Showing posts with label Crackers. Show all posts
Showing posts with label Crackers. Show all posts

Friday, November 11, 2011

Sci-Fi-Style Sabotage A Fear In New Hacks




By Jordan Robertson,
AP Technology Writer
October 23, 2011
Courtesy Of "The Boston Globe"


When a computer attack hobbled Iran’s unfinished nuclear power plant last year, it was assumed to be a military-grade strike, the handiwork of elite hacking professionals with nation-state backing.
Yet for all its science fiction sophistication, key elements have now been replicated in laboratory settings by security experts with little time, money or specialized skill. It is an alarming development that shows how technical advances are eroding the barrier that has long prevented computer assaults from leaping from the digital to the physical world.
The techniques demonstrated in recent months highlight the danger to operators of power plants, water systems and other critical infrastructure around the world.
“Things that sounded extremely unlikely a few years ago are now coming along,’’ said Scott Borg, director of the U.S. Cyber Consequences Unit, a nonprofit group that helps the U.S. government prepare for future attacks.
While the experiments have been performed in laboratory settings, and the findings presented at security conferences or in technical papers, the danger of another real-world attack such as the one on Iran is profound.
The team behind the so-called Stuxnet worm that was used to attack the Iranian nuclear facility may still be active. New malicious software with some of Stuxnet’s original code and behavior has surfaced, suggesting ongoing reconnaissance against industrial control systems.
And attacks on critical infrastructure are increasing. The Idaho National Laboratory, home to secretive defense labs intended to protect the nation’s power grids, water systems and other critical infrastructure, has responded to triple the number of computer attacks from clients this year over last, the U.S. Department of Homeland Security has revealed.
For years, ill-intentioned hackers have dreamed of plaguing the world’s infrastructure with a brand of sabotage reserved for Hollywood. They’ve mused about wreaking havoc in industrial settings by burning out power plants, bursting oil and gas pipelines, or stalling manufacturing plants.
But a key roadblock has prevented them from causing widespread destruction: they’ve lacked a way to take remote control of the electronic “controller’’ boxes that serve as the nerve centers for heavy machinery.
The attack on Iran changed all that. Now, security experts — and presumably, malicious hackers — are racing to find weaknesses. They’ve found a slew of vulnerabilities.
Think of the new findings as the hacking equivalent of Moore’s Law, the famous rule about computing power that it roughly doubles every couple of years. Just as better computer chips have accelerated the spread of PCs and consumer electronics over the past 40 years, new hacking techniques are making all kinds of critical infrastructure — even prisons — more vulnerable to attacks.
One thing all of the findings have in common is that mitigating the threat requires organizations to bridge a cultural divide that exists in many facilities. Among other things, separate teams responsible for computer and physical security need to start talking to each other and coordinate efforts.
Many of the threats at these facilities involve electronic equipment known as controllers. These devices take computer commands and send instructions to physical machinery, such as regulating how fast a conveyor belt moves.
They function as bridges between the computer and physical worlds. Computer hackers can exploit them to take over physical infrastructure. Stuxnet, for example, was designed to damage centrifuges in the nuclear plant being built in Iran by affecting how fast the controllers instructed the centrifuges to spin. Iran has blamed the U.S. and Israel for trying to sabotage what it says is a peaceful program.
Security researcher Dillon Beresford said it took him just two months and $20,000 in equipment to find more than a dozen vulnerabilities in the same type of electronic controllers used in Iran. The vulnerabilities, which included weak password protections, allowed him to take remote control of the devices and reprogram them.
“What all this is saying is you don’t have to be a nation-state to do this stuff. That’s very scary,’’ said Joe Weiss, an industrial control system expert. “There’s a perception barrier, and I think Dillon crashed that barrier.’’
One of the biggest makers of industrial controllers is Siemens AG, which made the controllers in question. The company said it has alerted customers, fixed some of the problems and is working closely with CERT, the cybersecurity arm of the U.S. Department of Homeland Security.
Siemens said the issue largely affects older models of controllers. Even with those, the company said, a hacker would have to bypass passwords and other security measures that operators should have in place. Siemens said it knows of no actual break-ins using the techniques identified by Beresford, who works in Austin, Texas, for NSS Labs Inc.,
Yet because the devices are designed to last for decades, replacing or updating them isn’t always easy. And the more research that comes out, the more likely attacks become.
One of the foremost Stuxnet experts, Ralph Langner, a security consultant in Hamburg, Germany, has come up with what he calls a “time bomb’’ of just four lines of programming code. He called it the most basic copycat attack that a Stuxnet-inspired prankster, criminal or terrorist could come up with.
“As low-level as these results may be, they will spread through the hacker community and will attract others who continue digging,’’ Langer said in an email.
The threat isn’t limited to power plants. Even prisons and jails are vulnerable.
Another research team, based in Virginia, was allowed to inspect a correctional facility — it won’t say which one — and found vulnerabilities that would allow it to open and close the facility’s doors, suppress alarms and tamper with video surveillance feeds.
During a tour of the facility, the researchers noticed controllers like the ones in Iran. They used knowledge of the facility’s network and that controller to demonstrate weaknesses.
They said it was crucial to isolate critical control systems from the Internet to prevent such attacks.
“People need to deem what’s critical infrastructure in their facilities and who might come in contact with those,’’ Teague Newman, one of the three behind the research.
Another example involves a Southern California power company that wanted to test the controllers used throughout its substations. It hired Mocana Corp., a San Francisco-based security firm, to do the evaluation.
Kurt Stammberger, a vice president at Mocana, told The Associated Press that his firm found multiple vulnerabilities that would allow a hacker to control any piece of equipment connected to the controllers.
“We’ve never looked at a device like this before, and we were able to find this in the first day,’’ Stammberger said. “These were big, major problems, and problems frankly that have been known about for at least a year and a half, but the utility had no clue.’’
He wouldn’t name the utility or the device maker. But he said it wasn’t a Siemens device, which points to an industrywide problem, not one limited to a single manufacturer.
Mocana is working with the device maker on a fix, Stammberger said. His firm presented its findings at the ICS Cyber Security Conference in September.
Even if a manufacturer fixes the problem in new devices, there’s no easy way to fix it in older units, short of installing new equipment. Industrial facilities are loath to do that because of the costs of even temporarily shutting its operations.
“The situation is not at all as bad as it was five to six years ago, but there’s much that remains to be done,’’ said Ulf Lindqvist, an expert on industrial control systems with SRI International. “We need to be as innovative and organized on the good-guy side as the bad guys can be.’’
MORE LIKE THIS »

