Category: Security

Holy Sh%$

Last weekend, the US Military lost control of a missile squadron:

President Obama was briefed this morning on an engineering power failure at F.E. Warren Air Force Base in Wyoming that took 50 nuclear intercontinental ballistic missiles (ICBMs), one-ninth of the U.S. missile stockpile, temporarily offline on Saturday.

The base is a main locus of the United States’ strategic nuclear forces. The 90th Missile Wing, headquartered there, controls 150 Minuteman III intercontinental ballistic nuclear missiles. They’re on full-time alert and are housed in a variety of bunkers across several states.

On Saturday morning, according to people briefed on what happened, a squadron of ICBMs suddenly dropped down into what’s known as “LF Down” status, meaning that the missileers in their bunkers could no longer communicate with the missiles themselves. LF Down status also means that various security protocols built into the missile delivery system, like intrusion alarms and warhead separation alarms, were offline. In LF Down status, the missiles are still technically launch-able, but they can only be controlled by an airborne command and control platform like the Boeing E-6 NAOC “Kneecap” aircraft, E-4B NAOC aircraft or perhaps the TACAMO fleet, which is primarily used to communicate with nuclear submarines. Had the country been placed on a higher state of nuclear alert, those platforms would be operating automatically because the frequencies used to transmit nuclear codes would be interfacing with separate systems, according to officials.

(strike-through original)

This is about 19 of our land based deterrent.

Great googly moogly.

I Really Cannot Wrap My Head Around this

As much as I rag on the Washington Post, there is some reporting of real value amongst the dross, including Dana Priest, who, along with William M. Arkin, have published an extensive investigative report on the burgeoning world of the American security-industrial complex:

These are some of the findings of a two-year investigation by The Washington Post that discovered what amounts to an alternative geography of the United States, a Top Secret America hidden from public view and lacking in thorough oversight. After nine years of unprecedented spending and growth, the result is that the system put in place to keep the United States safe is so massive that its effectiveness is impossible to determine.

Basically it points to a picture of a state security apparatus run amuck, where there are so many players, generating so much analysis, from so many sources, that it is impossible to separate the wheat from the chaff, or as Glenn Greenwald notes:

So it isn’t that we keep sacrificing our privacy to an always-growing National Security State in exchange for greater security. The opposite is true: we keep sacrificing our privacy to the always-growing National Security State in exchange for less security.

(emphasis original)

More than ever, we need to ensrhine into the constitution something analogous to the the Swedish concept of Offentlighetsprincipen (openness), because right now all that our paranoia is generating is a massive trail of profiteers/contractors without generating much in the way of security.

It should be noted that reigning in this will not be easy. You can be sure that when the budgets are in jeopardy, the various wings of the state security apparatus will come up with scary stories to subvert any effort at real reform, and the current administration is terrified of being labeled, “soft on fillintheblank,” so they do not have the inclination to even bend the curve.

I’ll be going through the story, and the supporting material, to see if I have anything to add.

I’m Not Sure if This is Real, or Just a Corporate Pissing Contest…

But Google is ditching Microsoft® Windows® completely. No one in the enterprise is going to be allowed to have it on their company machines anymore:

Google is phasing out the internal use of Microsoft’s ubiquitous Windows operating system because of security concerns, according to several Google employees.

The directive to move to other operating systems began in earnest in January, after Google’s Chinese operations were hacked, and could effectively end the use of Windows at Google, which employs more than 10,000 workers internationally.

“We’re not doing any more Windows. It is a security effort,” said one Google employee.

“Many people have been moved away from [Windows] PCs, mostly towards Mac OS, following the China hacking attacks,” said another.

New hires are now given the option of using Apple’s Mac computers or PCs running the Linux operating system. “Linux is open source and we feel good about it,” said one employee. “Microsoft we don’t feel so good about.”

Obviously with a bit more than 10,000 employees, one would assume that there somewhere around 20K licenses floating around, which is a small part of Microsoft’s market, but it’s also a poke in the eye.

Obviously, Google will move its employees to its online apps Google Docs at some point in the future, which might be a greater threat to Bill Gates’s revenue streams

Heads Up to My Reader(s)

A few weeks ago, a reader told me that my site was crashing their browser.

I checked it out, and found no problems, and so I concluded that it was something that Google™ Adsense™ was serving.

