacted files has got to give the people pursuing him cause to pause.

*In The Event Of Death.