Saturday, July 25, 2009

The Book On Information Warfare


By William S. Lind
Posted on: July 21st, 2009

Courtesy Of
The American Conservative Magazine

Ideas as Weapons is the title of a new book, a collection of essays edited by two Marine Corps officers, G.J. David Jr. and T.R. McKeldin (the publisher is Potomac Books). Subtitled “Influence and Perception in Modern Warfare,” the volume is dedicated to exploring the aspect of war most neglected by the Second Generation American military, ideas. The U.S. armed forces have never grasped the centrality of John Boyd’s dictum that for winning wars, people are most important, ideas come second and hardware is only third.

Mostly, the U.S. military reduces ideas to “Information Operations,” or IO, in which some junior officers and NCOs churn out leaflets, films etc. of indifferent quality. The idea, central to Fourth Generation war, that Information Operations are what you do, not what you say, is missed entirely. The results of typical IO range from minimal to hilarious. The book recalls one incident during the siege of Fallujah where Marines made and broadcast a film intended to show American troops feeding Iraqi refugees halal rations. It actually showed them feeding Arabs kosher rations, which did not play too well locally.

As with all collections, chapters vary in quality. They are organized in four parts, Geopolitical, Strategic, Operational (it’s nice to see Marines using that word correctly form once) and Tactical. In my view, the best chapter in the Geopolitical section is Ambassador David Passage’s “Reflections on Psychological Operations: The Imperative of Engaging a Conflicted Population.” He argues that “It has long been axiomatic in guerrilla warfare that a defending force (such as a government the United States is associated with) will find itself confronted with almost insuperable odds unless it can enlist the active – not passive – support of its own citizens in countering an insurgency.” Contrasting America’s failure in Vietnam with success in El Salvador, Ambassador Passage suggests the usual psyops messages are ineffective:

The modern age has reached the point where, given the babble of conflicting, contradicting, and combative messages, populations are decreasingly likely to simply accept what they are told. In the welter of competing messages and mediums, government-sponsored messages are at a particular disadvantage…

A better approach might be to ask questions rather that provide answers…

The fundamental message to the people of Iraq and Afghanistan and other countries in conflict needs to be, as the U.S. message was in El Salvador twenty years ago, “This is your country; the kind of country it’s going to be is up to you – not to the United States or any foreign country. What kind of country do you want it to be? Are you willing to help restore order, and law, and civility – or are you going to sit quietly while those who seek to destroy what you have do their work?”

A strong chapter in the Strategic section is Colonel William M. Darley USA’s “Clausewitz’s Theory of War and Information Operations.” Darley argues that “Contrary to entrenched perceptions, IO is not merely a family of related skill sets or capabilities that in all cases augment “kinetic operation.” Collectively, they are properly understood as a specific purpose and emphasis within an overall plan of action that under some circumstances might be the main effort.” I would add that in 4GW, they are usually the main effort.

Darley offers a Clausewitzian definition of IO, far broader than the current American technical definition. It reflects Clausewitz’s discussion of the power of “moral” factors in what is essentially a political contest. His chapter concludes with a quotation from Clausewitz that strikes to the heart of ongoing American failures in 4GW:

Political considerations do not determine the posting of guards or the employment of patrols. But they are the more influential in the planning of war, of the campaign, and often even of the battle…The only question, therefore, is whether, when war is being planned the political point of view should give way to the purely military…or should the political point of view remain dominant and the military (military force and violence) be subordinated to it?

The book’s Operational segment includes a devastating critique of the U.S. military’s whole intelligence system, “Clouding the Issue: Intelligence Collection, Analysis, and Dissemination during Operation Iraqi Freedom,” by Army Lt. Col. George J. Stroumpos. Too lengthy to summarize here, it proceeds from the statement that

Our intelligence apparatus has been our Achilles’ heel… the Coalition intelligence apparatus is a hodgepodge pick-up team, conflicting in its organization and lost in a sea of data. This, coupled with the sheer volume and complexity of the environment, is the primary problem…is poor information management and the resulting syntheses that follow from poor technique.

Ideas as Weapons’Tactical segment, which junior-level practitioners will find of particular value, includes a superb chapter, “Tactical Information Operations in West Rashid: An Iraqi National Police Battalion and Its Assigned U.S. Transition Team,” by Major E. Lawson Quinn, USMC. This chapter gets at one of the central fallacies of the whole American effort in Iraq (and elsewhere), namely that what local government forces need is American training in techniques. In reality, cultural factors are far more important than technical skills (Saddam’s forces, after all, were technically quite capable of maintaining order in Iraq without American training). Major Quinn gets at the central problem when he writes:

The Sunni population in West Rashid unquestionably viewed 2/7/2 (an Iraqi National Police battalion) as a sectarian organization that served the interests of the Shi’a majority at the expense of the Sunnis, if not an instrument of or in collusion with the Shi’a militias. The very demographic makeup of 2/7/2, less than ten Sunnis among the four hundred or so Shi’a members of the battalion, precluded overcoming that sectarian perception even if the Shi’a majority and leadership wanted to do so, but their actions clearly did not evince the slightest proclivity toward it.

