Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Saturday, July 20, 2013

NSA's ‘TAO’ Group Been Hacking China For 15 Years



By GEOFFREY INGERSOLL

The primary complaint against China’s outift of military hackers has been dual pronged: the U.S. private sector is losing expensive proprietary information, and the public sector is having its sensitive weapons systems compromised.
China’s response has been, simply: yeah but the U.S. did it to us first, and worse.
It turns out, China might just be telling it like it is this time.
The deafening sound of internet aggregators shredding Edward Snowden’s life into digestible pieces drowned out probably one of the most epic posts of the week: Matthew M. Aid’s Foreign Policy piece titled “Inside the NSA’s Ultra-Secret China Hacking Group.”
In it, Aid describes how the U.S. has a long history of penetrating China’s systems — what they call “Computer Network Exploitation.” The U.S. government, as we should have assumed, knows the most intimate details about the Chinese communist party and its People’s Liberation Army.
From Aid’s piece:
A highly secretive unit of the National Security Agency (NSA) … called the Office of Tailored Access Operations, or TAO, has successfully penetrated Chinese computer and telecommunications systems for almost 15 years, generating some of the best and most reliable intelligence information about what is going on inside the People’s Republic of China.
TAO mirrors China’s methods by first hacking into computer networks, then protecting themselves from being identified, and finally copying ALL communications and files from within that network.
If that sounds familiar, its because the process nearly matches the description Mandiant — the company that caught Chinese hackers red-handed — gave to explain the method the PLA uses to steal American information.
Except America’s system pre-dates that of China.
Chinese defence Ministry spokesman, Geng Yansheng, recently said in a briefing:
“The team was set up to better safeguard the internet security of the armed forces. Cyber security was an international problem, affecting civil and military areas. China is still “relatively weak” in internet security protection, and vulnerable to cyber-terrorism.”
It’s not just China in the mix either — it’s Israel, Singapore, Japan, Switzerland, the U.K. and others, British intelligence analyst Glenmore Trenear-Harvey told InfoSec.com.
“This is not just conventional military powers. Put bluntly, everyone’s at it. It is a game anyone can play. But do remember that we – the U.S. and UK – are doing this in reverse and we are very successful,” said Trenear-Harvey.
Not only has Obama ordered the military to draw up a list of potential cyber targets around the globe, but most of the military academies now offer majors in Cyber Warfare.
There’s also been revelations that the cyber war is getting a big boost from the civilian side. Apparently, more than a third of the Marine Corps’ cyber war will be fought by contractors.
Hackers may be full of old tricks, but it’s a new battlefield, and it looks like everyone is down to play the game.
“[Cyber Warfare] an incredibly potent weapon which will certainly be utilized,” said Trenear-Harvey.

Tuesday, June 25, 2013

Hacking The Drone War’s Secret History

Airmen load an inert Hellfire missile on a Predator drone in New Mexico in April. <em>Photo: Air Force</em>
Airmen load an inert Hellfire missile on a Predator drone in New Mexico in April. Photo: Air Force

By David Axe

In 2008 U.S. troops in Iraq discovered that Shi’ite insurgents had figured out how to tap and record video feeds from overhead American drones. Now you too can hack Washington’s globe-spanning fleet of silent, deadly armed robots — although legally, and only in an historical sense.