Well, it appears that, on occasion, Google™ Adsense™ serving a bit more than just ads, as Avast has discovered that the large ad networks have occasionally served up malware:

Malware that exploits holes in popular applications is being delivered by big ad delivery platforms including those run by Yahoo, Fox, and Google, according to Prague-based antivirus firm Avast.

Viruses and other malware were found to be lurking in ads last year on high-profile sites like The New York Times and conservative news aggregator Drudge Report.com, and this year on Drudge, TechCrunch and WhitePages.com. The practice has been dubbed “malvertising.”

Now, researchers at Avast are pointing fingers at some large ad delivery platforms including Yahoo’s Yield Manager and Fox Audience Network’s Fimserve.com, which together cover more than 50 percent of online ads, and to a much smaller degree Google’s DoubleClick. In addition, some of the malicious ads ended up on Yahoo and Google sites, Avast claims.

Google™ Adsense™ is not mentioned, just DoubleClick, though there are ties between the two, since Google™ owns Double Click, and the worst offenders honors go to Yahoo and Fox.

In any case, please keep your spyware and virus filters up to date.

Please note: once again, that I do not vet, nor do I endorse any ad that appears on my site, and I reserve the right to mock both the ads that appear on my site, as well as the advertisers.

Also, please note, this should be in no way construed as an inducement or a request for my reader(s) to click on any ad that they would not otherwise be inclined to investigate further. This would be a violation of the terms of service for Google Adsense.

Google Mulls Jumping C. Megalodon*


This is one big shark that they jumped.
With Frikken Lasers!

So, now that the Chinese have hacked into Google, the Google has decided to throw in their lot with the National Security Agency to protect themselves:

The world’s largest Internet search company and the world’s most powerful electronic surveillance organization are teaming up in the name of cybersecurity.

Under an agreement that is still being finalized, the National Security Agency would help Google analyze a major corporate espionage attack that the firm said originated in China and targeted its computer networks, according to cybersecurity experts familiar with the matter. The objective is to better defend Google — and its users — from future attack.

Google and the NSA declined to comment on the partnership. But sources with knowledge of the arrangement, speaking on the condition of anonymity, said the alliance is being designed to allow the two organizations to share critical information without violating Google’s policies or laws that protect the privacy of Americans’ online communications. The sources said the deal does not mean the NSA will be viewing users’ searches or e-mail accounts or that Google will be sharing proprietary data.

Of course, neither does giving money to a junkie mean that they will be buying heroin.

As Noah Schachtman notes, it doesn’t require a tinfoil hat to think that it is possible, nay, even likely, that the NSA will use this access to suck data like a giant hoover. It’s what they do:

But there’s a problem. The NSA and its predecessors also have a long history of spying on huge numbers of people, both at home and abroad. During the Cold War, the agency worked with companies like Western Union to intercept and read millions of telegrams. The during the war on terror years, the NSA teamed up with the telecommunications companies to eavesdrop on customers’ phone calls and Internet traffic right from the telcos’ switching stations. And even after the agency pledged to clean up its act — and was given wide new latitude to spy on whom they liked – the NSA was still caught “overcollecting” on U.S. citizens. According to the New York Times, the agency even “tried to wiretap a member of Congress without a warrant.”

All of which makes the NSA a particularly untrustworthy partner for a company that is almost wholly reliant on its customers’ trust and goodwill. We all know that Google automatically reads our G-Mail and scans our Google Calendars and dives into our Google searches, all in an attempt to put the most relevant ads in front of us. But we’ve tolerated the automated intrusions, because Google’s products are so good, and we believed that the company was since in its “don’t be evil” mantra.

The issue here is not that Google would voluntarily allow the NSA to access personally identifiable data, it is that they are ill equipped to defend themselves against a company that hoovered the entire Internet.

If the NSA does not leave a back door in the Google servers, without the knowledge of Google management, as part of their efforts, then they would not be doing their job properly.

This is like employing Lady Gaga as a model for tastefully modest evening wear.

*The largest shark, and likely largest predator fish ever. It died out some 1.5 million years ago. The Genus is still in dispute, between either Carcharodon (Great White) or Carcharocles (broad toothed Mako). But in either case, you are jumping C. Megalodon, you have jumped the biggest shark ever.