In fact, it was quite clear that at least the battalion leadership understood the value of information operations in reinforcing that perception. Even the casual Western observer…would have understood the message trumpeted by the large Shi’a flag posted at the front of the compound high atop the tallest building.

Ideas as Weaponsis a book that should be high on the reading list of every American commander in Iraq and Afghanistan, from the theater level down through company. I stress commanders, not just intelligence officers, because IO properly defined are at the heart of Fourth Generation war. Until American commanders at all levels understand that fact, we will continue to rocket and bomb our way to defeat.

Friday, July 17, 2009

"Rogue Hacker" and Black Ops


Behind The CyberAttacks On America and South Korea

By Tom Burghardt
Source:
Antifascist Calling...
July 12, 2009

Courtesy Of
Global Research

The iconic American investigative journalist I.F. Stone once said, "All governments are run by liars and nothing they say should be believed." Stone's credo is all the more relevant today when it comes to the pronouncements of intelligence agencies and their corporate masters, particularly where official enemies are concerned.

A widespread computer attack that began July 4 took down several U.S. Government, South Korean and financial web sites, the Associated Press reported.

Multiple media reports claim that the Treasury Department, the Department of Homeland Security (DHS), Secret Service, Federal Trade Commission and Department of Transportation web sites were struck by a distributed denial of service (DDOS) assault that began last Saturday.

According to Computerworld, "a botnet comprised of about 50,000 infected computers has been waging a war against U.S. government Web sites and causing headaches for businesses in the U.S. and South Korea." The magazine reported July 7, "on Saturday and Sunday the attack was consuming 20 to 40 gigabytes of bandwidth per second, about 10 times the rate of a typical DDoS attack, one security expert said after being briefed by the US-CERT on Tuesday. 'It's the biggest I've seen'."

This is particularly embarrassing to the DHS since the agency's U.S. Computer Emergency Readiness Team (U.S.-CERT) is responsible for preventing illegal hacking forays on government networks.

Attacks were also reported on the White House, the Department of Defense, the State Department, The Washington Post, U.S. Bancorp, the New York Stock Exchange and Nasdaq. Affected sites in South Korea included those of the presidential Blue House, the Ministry of Defense, the National Assembly, Shinhan Bank, the newspaper Chosun Ilbo. South Korea's top Internet Service Provider, Naver.com crashed on Tuesday, according to the Associated Press.

Despite the unsophisticated nature of the cyber incursion that employed a variant of the MyDoom virus, unnamed "senior U.S. officials" told The Wall Street Journal that American and South Korean officials are "probing North Korea's possible role." The same anonymous sources said that the botnet attack "coincided with North Korea's latest missile launches and followed a United Nations decision to impose new sanctions."

That the cyber assault also "coincided" with a holiday fireworks accident that killed 5 workers in North Carolina, multiple deaths due to drunk driving on U.S. highways or an Italian railway disaster that claimed 21 lives, is hardly "evidence" of Pyongyang's shadowy hand.

Nevertheless, South Korea's National Intelligence Service (NIS), the successor organization to the Korean Central Intelligence Agency (KCIA), was quick to blame the troglodytic Stalinist regime for the blitz. However, the opposition Democratic Party "accused the spy agency of spreading unsubstantiated rumors to whip up support for a new anti-terrorism bill that would give it more power."

In a media statement NIS said: "This is not a simple attack by an individual hacker, but appears to be thoroughly planned and executed by a specific organization or on a state level."

But given the nature of the event, not all cybersecurity specialists are convinced of a North Korean provenance. Amit Yoran, the former director of DHS' National Cybersecurity Division told Federal Computer Week: "I think at this point it is highly unlikely, highly improbable that any reliable attack-attribution data is available. It's a very intense process and it could take weeks. ... The analysis here--both technical and nontechnical--is not trivial and takes time."

In other words, NIS pronouncements should be taken with the proverbial grain of salt. After all, this is an agency with a repressive pedigree and its own dodgy agenda. "Trained-up fierce" by the CIA and the Pentagon, the South Korean intelligence service has been involved in some of the worst human rights abuses in East Asia.

According to a series of reports by investigative journalist Tim Shorrock, the agency was involved in the mass murder of their own citizens. In 1980, the Army's feared "Black Beret" Special Forces and the KCIA were given a "green light" by Washington to suppress a pro-democracy uprising in the southern city of Kwangju in which some 2,000 students and workers were massacred; hundreds more were "disappeared," tortured and imprisoned.

And with hostilities between Washington, Seoul and Pyongyang steadily on the rise, one cannot rule out the possibility that the cyberattacks are an exploitable entré by enterprising security agencies for further escalating the current crisis. Recent U.S. history is replete with examples of "intelligence and facts ... being fixed around the policy."

Fitting North Korea into the Frame

While the cyberassault "seemed to have come from South Korea," The Wall Street Journal reports that American and South Korean officials are "trying to assess whether this is some random attack or the North Koreans might be working through a proxy, said the official."

Just as likely however, someone or some entity may be trying to fit the repressive Stalinist regime into the frame.

Maneuvering to transform the thin gruel of fact into a meatier stew, Rodger Baker, the director of East Asian analysis at Stratfor, a private think-tank that describes itself as "the world leader in global intelligence" told Reuters the "timing of the cyber attacks raised suspicions about North Korea because it was around the U.S. Independence Day holiday and Pyongyang conducting missile tests."