Josh Begley, a 28-year-old NYU grad student, has just created an application programming interface — basically, a collection of building blocks for software development — that allows anyone with basic coding skills to organize, analyze and visualize drone-strike data from Pakistan, Yemen and Somalia dating back to 2002.
Based on information collected by the U.K. Bureau of Investigative Journalism, the API can be used to create interactive Websites (similar to this) that add depth, context and even a little humanity to the sterile news reports of the latest Unmanned Aerial Vehicle strike in some far-away conflict zone.
Begley tells Danger Room he’s trying to bridge the “empathy gap” between Western audiences and drone-attack victims. “To Americans like me, what may have previously been blank spots on the map all of a sudden have complex stories, voices of their own. From 30,000 feet it might just be cars and buildings. But there are people in them. People who live under the drones we fly.”
Begley has already experimented with a few interfaces using his API. One, he says, “assembles every covert drone attack on a Website, hides them behind numbered blank tiles, and lets you filter through the various years and countries where these attacks happened.”
Another interface is more practical,” he adds. “It’s just a simple search function — for researchers and legal scholars who want to look for a specific drone attack, or more easily go to the Bureau of Investigative Journalism and read the corresponding articles they’ve assembled.”
The drone API, which is actually Begley’s master’s thesis, is not his first foray into capturing robot-attack data. His @dronestream Twitter feed documents all reported UAV attacks. Last year Begley created an iPhone app that tracks drone strikes, but Apple rejected it. Other developers have jumped on the bandwagon, too. London-based artist James Bridle runs a Tumblr blog that matches overhead satellite imagery to reports of drone attacks.
The public release of Begley’s API, which took five months to complete, is timed to coincide with the White House-promoted National Day of Civic Hacking on June 1. Hacking Day aims to “liberate government data for coders and entrepreneurs.” The ACLU, for one, is commemorating the event with an API linked to the group’s vast database of documents related to U.S.-sanctioned torture of terror suspects.
“I’m actually not sure what people will learn,” Begley says of his own drone-strike API. “I just feel like I’ve been iterating on this data set for a little while and there are probably a bunch of more talented developers and designers who could find stuff in the data that I’m not seeing.”
With Pres. Barack Obama’s recent promise to rein in robotic attacks, the time is ripe to begin making sense of 12 years of drone warfare that has claimed thousands of lives. Begley’s API makes that vital self-reflection a whole lot easier.

Friday, March 22, 2013

Computer Fights Hacker Attack



"Born To Be Viral" is our new weekly slot for incredible videos that we think deserve to go wild across the web


Ever wondered what it looks like when a hacker attacks a computer and tries to break into someone's account?
Now Ben Reardon of Dataviz Australia has created a stunning visualisation that shows a single attack on a voice-over-IP (VOIP) server, similar to those used for Skype. Hacked VOIP servers are often used for black-market communications and cheap calling-card scams.
In the video above, the server is shown on the left, where the accounts of the people signed up to make calls are represented by blue bubbles. A hacker's attack comes from the right, launching small white and red bubbles that represent scans from a malicious computer program. The battle that plays out is slowed down by 25 per cent.
If the hacker's scans connect with the blue bubbles, they may be able to compromise the server, gathering the passwords of account holders and ultimately letting the hacker control other people's phone activity.
To protect itself against the attack, the server releases green honeypots: disguised data released to trap the intruding scans. But the hacker then increases the number of scans in an attempt to overwhelm the honeypots. In the end, the server wins the battle.
According to Reardon, countless attacks like this one occur every second. "The volume of data from this one attack is really a drop in the ocean in terms of the wider internet," he says.
Source: New Scientist

Wednesday, December 12, 2012

Hacking The Brain: The Next Domain Of Warfare




It’s been fashionable in military circles to talk about cyberspace as a “fifth domain” for warfare, along with land, space, air and sea. But there’s a sixth and arguably more important warfighting domain emerging: the human brain.
This new battlespace is not just about influencing hearts and minds with people seeking information. It’s about involuntarily penetrating, shaping, and coercing the mind in the ultimate realization of Clausewitz’s definition of war: compelling an adversary to submit to one’s will. And the most powerful tool in this war is brain-computer interface (BCI) technologies, which connect the human brain to devices.
Current BCI work ranges from researchers compiling and interfacing neural data such as in the Human Conectome Project to work by scientists hardening the human brain against rubber hose cryptanalysis to technologists connecting the brain to robotic systems. While these groups are streamlining the BCI for either security or humanitarian purposes, the reality is that misapplication of such research and technology has significant implications for the future of warfare.
Where BCIs can provide opportunities for injured or disabled soldiers to remain on active duty post-injury, enable paralyzed individuals to use their brain to type, or allow amputees to feel usingbionic limbs, they can also be exploited if hacked. BCIs can be used to manipulate … or kill.
Recently, security expert Barnaby Jack demonstrated the vulnerability of biotechnological systems by highlighting how easilypacemakers and implantable cardioverter-defibrillators (ICDs) could be hacked, raising fears about the susceptibility of even life-saving biotechnological implants. This vulnerability could easily be extended to biotechnologies that connect directly to the brain, such as vagus nerve stimulation or deep-brain stimulation.
Outside the body, recent experiments have proven that the brain can control and maneuverquadcopter drones and metal exoskeletons. How long before we harness the power of mind-controlled weaponized drones – or use BCIs to enhance the power, efficiency, and sheer lethality of our soldiers?
This new battlespace is not just about influencing hearts and minds. It’s about involuntarily penetrating and coercing the mind.
Given that military research arms such as the United States’ DARPA are investing in understanding complex neural processesand enhanced threat detection through BCI scan for P300responses, it seems the marriage between neuroscience and military systems will fundamentally alter the future of conflict.
And it is here that military researchers need to harden the systems that enable military application of BCIs. We need to prevent BCIs from being disrupted or manipulated, and safeguard against the ability of the enemy to hack an individual’s brain.
The possibilities for damage, destruction, and chaos are very real. This could include manipulating a soldier’s BCI during conflict so that s/he were forced to pull the gun trigger on friendlies, install malicious code in his own secure computer system, call in inaccurate coordinates for an air strike, or divulge state secrets to the enemy seemingly voluntarily. Whether an insider has fallen victim to BCI hacking and exploits a system from within, or an external threat is compelled to initiate a physical attack on hard and soft targets, the results would present major complications: in attribution, effectiveness of kinetic operations, and stability of geopolitical relations.
Like every other domain of warfare, the mind as the sixth domain is neither isolated nor removed from other domains; coordinated attacks across all domains will continue to be the norm. It’s just that military and defense thinkers now need to account for the subtleties of the human mind … and our increasing reliance upon the brain-computer interface.
Regardless of how it will look, though, the threat is real and not as far away as we would like – especially now that researchers just discovered a zero-day vulnerability in the brain.
Via: "Wired"