Tefillin of Mass Destruction

Click for full size



You shall bind them as a sign on your hand, and they shall be as frontlets between your eyes

Deuteronomy 6:8

So a plane was diverted to Philadelphia on a New York to Kentucky flight because of concerns of the straps and boxes that a Jewish Teen was wearing as he prayed:

Jewish teen’s prayers spark airliner scare
Flight is diverted after religious item is mistaken for a bomb, police say

updated 9:18 a.m. ET, Fri., Jan. 22, 2010

PHILADELPHIA – A Jewish teenager trying to pray on a New York-to-Kentucky flight caused a scare Thursday when he pulled out a set of small boxes containing holy scrolls, leading the captain to divert the flight to Philadelphia, where the commuter plane was greeted by police, bomb-sniffing dogs and federal agents.

The 17-year-old on US Airways Express Flight 3079 was using tefillin, a set of small boxes containing biblical passages that are attached to leather straps, Philadelphia police Lt. Frank Vanore said.

You know, the guy wearing Tefillin is among the people least likely to be an Islamic bomber.

Dances With TSA

I’m sitting in Philadelphia waiting for the flight to Boston, and I thought that I would relate my experience with airport security.

It was a surprisingly smooth experience, despite the fact that they pulled my bag for further inspection.

The 7 day yartzheit (memorial candle) is a 3″ x 14″cylinder, so I can see how the X-ray machine operator flagged it for further scrutiny.

Still, the whole process, show my ID (honest, officer, I look better in person) and bording pass, take off shoes, put shoes, keys, etc. in bin, put bin and bag through the X-ray machine, grab my stuff, put on my shoes, open my case, show the candle, let the TSA guy wipe my stuff with a “sniffer”, and repacking my case only took about 15 minutes.

I can’t complain.

Why the Air Force as an Independent Service Should be Abolished: Part 32

Matthew Yglesias reports that retired USAF Lieutenant General Tom McInerney has just called for mandatory strip searches of all Muslims aged between the ages of 18 to 28 in an interview with (who else)Fox News.

This guy is bats%$# insane, but his insanity is endemic with the Air Force, as has been noted in a number of stories regarding a pervasive atmosphere of religious harassment at the Air Force academy.

(I’ve done a couple of posts on the problem generally.)

The problem here is not that he was in the Air Force. Any organization will have its share of crazies, criminals, and incompetents.

The problem is that he made it to 3-stars, despite being clearly unhinged, and there is way too much of that in the US air force.

In fact, in the video below, it’s clear that it’s so crazy that the interviewer on Fox feels the need to call him out on this, because of the hostility it would engender:

Bootnote: It looks like Al-Jazeerah is already covering it, so congratulations general, you just murdered a dozen or so US troops over the next few months.

Elections Have Consequences: Not Pandering to the House of Saud

In response to the attempted bombing of Northwest Flight 253, the TSA will engage in aggressive screening of travelers from 14 countries.

I think that, once again, we are seeing something that is more security theater than real security, but there is a refreshing change in this little charade:

Citizens of 14 nations, including Pakistan, Saudi Arabia and Nigeria, who are flying to the United States will be subjected indefinitely to the intense screening at airports worldwide that was imposed after the Christmas Day bombing plot, Obama administration officials announced Sunday.

………………

Citizens of Cuba, Iran, Sudan and Syria, countries that are considered “state sponsors of terrorism,” as well as those of “countries of interest” — including Afghanistan, Algeria, Lebanon, Libya, Iraq, Nigeria, Pakistan, Saudi Arabia, Somalia and Yemen — will face the special scrutiny, officials said.

(emphasis mine)

This is significant break from the way that Bush and His Evil Minions dealt with the House of Saud, which basically involved putting their tongues so far up the anus of Prince Bandar that they tasted tonsils.

Security Theater

Bruce Schneier, once again, is all over it:

Our current response to terrorism is a form of “magical thinking.” It relies on the idea that we can somehow make ourselves safer by protecting against what the terrorists happened to do last time.

Unfortunately for politicians, the security measures that work are largely invisible. Such measures include enhancing the intelligence-gathering abilities of the secret services, hiring cultural experts and Arabic translators, building bridges with Islamic communities both nationally and internationally, funding police capabilities — both investigative arms to prevent terrorist attacks, and emergency communications systems for after attacks occur — and arresting terrorist plotters without media fanfare.