Another "expert," Nicholas Eberstadt, a senior researcher at the rightist American Enterprise Institute (AEI), linked the cyber blitz to a recent flurry of missile tests as well as to North Korea's recent test of a nuclear device. He told Asia Times: "The general purpose was clear. When one looks at the nuclear chessboard, their security is integrally tied to cyber-warfare. ... This strategy fits in integrally with tests of atomic devices."

Eberstadt's proof? He has none, but handily furnishes us with a speculative worst-case scenario that has the North launching a massive artillery and missile attack on major U.S. bases "in tandem with a full-scale cyber-offensive." In other words, Eberstadt has conjured up a digital bogeyman to scare the kiddies.

Such pronouncements are all the more remarkable given the decrepit state of the North's technological infrastructure. Computerworld reported July 10, there "are just over a million telephone lines installed in the country of 26 million people, home PCs are rare and Internet access is heavily restricted."

While the country has made IT expertise a priority, the publication averred that "North Korea's sophistication in hacking makes it less likely to be behind the attacks."

Despite something as trivial as evidence, Rep. Peter Hoekstra (R-MI), ranking Republican on the House Intelligence Committee, urged President Obama to launch a cyber attack against North Korea.

Hoekstra told the right-wing America's Morning News radio show on Friday, "some of the best people in America" had been investigating the attacks and have concluded that "all the fingers" point to North Korea as the culprit.

That Hoekstra's comments were showcased by the radio mouthpiece of The Washington Times, speak volumes to the agenda being pushed here.

The far-right news outlet is a wholly-owned subsidiary of clerical-fascist, the Rev. Sun Myung Moon and his Unification Church empire. With long-standing ties to Japanese and Korean fascists and war criminals, including reputed yakuza capo tutti capos Ryoichi Sasakawa and Yoshio Kodama, "Moon's Korea-based church got its first boost as an international organization when Kim Jong-Pil, the founder of the Korean Central Intelligence Agency, brokered a relationship between Moon and ... Japan's leading rightist financiers," according to a definitive series of reports by investigative journalist Robert Parry.

Added Hoekstra, North Korea should be "sent a strong message."

"Whether it is a counterattack on cyber, whether it is, you know, more international sanctions ... but it is time for America and South Korea, Japan and others to stand up to North Korea or the next time ... they will go in and shut down a banking system or they will manipulate financial data or they will manipulate the electrical grid, either here or in South Korea," Hoekstra said. "Or they will try to, and they may miscalculate, and people could be killed."

Hoekstra's provocative statements echo remarks offered up by STRATCOM commander General Kevin Chilton. In May, Chilton suggested that "the White House retains the option to respond with physical force--potentially even using nuclear weapons--if a foreign entity conducts a disabling cyber attack against U.S. computer networks," according to a disturbing report published by Global Security Newswire.

And with a vested interest in blaming their historic enemy for the cyberstrike, enterprising defense and security grifters on the southern side of the 38th parallel--and in Washington--have been hyping reports that the Stalinist regime is building a "cyber division" within the North Korean army.

Indeed, Bloomberg News reported that "South Korea's Defense Ministry plans to spend 489 billion won ($382 million) next year to beef up its defense against cyber warfare, the ministry said in a budget report today."

Who might benefit from such a large expenditure of public funds? Why private U.S. defense and security corporations of course!

Amongst the largest U.S. firms doing business with the South Korean Ministry of Defense, one finds the usual suspects. These include Boeing, Lockheed Martin, Northrop Grumman, General Dynamics, L3 Communications and Booz Allen Hamilton to name but a few of the dozens of corporations with a stake in the South Korean military bazaar. That all of the above-named entities are heavily-leveraged in the emerging cybersecurity market is hardly a coincidence.

The Korean Herald reported in its July 10 edition that "some experts here [are] now fingering hackers in the United States" as the culprits. Hong Min-pyo, the CEO of the security software firm Shiftworks who forensically examined the virus, "raised the possibility of the distributed denial of service attacks originating from a locale in the United States, which also was hit by the attacks."

Unlike corporate media here in the heimat, the Herald referenced critics who warned "against politicizing the latest cyber infections," including opposition Democratic Party lawmakers who "protested the passing of the anti-cyber terrorism bill citing invasion of privacy and internet censorship." The opposition demanded the government "offer concrete evidence to prove that North Korea was involved in the latest attacks."

But given the right-wing political offense currently underway in Seoul and Washington, opposition lawmakers may have a very long wait.

A Sociopath with a Keyboard and a Grudge ... or Something More Sinister?

The unsophisticated nature of the attack should have alerted the media that any number of bad actors, particularly cybercriminals who specialize in transforming computers into zombie machines, or botnets, for their own nefarious purposes were prime suspects.

Computerworld reported July 8, that "an updated version of the MyDoom virus is responsible for a large DDOS (distributed denial of service) attack that took down major U.S. Web sites over the weekend and South Korean Web sites on Wednesday, according to Korean computer security company AhnLab."

Since its 2004 appearance, MyDoom has become "the fasted-spreading e-mail worm in Internet history." When a PC is infected with MyDoom, malicious code enables the program to harvest email addresses and mail itself out endlessly, the publication reports. According to AhnLab, the latest version contains an additional file with a list of web sites to be attacked.

Computerworld reported July 9, that infected systems also contain a destructive Trojan "programmed to encrypt user data or reformat the hard drive of a PC," thus erasing the evidence.

Joe Stewart, a researcher with SecureWorks who examined the code, told Computerworld that the botnet "does not use typical antivirus evasion techniques and does not appear to have been written by a professional malware writer."

Stewart told the publication that it is unusual to see low-profile state web sites being hit. "Who goes around targeting a site like the FAA or the U.S. Treasury? It's not something that most people would think to attack."

