Showing posts with label Stellar Wind (NSA). Show all posts
Showing posts with label Stellar Wind (NSA). Show all posts

Saturday, March 15, 2014

How The NSA Plans To Infect ‘Millions’ Of Computers With Malware

Featured photo - How the NSA Plans to Infect ‘Millions’ of Computers with Malware
One presentation outlines how the NSA performs “industrial-scale exploitation” of computer networks across the world.

By Ryan Gallagher and Glenn Greenwald

Top-secret documents reveal that the National Security Agency is dramatically expanding its ability to covertly hack into computers on a mass scale by using automated systems that reduce the level of human oversight in the process.
The classified files – provided previously by NSA whistleblower Edward Snowden – contain new details about groundbreaking surveillance technology the agency has developed to infect potentially millions of computers worldwide with malware “implants.” The clandestine initiative enables the NSA to break into targeted computers and to siphon out data from foreign Internet and phone networks.
The covert infrastructure that supports the hacking efforts operates from the agency’s headquarters in Fort Meade, Maryland, and from eavesdropping bases in the United Kingdom and Japan. GCHQ, the British intelligence agency, appears to have played an integral role in helping to develop the implants tactic.
In some cases the NSA has masqueraded as a fake Facebook server, using the social media site as a launching pad to infect a target’s computer and exfiltrate files from a hard drive. In others, it has sent out spam emails laced with the malware, which can be tailored to covertly record audio from a computer’s microphone and take snapshots with its webcam. The hacking systems have also enabled the NSA to launch cyberattacks by corrupting and disrupting file downloads or denying access to websites.
The implants being deployed were once reserved for a few hundred hard-to-reach targets, whose communications could not be monitored through traditional wiretaps. But the documents analyzed by The Intercept show how the NSA has aggressively accelerated its hacking initiatives in the past decade by computerizing some processes previously handled by humans. The automated system – codenamed TURBINE – is designed to “allow the current implant network to scale to large size (millions of implants) by creating a system that does automated control implants by groups instead of individually.”
In a top-secret presentation, dated August 2009, the NSA describes a pre-programmed part of the covert infrastructure called the “Expert System,” which is designed to operate “like the brain.” The system manages the applications and functions of the implants and “decides” what tools they need to best extract data from infected machines.
Mikko Hypponen, an expert in malware who serves as chief research officer at the Finnish security firm F-Secure, calls the revelations “disturbing.” The NSA’s surveillance techniques, he warns, could inadvertently be undermining the security of the Internet.
“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.”
Hypponen believes that governments could arguably justify using malware in a small number of targeted cases against adversaries. But millions of malware implants being deployed by the NSA as part of an automated process, he says, would be “out of control.”
“That would definitely not be proportionate,” Hypponen says. “It couldn’t possibly be targeted and named. It sounds like wholesale infection and wholesale surveillance.”
The NSA declined to answer questions about its deployment of implants, pointing to a new presidential policy directive announced by President Obama. “As the president made clear on 17 January,” the agency said in a statement, “signals intelligence shall be collected exclusively where there is a foreign intelligence or counterintelligence purpose to support national and departmental missions, and not for any other purposes.”
 “Owning The Net”
The NSA began rapidly escalating its hacking efforts a decade ago. In 2004, according to secretinternal records, the agency was managing a small network of only 100 to 150 implants. But over the next six to eight years, as an elite unit called Tailored Access Operations (TAO) recruited new hackers and developed new malware tools, the number of implants soared to tens of thousands.
To penetrate foreign computer networks and monitor communications that it did not have access to through other means, the NSA wanted to go beyond the limits of traditional signals intelligence, or SIGINT, the agency’s term for the interception of electronic communications. Instead, it sought to broaden “active” surveillance methods – tactics designed to directly infiltrate a target’s computers or network devices.
In the documents, the agency describes such techniques as “a more aggressive approach to SIGINT” and says that the TAO unit’s mission is to “aggressively scale” these operations.
But the NSA recognized that managing a massive network of implants is too big a job for humans alone.
“One of the greatest challenges for active SIGINT/attack is scale,” explains the top-secret presentation from 2009. “Human ‘drivers’ limit ability for large-scale exploitation (humans tend to operate within their own environment, not taking into account the bigger picture).”
The agency’s solution was TURBINE. Developed as part of TAO unit, it is described in the leaked documents as an “intelligent command and control capability” that enables “industrial-scale exploitation.”
TURBINE was designed to make deploying malware much easier for the NSA’s hackers by reducing their role in overseeing its functions. The system would “relieve the user from needing to know/care about the details,” the NSA’s Technology Directorate notes in one secret document from 2009. “For example, a user should be able to ask for ‘all details about application X’ and not need to know how and where the application keeps files, registry entries, user application data, etc.”
In practice, this meant that TURBINE would automate crucial processes that previously had to be performed manually – including the configuration of the implants as well as surveillance collection, or “tasking,” of data from infected systems. But automating these processes was about much more than a simple technicality. The move represented a major tactical shift within the NSA that was expected to have a profound impact – allowing the agency to push forward into a new frontier of surveillance operations.