Sunday, September 09, 2012

Hacking The Brain and Successfully Extracting Sensitive Data




With a chilling hint of the not-so-distant future, researchers at the Usenix Security conference have demonstrated a zero-day vulnerabilityin your brain. Using a commercial off-the-shelf brain-computer interface, the researchers have shown that it’s possible to hack your brain, forcing you to reveal information that you’d rather keep secret.
As we’ve covered in the past, a brain-computer interface is a two-part device: There’s the hardware — which is usually a headset (an EEG; an electroencephalograph) with sensors that rest on your scalp — and software, which processes your brain activity and tries to work out what you’re trying to do (turn left, double click, open box, etc.) BCIs are generally used in a medical setting with very expensive equipment, but in the last few years cheaper, commercial offerings have emerged. For $200-300, you can buy an Emotiv (pictured above) or Neurosky BCI, go through a short training process, and begin mind controlling your computer.
Brain hacking accuracy
Both of these commercial BCIs have an API — an interface that allows developers to use the BCI’s output in their own programs. In this case, the security researchers — from the Universities of Oxford and Geneva, and the University of California, Berkeley — created a custom program that was specially designed with the sole purpose of finding out sensitive data, such as the location of your home, your debit card PIN, which bank you use, and your date of birth. The researchers tried out their program on 28 participants (who were cooperative and didn’t know that they were being brain-hacked), and in general the experiments had a 10 to 40% chance of success of obtaining useful information (pictured above).
P300 responseTo extract this information, the researchers rely on what’s known as the P300 response — a very specific brainwave pattern (pictured right) that occurs when you recognize something that is meaningful (a person’s face), or when you recognize something that fits your current task (a hammer in the shed). The researchers basically designed a program that flashes up pictures of maps, banks, and card PINs, and makes a note every time your brain experiences a P300. Afterwards, it’s easy to pore through the data and work out — with fairly good accuracy — where a person banks, where they live, and so on.
The security researchers' brain hacking setupIn a real-world scenario, the researchers foresee a game that is specially tailored by hackers to extract sensitive information from your brain — or perhaps an attack vector that also uses social engineering to lull you into a false sense of security. It’s harder to extract data from someone who knows they’re being attacked — as interrogators and torturers well know.
Moving forward, this brain hack can only improve in efficacy as BCIs become cheaper, more accurate, and thus more extensively used. Really, your only defense is to not think about the topic — but if you’re proactively on the defensive, then the hacker has already messed up. The only viable solution that I can think of is to ensure that you don’t use your brain-computer interface with shady software,brain malware — but then again, in a science-fictional future, isn’t it almost guaranteed that the government would mandate the inclusion of brain-hacking software in the operating system itself?