When contacted Friday for an update, Stewart told Computerworld there is "still zero evidence of North Korean involvement." Though relatively lengthy in duration, Stewart believes the attack could have been launched by a single person.

Who then might attack "low-profile web sites" such as the Federal Trade Commission for example?

According to Wired, the FTC shut down an Internet Service Provider for its illegal and highly-lucrative hosting practices.

Identified as a "Black Hat" firm variously known as "Pricewert," "3fn.net" and "APS Telecom" the company was accused by the FTC June 3 of "actively recruiting" to its hosting service "thousands of 'rogue' web sites distributing 'illegal, malicious, and harmful electronic content including child pornography, spyware, viruses, trojan horses, phishing, botnet command and control servers, and pornography featuring violence, bestiality, and incest'."

Wired reported that the company "had thousands of servers" in the San Jose, Calif. area and the firm "actively shields its criminal clientele by either ignoring take-down requests issued by the online security community or shifting its criminal clients to other internet protocol addresses controlled by Pricewert so that they may evade detection."

The Washington Post reported June 3, that "Botnet experts ... have found that 3FN housed many of the command and control networks for 'Cutwail,' one of the world's largest spam botnets. As late as mid-April, Joe Stewart, a botnet expert and director of malware research at SecureWorks, tracked nearly a dozen Cutwail control networks hosted at 3FN."

Which raises an uncomfortable question for security "experts" hyping North Korea's alleged "cybersecurity threat:" were the past week's attacks the work of a sociopath with a keyboard and a grudge, particularly if one of his/her botnets lost the critical command and control hubs that make spam, an illicit drugs market and Internet porn profitably sizzle?

While we may never know who actually launched the incursions, we just might have a slight inkling of who'll benefit. As Antifascist Calling reported July 6, plans are already afoot to roll-out Einstein 3, a Bush-era surveillance program to screen state computer traffic on private-sector networks.

In partnership with the Department of Homeland Security and the National Security Agency, communications, defense and security firms such as AT&T, General Dynamics, L3 Communications, MCI, Qwest, Sprint and Verizon stand to make billions from contracts under the government's Managed Trusted Internet Protocol Services (MTIPS) program with its built-in "Einstein domain."

How's that for timing!

Tom Burghardt is a researcher and activist based in the San Francisco Bay Area. In addition to publishing in Covert Action Quarterly and Global Research, his articles can be read on Dissident Voice, The Intelligence Daily, Pacific Free Press and the whistleblowing website Wikileaks. He is the editor of Police State America: U.S. Military "Civil Disturbance" Planning, distributed by AK Press.


Tom Burghardt is a frequent contributor to Global Research.

Global Research Articles by Tom Burghardt

Thursday, April 09, 2009

Cyber-Skirmish At The Top Of The World

By Peter Lee
April 8, 2009
Courtesy Of Aisa Times Online

For the past decade or more, China has been engaged in a game of whack-a-mole to control the burgeoning channels of digital communication between Tibetan dissidents inside Tibet and in the Tibetan diaspora. Despite Beijing's resolve to define the Tibetan issue as a solely internal matter for the People's Republic of China, Tibetan Internet issues have been quietly internationalized, thanks to the efforts of Western activists to provide cyber-security services for Tibetan dissidents and emigres.

In March 2008, Canadian investigators achieved a cyber-security triumph: the exposure of a malicious data-gathering botnet, a large number of compromised computers used to create and send spam or viruses, targeting the Tibetan international community. The botnet's exposure could almost - but not quite - be construed as a counter-intelligence operation against a hacker network apparently operating out of China.

Domestically, China routinely monitors and blocks websites, chat rooms and plain-text e-mail nationwide on a host of sensitive subjects, including Tibet, using thousands of real and virtual cybercops and its US$700 million Golden Shield infrastructure - derisively called "The Great Firewall of China" (GFW). It also employs the technical assistance of local service providers (including the in-China operations of multi-nationals like Yahoo!) to gather information on domestic dissidents.

Efforts in the sensitive Tibetan regions of China are more direct and draconian, especially in the context of heightened tensions following the unrest in March 2008.

Landline, cell and Internet services in Tibetan areas were interrupted during the period of unrest. When the Chinese government became aware that Tibetan dissidents were using the video-sharing website YouTube as a text-free method to communicate, it shut it down. When image-sharing website Flickr emerged as a potential source of visual information, it was blocked. Tibetan radio broadcasts by Voice of America (VOA), Radio Free Asia (RFA) and Voice of Tibet were jammed. A campaign against satellite dishes was intensified to limit the audience of VOA's direct-to-dish Tibet TV service. In order to cut off cell-phone based talk, text, and images, China reportedly limited service and tore down cell phone towers.

When confronting in cyberspace supporters of Tibetan dissidents located outside of China, the Chinese government is apparently abetted by a group of hackers, acting either pro bono or with government encouragement. The hackers disrupt websites, harass activists and, it transpires, organize extensive espionage operations against targeted computers around the world.

China's efforts against the Tibetan independence movement and Tibetan government-in-exile have been countered by a variety of overseas "hacktivists" - computer hackers with an activist bent. Some of these derive a measure of support, including some financial backing, from Western governments.

The hacktivist organization with the highest profile and level of capability and professionalism is probably Citizen Lab, run by Professor Ron Deibert in the University of Toronto's Munk Center for International Studies.

Citizen Lab was in the news recently when it midwived a report [1] by Information Warfare Monitor announcing the existence of a cyberspying operation targeting computers belonging to the Tibetan government-in-exile, Tibetan non-governmental organizations (NGOs), and a host of other governments and organizations around the world.

In 2008, at the request of the Office of the Dalai Lama, Citizen Lab checked the computers of the Tibetan government in exile offices in Dharmsala in India and in various European cities to determine if they were infected with malware.