It’s very clear that many of the so-called security measures do not enhance security, but exist to create an appearance of security.

Just go read it.

I’m Shocked, Shocked To Find That Gambling Is Going On In Here!


(Cue Captain Renault)

So, Tom Ridge tells us now that Bush and His Evil Minions manipulated terror alerts for political gain.

But he vehemently denied any such effort while he was in office, and delayed his resignation as head of DHS until after the election.

He knew that it was wrong, but he kept his mouth shut, and now he writes a book, and it’s supposed to make everything hunky dory….It does not.

Mr. Ridge, as I stated only yesterday, I do not take the term “treason” lightly, but it appears to me that your complicity in this affair, when you knew that it was happening, and you know that it was wrong, and you knew that it was damaging to the country, comes awfully close to that term.

Coast Guard Stripped of Acquisition Power

Following the Coast Guard’s Deepwater modernization program, I am not surprised that the Department of Homeland Security has stripped the Coast Guard of acquisition authority, so that now the DHS will have to sign off on, and supervise all contracts.

To be fair, this is not entirely the Coast Guard’s fault. Deepwater was managed under the Lead System Integrator (LSI) model, which is best defined as trusting the fox to manage the hen house.

Now, if only we could do the same with the USAF and Navy.

And in the World of Ineffective Abusive Security Techniques …..

Mario Labbé, a frequent flying record executive in Montreal, has discovered that his name was erroneously on the no-fly list.

After many attempts to have this corrected, Mr. Labbechanged his name to François Mario Labbé, which ended his monthly harassment.

I’m not sure what concerns me more, that one can be put on the no-fly list with no recourse, or that you can fix it by tweaking your name.

So, I guess Osama bin Laden could fly around the United States as LeRoy Ricks, Professional Elvis Impersonator.*

*3 Shows a day in Vegas……Think about it. It’s the last place that anyone would look for bin Laden.

Homeland Security Suspends Trusted Traveler Program

Verified Identity Pass, Inc., which operates the “Clear” program lost 33,000 customers’ records when an unencrypted laptop was stolen.

While it was recovered a week later, what happened to the data is unclear.

Among the data was:

  • Names
  • Addresses
  • Birth dates
  • Driver’s license, passport and green card data

Which one could describe as an “identity theft kit” for 33,000 people, and since the program also collects the following:

  • Credit card information
  • Digital photo
  • Digital images of all of the applicant’s fingerprints and his or her irises
  • Previous home addresses for the past five years
  • Digital images of passports and driver’s licenses.

It could have been much worse.

Security expert Bruce Schneier analyzes this sort of “trusted traveler” program, and finds it wanting from a security standpoint:

I think of Clear as a $100 service that tells terrorists if the F.B.I. is on to them or not. Why in the world would we provide terrorists with this ability?

Congress Attempting to Regulate Satellite Launches Without US Content

The House 2009 Defense Authorization Bill has a section that allows for punitive actions to be taken against “a foreign-owned company that is engaged with the People’s Republic of China in the development, manufacture or launch of certain satellites” (Paid Subscription Required).

This is about Thales Alenia Space, which has communications satellites that use no US content, and they are cleaning up by using the dirt cheap Chinese Long March boosters to launch satellites that have no ITAR (International Traffic in Arms Regulations) components.

It appears that something got Duncan Hunter’s (R-CA) nose out of joint about this, but given the restrictions on what are commercial technology present in the ITAR regulations, it was inevitable that this would happen.

I wonder if the WTO will end up getting involved in this.

Corruption Among Border Patrol on Rise

This is not a surprise. As enforcement efforts increase, smugglers will naturally turn to corrupting enforcement officers as a way to do business.

Note that this isn’t all just that though:

When the Homeland Security Department was created in 2003, the internal affairs unit was dissolved and its functions spread among other agencies. Since the unit was reborn last year, it has grown from five investigators to a projected 200 by the end of the year.

Once again Bush and His Evil Minions manage to completely f^%$ up the execution.

Note that the best way to reduce corruption is to make sure that the border guards are well paid and have good working conditions. Underpaid and abused employees are more receptive to graft.