Friday, November 11, 2011

Sci-Fi-Style Sabotage A Fear In New Hacks




By Jordan Robertson,
AP Technology Writer
October 23, 2011
Courtesy Of "The Boston Globe"


When a computer attack hobbled Iran’s unfinished nuclear power plant last year, it was assumed to be a military-grade strike, the handiwork of elite hacking professionals with nation-state backing.
Yet for all its science fiction sophistication, key elements have now been replicated in laboratory settings by security experts with little time, money or specialized skill. It is an alarming development that shows how technical advances are eroding the barrier that has long prevented computer assaults from leaping from the digital to the physical world.
The techniques demonstrated in recent months highlight the danger to operators of power plants, water systems and other critical infrastructure around the world.
“Things that sounded extremely unlikely a few years ago are now coming along,’’ said Scott Borg, director of the U.S. Cyber Consequences Unit, a nonprofit group that helps the U.S. government prepare for future attacks.
While the experiments have been performed in laboratory settings, and the findings presented at security conferences or in technical papers, the danger of another real-world attack such as the one on Iran is profound.
The team behind the so-called Stuxnet worm that was used to attack the Iranian nuclear facility may still be active. New malicious software with some of Stuxnet’s original code and behavior has surfaced, suggesting ongoing reconnaissance against industrial control systems.
And attacks on critical infrastructure are increasing. The Idaho National Laboratory, home to secretive defense labs intended to protect the nation’s power grids, water systems and other critical infrastructure, has responded to triple the number of computer attacks from clients this year over last, the U.S. Department of Homeland Security has revealed.
For years, ill-intentioned hackers have dreamed of plaguing the world’s infrastructure with a brand of sabotage reserved for Hollywood. They’ve mused about wreaking havoc in industrial settings by burning out power plants, bursting oil and gas pipelines, or stalling manufacturing plants.
But a key roadblock has prevented them from causing widespread destruction: they’ve lacked a way to take remote control of the electronic “controller’’ boxes that serve as the nerve centers for heavy machinery.
The attack on Iran changed all that. Now, security experts — and presumably, malicious hackers — are racing to find weaknesses. They’ve found a slew of vulnerabilities.
Think of the new findings as the hacking equivalent of Moore’s Law, the famous rule about computing power that it roughly doubles every couple of years. Just as better computer chips have accelerated the spread of PCs and consumer electronics over the past 40 years, new hacking techniques are making all kinds of critical infrastructure — even prisons — more vulnerable to attacks.
One thing all of the findings have in common is that mitigating the threat requires organizations to bridge a cultural divide that exists in many facilities. Among other things, separate teams responsible for computer and physical security need to start talking to each other and coordinate efforts.
Many of the threats at these facilities involve electronic equipment known as controllers. These devices take computer commands and send instructions to physical machinery, such as regulating how fast a conveyor belt moves.
They function as bridges between the computer and physical worlds. Computer hackers can exploit them to take over physical infrastructure. Stuxnet, for example, was designed to damage centrifuges in the nuclear plant being built in Iran by affecting how fast the controllers instructed the centrifuges to spin. Iran has blamed the U.S. and Israel for trying to sabotage what it says is a peaceful program.
Security researcher Dillon Beresford said it took him just two months and $20,000 in equipment to find more than a dozen vulnerabilities in the same type of electronic controllers used in Iran. The vulnerabilities, which included weak password protections, allowed him to take remote control of the devices and reprogram them.
“What all this is saying is you don’t have to be a nation-state to do this stuff. That’s very scary,’’ said Joe Weiss, an industrial control system expert. “There’s a perception barrier, and I think Dillon crashed that barrier.’’
One of the biggest makers of industrial controllers is Siemens AG, which made the controllers in question. The company said it has alerted customers, fixed some of the problems and is working closely with CERT, the cybersecurity arm of the U.S. Department of Homeland Security.
Siemens said the issue largely affects older models of controllers. Even with those, the company said, a hacker would have to bypass passwords and other security measures that operators should have in place. Siemens said it knows of no actual break-ins using the techniques identified by Beresford, who works in Austin, Texas, for NSS Labs Inc.,
Yet because the devices are designed to last for decades, replacing or updating them isn’t always easy. And the more research that comes out, the more likely attacks become.
One of the foremost Stuxnet experts, Ralph Langner, a security consultant in Hamburg, Germany, has come up with what he calls a “time bomb’’ of just four lines of programming code. He called it the most basic copycat attack that a Stuxnet-inspired prankster, criminal or terrorist could come up with.
“As low-level as these results may be, they will spread through the hacker community and will attract others who continue digging,’’ Langer said in an email.
The threat isn’t limited to power plants. Even prisons and jails are vulnerable.
Another research team, based in Virginia, was allowed to inspect a correctional facility — it won’t say which one — and found vulnerabilities that would allow it to open and close the facility’s doors, suppress alarms and tamper with video surveillance feeds.
During a tour of the facility, the researchers noticed controllers like the ones in Iran. They used knowledge of the facility’s network and that controller to demonstrate weaknesses.
They said it was crucial to isolate critical control systems from the Internet to prevent such attacks.
“People need to deem what’s critical infrastructure in their facilities and who might come in contact with those,’’ Teague Newman, one of the three behind the research.
Another example involves a Southern California power company that wanted to test the controllers used throughout its substations. It hired Mocana Corp., a San Francisco-based security firm, to do the evaluation.
Kurt Stammberger, a vice president at Mocana, told The Associated Press that his firm found multiple vulnerabilities that would allow a hacker to control any piece of equipment connected to the controllers.
“We’ve never looked at a device like this before, and we were able to find this in the first day,’’ Stammberger said. “These were big, major problems, and problems frankly that have been known about for at least a year and a half, but the utility had no clue.’’
He wouldn’t name the utility or the device maker. But he said it wasn’t a Siemens device, which points to an industrywide problem, not one limited to a single manufacturer.
Mocana is working with the device maker on a fix, Stammberger said. His firm presented its findings at the ICS Cyber Security Conference in September.
Even if a manufacturer fixes the problem in new devices, there’s no easy way to fix it in older units, short of installing new equipment. Industrial facilities are loath to do that because of the costs of even temporarily shutting its operations.
“The situation is not at all as bad as it was five to six years ago, but there’s much that remains to be done,’’ said Ulf Lindqvist, an expert on industrial control systems with SRI International. “We need to be as innovative and organized on the good-guy side as the bad guys can be.’’
MORE LIKE THIS »