Citizen Lab investigator Greg Walton collected reams of suspicious code. By plugging a likely bit into Google, he was able to locate the server that the malware was communicating with. He lured the server into establishing communication with a "honeypot" - a computer set up to document and trace cyber-intrusions - and finally penetrated it.

Walton discovered three other servers supporting the malware, and obtained a list of almost 1,300 computers - many located in the offices of emigre Tibetan government and NGOs around the world, but also in numerous Taiwanese, European and Asian governmental offices - from which they were collecting information.
The operation, which the investigators named "GhostNet", used a Trojan hidden in e-mail attachments to compromise a computer's security and download a piece of malware called gh0st RAT (RAT standing for Remote Access Tool). Gh0st RAT allowed a remote operator both to examine files on the computer and to upload them to a gh0st RAT server. Keystrokes could also be logged - a key hacking tool for acquiring passwords - and, purportedly, the computer's microphones and webcam could be activated and the audio and video sent to the gh0st RAT server.

This was not Citizen Lab's first foray into the world of China-related cyber-security. In fact, Citizen Lab finds itself at the center of many issues pertaining to China, Tibet and the Internet.

In October 2008, Citizen Lab issued a report revealing that TOM-Skype, a joint venture by Skype and an arm of Hong Kong tycoon Li Ka-shing's empire offering encrypted voice and text messaging services inside of China, saved copies of text messages on a network of eight servers.

This was a big deal for three reasons.

First, though TOM-Skype admitted that Chinese-mandated filtering software would knock out messages with forbidden keywords, it had previously claimed that the filtered messages were discarded. Not true. The filtered messages were stored on the eight servers.

Secondly, TOM-Skype is supposed to be a private, encrypted service with encryption keys that were the secret property of the service's users. Nevertheless, it was revealed that, presumably at the behest of the Chinese government, TOM-Skype saved both the traffic and the keys needed to decrypt it.

Third, the servers were also apparently storing traffic that did not contain banned keywords - an indication that the Chinese government was selecting individuals and accounts to monitor, and dumping all their traffic on the servers for examination.

The TOM-Skype affair highlights the central role played in the battle between the Chinese state and those who wish to navigate the Internet beyond its control by a unique technical feature of Internet communication: 128-bit encryption.

In the 1990s, Phil Zimmerman, an American political activist, developed an unbreakable open source 128-bit encryption program employing private and public keys that he called, tongue-in-cheek, "Pretty Good Privacy" or PGP. The US government, realizing that propagation of PGP would put an end to the era in which the National Security Agency (NSA) possessed the technical means to monitor every form of electronic communication from telegrams and faxes to computer traffic, bitterly fought Zimmerman's efforts to publicize the code.

The government placed 128-bit encryption on a list of munitions proscribed for export. Zimmerman countered by printing the PGP source code in book form and claimed his right to protection under the First Amendment of the US constitution. In 1996, realizing that mathematicians and programmers overseas were capable of developing equivalent programs, the US government dropped its investigation of Zimmerman and permitted the export of PGP.

Probably, if the Federal Bureau of Investigation and NSA had succeeded in their efforts to keep the 128-bit genie in the bottle until September 11, 2001, changing the security vs freedom equation, we would be living in a world where every government demanded a copy of everybody's encryption key.

As it is, today the open, distributed international architecture of the Internet demands encryption in order to protect both the sensitive data that travels along it and the network itself. All efforts to impose - and evade - monitoring and control of digital information take place in the shadow of 128-bit encryption.

Governments around the world, "free" as well as totalitarian, have responded with a variety of strategies to ensure that encrypted communications yield up their secrets.

Rights of privacy are extremely limited, if not non-existent, when it comes to encryption. Companies and individuals are expected to produce keys at government demand in response to informal requests, pointed demands, subpoenas, or something called "rubber hose cryptoanalysis", a euphemism for the extraction of cryptographic secrets (eg the password to an encrypted file) from a person by coercion.

Governments, especially the United States, are rumored to routinely seed computers, software and even mathematical elements of the decryption algorithm itself with backdoors that enable the surreptitious acquisition of passwords and the precious keys.

Commercial providers of encrypted e-mail worldwide are apparently eager to cooperate with the government and avoid being identified as a provider of genuinely secure communications to terrorists, criminals and any other suspect entity.

In the course of a criminal investigation of steroid smuggling, one provider, Hushmail, revealed [2] that it was able to turn over decrypted traffic to the Canadian government because it had a Java applet that could penetrate its customers' computers to extract the supposedly sacrosanct private key.

And if a key really can't be provided, but plain and encrypted versions of the same message are available and can be attacked with adequate time, skill and resources, the underlying code may be broken.

China has made the somewhat counterintuitive but perhaps inevitable decision to join the family of nations that tolerates but controls encrypted communication - and engages in the never-ending, no-holds-barred struggle to track and crack it.

China, after all, is anxious to reap the economic rewards of being at the forefront of the digital networking revolution. Since China is already near the forefront of the hacking, cracking, phishing (the use of a fake websites or e-mails to obtain to gather confidential data), and cybercrime revolution, it must also accept the need of businesses and individuals to encrypt sensitive data.

China, like governments around the world, insists that businesses offering encrypted communications within their borders provide the means to generate decrypted traffic at the demand of law enforcement.

As the TOM-Skype case shows, any commercial participant in encrypted communication activities will be expected to provide a backdoor and/or a helping hand to Chinese security organizations.
The attention of dissidents - and the security personnel who track them - must turn elsewhere for more private communications.

Secure, non-commercial e-mail encryption is still available to those who have the ability and desire to forego the commercial services and are willing and able to engage in the rather laborious process of maintaining their own collection of encryption keys and coding and decoding their traffic without relying on the web-based public key servers.