Tuesday, October 05, 2010

Hackers Are Screwing With Oppressive Regimes

Just Like Wikileaks

The principle that information-hoarding is evil and helps cement illegitimate power has inspired hacker activists all over the world for decades.

By Peter Ludlow
September 19, 2010
Courtesy Of "Alter Net"

In recent months there has been considerable discussion about the WikiLeaks phenomenon, and understandably so, given the volume and sensitivity of the documents the website has released. What this discussion has revealed, however, is that the media and government agencies believe there is a single protagonist to be concerned with -- something of a James Bond villain, if you will -- when in fact the protagonist is something altogether different: an informal network of revolutionary individuals bound by a shared ethic and culture.
According to conventional wisdom, the alleged protagonist is, of course, WikiLeaks founder Julian Assange, and the discussion of him has ranged from Raffi Khatchadourian's June portrait in The New Yorker, which makes Assange sound like a master spy in a John le CarrĂ© novel, to Tunku Varadarajan's epic ad hominem bloviation in The Daily Beast: "With his bloodless, sallow face, his lank hair drained of all color, his languorous, very un-Australian limbs, and his aura of blinding pallor that appears to admit no nuance, Assange looks every inch the amoral, uber-nerd villain."
Some have called for putting Assange "out of business" (even if we must violate international law to do it), while others, ranging from Daniel Ellsberg to Assange himself, think he is (in Ellsberg's words) "in some danger." I don't doubt that Assange is in danger, but even if he is put out of business by arrest, assassination or character impeachment with charges of sexual misconduct, it would not stanch the flow of secret documents into the public domain. To think otherwise is an error that reflects a colossal misunderstanding of the nature of WikiLeaks and the subculture from which it emerged.
WikiLeaks is not the one-off creation of a solitary genius; it is the product of decades of collaborative work by people engaged in applying computer hacking to political causes, in particular, to the principle that information-hoarding is evil -- and, as Stewart Brand said in 1984, "Information wants to be free." Today there is a broad spectrum of people engaged in this cause, so that were Assange to be eliminated today, WikiLeaks would doubtless continue, and even if WikiLeaks were somehow to be eliminated, new sites would emerge to replace it.
Let's begin by considering whether it is possible to take WikiLeaks offline, as called for in the Washington Post by former Bush speechwriter Marc Thiessen, who added that "taking [Assange] off the streets is not enough; we must also recover the documents he unlawfully possesses and disable the system he has built to illegally disseminate classified information."
Consider the demand that we "recover the documents." Even the documents that have not been made public by WikiLeaks are widely distributed all over the Internet. WikiLeaks has released an encrypted 1.4 gigabyte file called "insurance.aes256." If something happens to Assange, the password to the encrypted file will be released (presumably via a single Twitter tweet). What's in the file? We don't know, but at 1.4 gigabytes, it is nineteen times the size of the Afghan war log that was recently distributed to major newspapers. Legendary hacker Kevin Poulsen speculates that the file "is doubtless in the hands of thousands, if not tens of thousands, of netizens already."
It's also a bit difficult to "disable the system," since WikiLeaks did not need to create a new network; the group simply relied on existing electronic communications networks (e.g., the Internet) and the fact that there are tens of thousands of like-minded people all over the world. Where did all those like-minded people come from? Are they all under the spell of Assange? To the contrary, they were active long before Assange sat down to hack his first computer.
It has long been an ethical principle of hackers that ideas and information are not to be hoarded but are to be shared.In 1984, when Assange turned 13, Steven Levy described this attitude in his book Hackers. After interviewing a number of hackers, he distilled a "hacker ethic," which included, among others, the following two maxims: (1) all information should be free; (2) mistrust authority and promote decentralization.
These sentiments were poetically expressed by a hacker named The Mentor, in an essay titled "The Conscience of a Hacker." It was written shortly after his arrest, and appeared in the important hacker publication Phrack in 1986.
We explore…and you call us criminals. We seek after knowledge…and you call us criminals. We exist without skin color, without nationality, without religious bias…and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it's for our own good, yet we're the criminals. Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for. I am a hacker, and this is my manifesto. You may stop this individual, but you can't stop us all.
Indeed, you can't stop them all. One year after The Mentor's manifesto was published, Assange acquired a modem and entered cyberspace for the first time. In the quarter-century since, that basic hacker philosophy has not been abandoned, and indeed has evolved into a broad cultural movement. Hacker conferences with thousands of attendees have sprung up in places ranging from Amsterdam and New York to Las Vegas and Abu Dhabi, and small weekly hacker meetups are routine in every major city in the world.
For many hackers, this activity has taken a decidedly political turn -- into what is sometimes called hacktivism. Hacktivism is the application of information technologies (and the hacking of them) to political action. This has ranged from simple website defacings and attempts to unbottle secret information to efforts to ensure the privacy of ordinary citizens by providing them military-grade encryption (a successful mission of the infamous Cypherpunks).
Hacktivism has been extended to political action against all manner of power structures. One of the earliest examples is the Hong Kong Blondes -- a group that disrupted computer networks in China in the 1990s so people could get access to blocked websites. The Hong Kong Blondes were in turn assisted by a Texas-based hacker group called the Cult of the Dead Cow (cDc), which helped them with advanced encryption technology. In 2006 the cDc subsequently waged a PR campaign against Google (calling it Goolag) when Google caved in to Chinese censorship demands. Their slogan: "Goolag: Exporting censorship, one search at a time."
Examples of hacktivism by other groups have included denizens of the rowdy, transgressive and scatological 4Chan website, operating under the name Anonymous, in its assault on attempted censorship by the Church of Scientology, using a series of denial-of-service attacks against Scientology websites. Anonymous also moved against the Iranian government during the 2009 elections, when it established a website that shared information from inside Iran and provided advice to Iranian activists on how to encrypt and safely transmit communications. Another notable example is a group of Portuguese hackers called Urban Ka0s, which protested the Indonesian government's treatment of East Timor by hacking Indonesian government websites in the 1990s and posting alternative pages that protested the government's policies.
The political compass of these hacktivist groups has never pointed true right or true left -- at least by our typical way of charting the political landscape. They have been consistently unified in their adherence to the basic hacker principles as outlined by Levy and The Mentor in the 1980s: information should not be hoarded by powerful constituencies -- it needs to be placed in the hands of the general public. This principle is followed even to the point of threatening to become a "foolish consistency" -- as in the recent document dump from WikiLeaks, which drew the rebuke of five human rights organizations, including Amnesty International, because, they felt, civilian sources were not adequately protected.
As described in Khatchadourian's New Yorker profile, Assange's philosophy blends in seamlessly with the hacktivist tradition: it can't be characterized in terms of left versus right so much as individual versus institution. In particular, Assange holds that truth, creativity, etc. are corrupted by institutional hierarchies, or what he calls "patronage networks," and that much of illegitimate power is perpetuated by the hoarding of information.
Meanwhile, in a profile of Army Pvt. Bradley Manning, the man accused of leaking documents to WikiLeaks, the New York Times considered many explanations for what Manning did. He was troubled because "classmates made fun of him for being gay"; he was "ignored" by his superiors; he was "self-medicating." Curiously elided was what Manning actually said his motivation was. In a May 25 conversation, the hacker Adrian Lamo asked Manning why he gave the information to WikiLeaks when he could have sold it to Russia or China and "made bank." Manning replied in true hacktivist fashion, "Because it's public data...it belongs in the public domain...information should be free...if it's out in the open...it should [do the] public good."
The traditional media, governments and their security organizations just cannot get unglued from the idea that there must be a single mastermind behind an operation like WikiLeaks. While this model works great in fictional dramas, it does not track what is really happening. This is not a one-man or even one-group operation. It is a network of thousands motivated by a shared hacktivist culture and ethic. And with or without Assange, it is not going away.
Peter Ludlow, a professor of philosophy at Northwestern University, is the editor of Crypto Anarchy, Cyberstates, and Pirate Utopias.