However, encryption does not encode the e-mail header, which exposes information on the sender and receiver, thereby providing security forces with a point of entry to generate a social-web map of senders and recipients that is, in itself, a source of dangerous intelligence. Furthermore, the very act of sending and receiving encrypted e-mail possibly attracts unwelcome scrutiny, both in China and around the world,

Beyond e-mail encryption, there are other options for those inside China desiring untrammeled access to the global Internet. They involve exploiting https - the encrypted hypertext transfer protocol designed for secure financial transactions - to establish contact with computers outside China that can be used as proxies.

Detailed online manuals provide instructions to Tibetan dissidents, Falungong adherents, and anybody else hoping to evade the prying eyes of the Chinese security forces and safely surf the web, communicate or blog internationally.

The most widely-used facilities are Dynaweb, Garden and Ultra Surf. These services coordinate their offerings through the Global Internet Freedom Consortium (GIFC), a group that receives some US government funding and is apparently run by friends of Falungong, the outlawed and extremely tech-savvy Chinese religious group-cum-political movement.

The three services gleefully run a never-ending Spy vs Spy war with the Chinese cybercops, continually flooding the zone with new Internet Protocol (IP) addresses - a computer's identification number on a network - that their users (and the Chinese security organizations that inevitably participate in the service) link to with a "tunnel discovery agent" in order to connect to proxy servers - a computer system or application program that acts as a go-between - before the Chinese government shuts them down.

They count VOA and RFA as their clients and proudly state that the service has never been interrupted.

But, in the case of gh0st RAT, maybe score this round to China. In its own analysis of the computer security travails of the Tibetan emigre community, "Snooping Dragon", the University of Cambridge reported [3] that the China hackers availed themselves of Dynaweb's facilities:
However, after a while, we saw a number of accesses through Dynaweb - a set of anonymization proxy servers associated with the Falungong religious movement, which is also detested by the government of China. We are at a loss how to explain this. Perhaps the Chinese detected the start of our clean-up operation and decided to hint that they had compromised Dynaweb - whether to deter people from using it, or to deter the US government from funding it? We just have no idea.
As a public service that aggressively markets its product in a strategy to overwhelm China's security apparatus, the GIFC's partners are vulnerable in turn to the most diabolical weapon in China's arsenal - porn.

Porn is the bugbear of censorship circumvention service providers.
Ironically, it has pushed the service providers themselves to assume the role of censors. In a white paper [4] entitled Defeat Internet Censorship, The GIFC interrupted its triumphalist recitation of its omnipotent software capabilities to note:
With limited resource and bandwidth, an anti-censorship system with unrestricted access will soon be consumed by pornography, gambling and drug-related information and become useless to users in the most-needed regions. Therefore, it is critical and beneficial for an anti-censorship system to have some built-in mechanisms to control content access. At least, it should have the ability to block some high-profile pornography portals in order to save the bandwidth for better uses. It should also provide tools for law enforcing authorities in the free world to monitor the information flow when needed to avoid the encryption channels being exploited for terrorist communications.
In a demonstration that irony is, if not dead, on hiatus at GIFC, the writers of the white paper also proposed that, once China's surfers emerge from the Great Firewall rabbit hole, they be directed toward more wholesome browsing courtesy of GIFC in its role as portal manager and content provider:
To better protect and serve users who have overcome the blocking and reached the other side of [the] GFW, it is highly beneficial to provide them with an uncensored, trustworthy portal site in their own native languages, which provides services such as search engines, directories, bulletin boards, e-mails and chat rooms. These services are better protected when they are tightly integrated with the anti-censorship tools they use. More importantly, such a portal site can shield users from those overseas websites set up by the Chinese regime or communist regime-backed entities. Their websites serve as a trap to collect users' information as well as serve their exported propaganda machinery.
But legitimate porn-surfing by frustrated citizens, dedicated freedom activists and fanatical cultists to whom GIFC caters is probably just the tip of the iceberg.

Beneath the high-minded concern for the morals, safety and education of Chinese web surfers is perhaps the concern that the service could not survive a concerted attack by malicious Chinese government users logging on simultaneously to download a lifetime's supply of porn and bootlegged Jackie Chan movies - and the GIFC might need a Great Firewall of its own to protect itself.

An alternative to a high-profile, high-intensity professional circumvention service under continual attack by the Chinese government is an "anonymizer" program called TOR (The Onion Router).

TOR performs a multiple-layer encryption of requests for web pages and relies on a network of computers supplied by volunteers to strip the address layers (like an onion) until the last server - the TOR exit node - connects to the destination using its own IP address. Each computer only knows the previous link; if the message is intercepted, it cannot be traced back to the originator.

Traffic analysis can reportedly compromise the anonymity of the TOR network, but its true vulnerability is highlighted by a post from the UK entitled "Why You Need Balls of Steel to Operate a TOR Exit Node" [5]:
[After providing service as a TOR exit node for about one year] I was visited by the police in November 2008 because my IP address had turned up in the server logs of a site offering, or perhaps trading in (I was not told the details of the offence) indecent images of children … It was what is known as a "dawn raid" and, amazingly enough, my children were still asleep when it occurred. Thank God … I was overwhelmed by horror to be implicated in such a thing. I was desperately worried about my family. One of the officers had told my wife that Social Services would be informed as a matter of course and there was a possibility that my children would be taken into care …
After an agonizing four-month investigation, the police dropped the case. But the writer concludes: "I think, in retrospect, I was desperately naive to run a TOR exit server on a home computer."

So, it doesn't take much to degrade the TOR system. Just a collection of malicious hackers going on the system masquerading as legitimate users, hogging bandwidth, downloading child porn, or visiting sites flagged by the police as terrorist/criminal-related. If a genuine cyberwar erupts, one would expect that the TOR network will grind to a halt in a matter of minutes.