Saturday, July 25, 2009

The Book On Information Warfare


By William S. Lind
Posted on: July 21st, 2009

Courtesy Of
The American Conservative Magazine

Ideas as Weapons is the title of a new book, a collection of essays edited by two Marine Corps officers, G.J. David Jr. and T.R. McKeldin (the publisher is Potomac Books). Subtitled “Influence and Perception in Modern Warfare,” the volume is dedicated to exploring the aspect of war most neglected by the Second Generation American military, ideas. The U.S. armed forces have never grasped the centrality of John Boyd’s dictum that for winning wars, people are most important, ideas come second and hardware is only third.

Mostly, the U.S. military reduces ideas to “Information Operations,” or IO, in which some junior officers and NCOs churn out leaflets, films etc. of indifferent quality. The idea, central to Fourth Generation war, that Information Operations are what you do, not what you say, is missed entirely. The results of typical IO range from minimal to hilarious. The book recalls one incident during the siege of Fallujah where Marines made and broadcast a film intended to show American troops feeding Iraqi refugees halal rations. It actually showed them feeding Arabs kosher rations, which did not play too well locally.

As with all collections, chapters vary in quality. They are organized in four parts, Geopolitical, Strategic, Operational (it’s nice to see Marines using that word correctly form once) and Tactical. In my view, the best chapter in the Geopolitical section is Ambassador David Passage’s “Reflections on Psychological Operations: The Imperative of Engaging a Conflicted Population.” He argues that “It has long been axiomatic in guerrilla warfare that a defending force (such as a government the United States is associated with) will find itself confronted with almost insuperable odds unless it can enlist the active – not passive – support of its own citizens in countering an insurgency.” Contrasting America’s failure in Vietnam with success in El Salvador, Ambassador Passage suggests the usual psyops messages are ineffective:

The modern age has reached the point where, given the babble of conflicting, contradicting, and combative messages, populations are decreasingly likely to simply accept what they are told. In the welter of competing messages and mediums, government-sponsored messages are at a particular disadvantage…

A better approach might be to ask questions rather that provide answers…

The fundamental message to the people of Iraq and Afghanistan and other countries in conflict needs to be, as the U.S. message was in El Salvador twenty years ago, “This is your country; the kind of country it’s going to be is up to you – not to the United States or any foreign country. What kind of country do you want it to be? Are you willing to help restore order, and law, and civility – or are you going to sit quietly while those who seek to destroy what you have do their work?”

A strong chapter in the Strategic section is Colonel William M. Darley USA’s “Clausewitz’s Theory of War and Information Operations.” Darley argues that “Contrary to entrenched perceptions, IO is not merely a family of related skill sets or capabilities that in all cases augment “kinetic operation.” Collectively, they are properly understood as a specific purpose and emphasis within an overall plan of action that under some circumstances might be the main effort.” I would add that in 4GW, they are usually the main effort.

Darley offers a Clausewitzian definition of IO, far broader than the current American technical definition. It reflects Clausewitz’s discussion of the power of “moral” factors in what is essentially a political contest. His chapter concludes with a quotation from Clausewitz that strikes to the heart of ongoing American failures in 4GW:

Political considerations do not determine the posting of guards or the employment of patrols. But they are the more influential in the planning of war, of the campaign, and often even of the battle…The only question, therefore, is whether, when war is being planned the political point of view should give way to the purely military…or should the political point of view remain dominant and the military (military force and violence) be subordinated to it?

The book’s Operational segment includes a devastating critique of the U.S. military’s whole intelligence system, “Clouding the Issue: Intelligence Collection, Analysis, and Dissemination during Operation Iraqi Freedom,” by Army Lt. Col. George J. Stroumpos. Too lengthy to summarize here, it proceeds from the statement that

Our intelligence apparatus has been our Achilles’ heel… the Coalition intelligence apparatus is a hodgepodge pick-up team, conflicting in its organization and lost in a sea of data. This, coupled with the sheer volume and complexity of the environment, is the primary problem…is poor information management and the resulting syntheses that follow from poor technique.

Ideas as Weapons’Tactical segment, which junior-level practitioners will find of particular value, includes a superb chapter, “Tactical Information Operations in West Rashid: An Iraqi National Police Battalion and Its Assigned U.S. Transition Team,” by Major E. Lawson Quinn, USMC. This chapter gets at one of the central fallacies of the whole American effort in Iraq (and elsewhere), namely that what local government forces need is American training in techniques. In reality, cultural factors are far more important than technical skills (Saddam’s forces, after all, were technically quite capable of maintaining order in Iraq without American training). Major Quinn gets at the central problem when he writes:

The Sunni population in West Rashid unquestionably viewed 2/7/2 (an Iraqi National Police battalion) as a sectarian organization that served the interests of the Shi’a majority at the expense of the Sunnis, if not an instrument of or in collusion with the Shi’a militias. The very demographic makeup of 2/7/2, less than ten Sunnis among the four hundred or so Shi’a members of the battalion, precluded overcoming that sectarian perception even if the Shi’a majority and leadership wanted to do so, but their actions clearly did not evince the slightest proclivity toward it.

In fact, it was quite clear that at least the battalion leadership understood the value of information operations in reinforcing that perception. Even the casual Western observer…would have understood the message trumpeted by the large Shi’a flag posted at the front of the compound high atop the tallest building.

Ideas as Weaponsis a book that should be high on the reading list of every American commander in Iraq and Afghanistan, from the theater level down through company. I stress commanders, not just intelligence officers, because IO properly defined are at the heart of Fourth Generation war. Until American commanders at all levels understand that fact, we will continue to rocket and bomb our way to defeat.

Monday, July 20, 2009

Cyberstrikes Originated From Britain, Not North Korea


Say Experts

By Bobbie Johnson, San Francisco
Wednesday 15 July 2009 02.34 BST
Courtesy Of
The Guardian

A recent wave of cyber attacks that crippled thousands of computers and websites in the United States and South Korea could have originated from inside Britain, experts have warned.

According to security researchers in Vietnam, the source of last week's string of attacks by the Mydoom virus - which overwhelmed systems belonging to the US Treasury and the office of the South Korean president Lee Myung-Bak - can be traced to the UK.

"We have analysed the malware pattern that we received" said Nguyen Minh Duc, a director of Vietnamese security company BKIS, in a post on the company's blog. "We found a master server located in the UK."

Investigators said they had discovered new details on how the strikes took place by investigating and tracing back the attacks.

According to BKIS, infected computers had tried to contact one of eight so-called command and control servers every three minutes. These machines then gave instructions to the hacked PC - generally ordering them to direct traffic straight at victim websites, in attempt to overload them and force them to crash.

But these eight servers were themselves being controlled by a single source, which evidence indicated was located somewhere in Britain.

"Having located the attacking source in UK, we believe that it is completely possible to find out the hacker," wrote Nguyen. "This of course depends on the US and South Korean governments."

The findings contradict some earlier reports that the surge in attacks may have been coordinated from North Korea, a theory largely driven by intelligence reports presented to the authorities in Seoul.

Despite the news, government officials in South Korea are still trying to ascertain whether the strikes actually originated in the UK - or whether Britain was simply being used to screen the true location of those behind the attacks.

"We don't know that the attackers were actually based in Britain, or mainly hacked a British IP address and used it for delivery,'' an official from the Korean Communications Commission told the Korea Times.