The latest iteration in the struggle between the Chinese government and dissidents over Internet communication is brought to us by none other than Citizen Lab.

In 2007, Citizen Lab developed and spun off a "censorship circumvention software" it called Psiphon, which establishes an encrypted link from inside a country that limits Internet browsing to a computer in another country that allows free browsing.

Citizen Lab's Ron Deibert undoubtedly did not endear himself to the Chinese government by publicizing the Psiphon service in the aftermath of the unrest in Tibet last year as a way for activists inside China to get the word out to the West. Psiphon also advertised its commercial service to foreigners as a safeguard against Chinese cybersnooping during the 2008 Beijing Summer Olympic Games; apparently the BBC and the US State Department signed up for the service as a way to secure their communications from Beijing.

Psiphon uses the "small is beautiful" strategy, but avoids the problems of TOR by eschewing the "anonymizer" route. Instead, the network's integrity is protected because the owners of the computers in the free-browsing countries - called "psiphonodes" in the company jargon - only invite users of the service, "psiphonsites", that they personally know and trust.

The owners provide a distinct URL or web address (generated by Psiphon) pointing to their computer, and a unique password for each user, that enables the user to connect to the page using the https protocol; once logged in the owner's computer, the user can surf to his or her heart's content.

Well over 150,000 owners have signed up to become Psiphonodes. It is unclear how many users link to these nodes.

User traffic can be monitored by the psiphonodes and apparently some of the operators have been knocked out of their Birkenstocks by the insatiable demand for porn of some of their trusted users - and the legal risk that serving as the connecting node to the offending site exposes them.

Psiphon, as a diffuse set of mini-networks each closely controlled by its own node, is proof against a massive, malicious use attack that threatens the GIFC and TOR services.

Its vulnerability seems to exist not in the world of cyberspace, but in the realm of the system's human users and operators.

A Psiphon system can apparently be compromised if the node or site computer is penetrated through operator carelessness in response to something called "social engineering": the deployment of phishing e-mail that exploits the human target's natural curiosity and desire to engage and communicate, and enables the installation of malware - like the gh0st RAT program that bedeviled the Tibetan government in exile.

For the record, Citizen Lab denied that its investigation of gh0st RAT was related to any vulnerabilities in Psiphon and did not confirm that any of the targeted computers were running as Psiphon nodes serving inside China.

Indeed, the penetration of computers in Dharmsala - one monk reported watching Outlook Express open by itself and send an e-mail off with a document attached - was a pressing issue in itself, and enough to justify the extensive investigation.

However, what happened to the Tibetan computers brings to mind weaknesses that might be exploited at Psiphon node or site on a PC platform: non-professional operators with an uncertain grasp of security working on vulnerable machines, unwittingly downloading malware that enables remote observers to read files, keylog passwords and extract keys.

On a psiphonsite, malware could extract details of the log-in and disable and/or imperil its psiphonode by logging in for a malicious, bandwidth-hogging session. If a psiphonode is identified and penetrated, apparently details of the psiphonsite(s) it is serving - and the pages they have visited - can be extracted.

Balancing Psiphon's reliance on a "network of trust" versus the willingness of the Chinese government (or their bespoke hackers) to pour resources in the cyber struggle with the Tibetan emigre movement, this skirmish in cyberspace might turn out to be a draw.

Interestingly, Citizen Lab seems to be interested in dialing down the rhetoric in the wake of its cybersecurity coup against "GhostNet".

Despite a preponderance of circumstantial evidence - such as the nature of the targets and the existence of three out of four of the gh0st RAT control servers inside China - its report went out of its way to caveat assumptions of Chinese government involvement in the attack and stress that Citizen Lab researchers had not broken any laws in the investigation.

Certainly, Citizen Lab did not wish to find itself - or the Canadian government - characterized as a provider of counter-intelligence services to the Tibetan government in exile in its battle with incessant Chinese cyber-intrusions.

Citizen Lab's restraint may have also reflected Professor Deibert's publicized dismay at the West's growing interest in militarizing the Internet - illustrated by a bipartisan proposal that the Barack Obama administration appoint a "Cybersecurity National Adviser" with the power to disconnect the government and "critical" civilian networks from the Internet in case of national emergency - largely in response to China's perceived intentions and capabilities in cyberwarfare.

On a more strategic level, Deibert's caution may also reflect an awareness that the censorship-circumvention infrastructure may be adequate for low-level skirmishing with malicious Chinese hacker-patriots and the drudges running day-to-day Internet interdiction for China, but perhaps would not be able to withstand a concerted assault by China's cyberwarfare specialists - or cope with an Internet fragmented into Chinese and Western cybersecurity fortresses.

The Internet seems destined to frustrate both hopes of China for national security, and those of dissidents for an irresistible truth weapon.

One of the most famous observations concerning the Internet is by John Gilmore, founder of the Electronic Freedom Foundation: "The Internet treats censorship as a defect and routes around it."

Perhaps the Internet has the same response to censorship's doppelgangers - secrecy, encryption and the user's desire for privacy: it rejects them and finds a way around.

Those bits and bytes just want to be free. And we have to find a way to live with that.

Notes
1. See Tracking GhostNet: Investigating a Cyber Espionage Network
2. See Hushmail warns users over law enforcement backdoor.
3. For the report, click here.
4. See Defeat Internet Censorship: Overview of Advanced Technologies and Products
5. See Why you need balls of steel to operate a Tor exit node

Peter Lee writes on East and South Asian affairs and their intersection with US foreign policy.

(Copyright 2009 Asia Times Online (Holdings) Ltd. All rights reserved.)