The ramifications are starkly illustrated in one undated top-secret NSA document, which describes how the agency planned for TURBINE to “increase the current capability to deploy and manage hundreds of Computer Network Exploitation (CNE) and Computer Network Attack (CNA) implants to potentially millions of implants.” (CNE mines intelligence from computers and networks; CNA seeks to disrupt, damage or destroy them.)
Eventually, the secret files indicate, the NSA’s plans for TURBINE came to fruition. The system has been operational in some capacity since at least July 2010, and its role has become increasingly central to NSA hacking operations.
Earlier reports based on the Snowden files indicate that the NSA has already deployed between 85,000 and 100,000 of its implants against computers and networks across the world, with plans to keep on scaling up those numbers.
The intelligence community’s top-secret “Black Budget” for 2013, obtained by Snowden, lists TURBINE as part of a broader NSA surveillance initiative named “Owning the Net.”
The agency sought $67.6 million in taxpayer funding for its Owning the Net program last year. Some of the money was earmarked for TURBINE, expanding the system to encompass “a wider variety” of networks and “enabling greater automation of computer network exploitation.”
 Circumventing Encryption
The NSA has a diverse arsenal of malware tools, each highly sophisticated and customizable for different purposes.
One implant, codenamed UNITEDRAKE, can be used with a variety of “plug-ins” that enable the agency to gain total control of an infected computer.
An implant plug-in named CAPTIVATEDAUDIENCE, for example, is used to take over a targeted computer’s microphone and record conversations taking place near the device. Another, GUMFISH, can covertly take over a computer’s webcam and snap photographs. FOGGYBOTTOM records logs of Internet browsing histories and collects login details and passwords used to access websites and email accounts. GROK is used to log keystrokes. And SALVAGERABBIT exfiltrates data from removable flash drives that connect to an infected computer.
The implants can enable the NSA to circumvent privacy-enhancing encryption tools that are used to browse the Internet anonymously or scramble the contents of emails as they are being sent across networks. That’s because the NSA’s malware gives the agency unfettered access to a target’s computer before the user protects their communications with encryption.
It is unclear how many of the implants are being deployed on an annual basis or which variants of them are currently active in computer systems across the world.
Previous reports have alleged that the NSA worked with Israel to develop the Stuxnet malware, which was used to sabotage Iranian nuclear facilities. The agency also reportedly worked with Israel to deploy malware called Flame to infiltrate computers and spy on communications in countries across the Middle East.
According to the Snowden files, the technology has been used to seek out terror suspects as well as individuals regarded by the NSA as “extremist.” But the mandate of the NSA’s hackers is not limited to invading the systems of those who pose a threat to national security.
In one secret post on an internal message board, an operative from the NSA’s Signals Intelligence Directorate describes using malware attacks against systems administrators who work at foreign phone and Internet service providers. By hacking an administrator’s computer, the agency can gain covert access to communications that are processed by his company. “Sys admins are a means to an end,” the NSA operative writes.
The internal post – titled “I hunt sys admins” – makes clear that terrorists aren’t the only targets of such NSA attacks. Compromising a systems administrator, the operative notes, makes it easier to get to other targets of interest, including any “government official that happens to be using the network some admin takes care of.”
Similar tactics have been adopted by Government Communications Headquarters, the NSA’s British counterpart. As the German newspaper Der Spiegel reported in September, GCHQ hacked computers belonging to network engineers at Belgacom, the Belgian telecommunications provider.
The mission, codenamed “Operation Socialist,” was designed to enable GCHQ to monitor mobile phones connected to Belgacom’s network. The secret files deem the mission a “success,” and indicate that the agency had the ability to covertly access Belgacom’s systems since at least 2010.
Infiltrating cellphone networks, however, is not all that the malware can be used to accomplish. The NSA has specifically tailored some of its implants to infect large-scale network routers used by Internet service providers in foreign countries. By compromising routers – the devices that connect computer networks and transport data packets across the Internet – the agency can gain covert access to monitor Internet traffic, record the browsing sessions of users, and intercept communications.
Two implants the NSA injects into network routers, HAMMERCHANT and HAMMERSTEIN, help the agency to intercept and perform “exploitation attacks” against data that is sent through aVirtual Private Network, a tool that uses encrypted “tunnels” to enhance the security and privacy of an Internet session.
The implants also track phone calls sent across the network via Skype and other Voice Over IP software, revealing the username of the person making the call. If the audio of the VOIP conversation is sent over the Internet using unencrypted “Real-time Transport Protocol” packets, the implants can covertly record the audio data and then return it to the NSA for analysis.
But not all of the NSA’s implants are used to gather intelligence, the secret files show. Sometimes, the agency’s aim is disruption rather than surveillance. QUANTUMSKY, a piece of NSA malware developed in 2004, is used to block targets from accessing certain websites. QUANTUMCOPPER, first tested in 2008, corrupts a target’s file downloads. These two “attack” techniques are revealed on a classified list that features nine NSA hacking tools, six of which are used for intelligence gathering. Just one is used for “defensive” purposes – to protect U.S. government networks against intrusions.
 “Mass Exploitation Potential”
Before it can extract data from an implant or use it to attack a system, the NSA must first install the malware on a targeted computer or network.
According to one top-secret document from 2012, the agency can deploy malware by sending out spam emails that trick targets into clicking a malicious link. Once activated, a “back-door implant” infects their computers within eight seconds.
There’s only one problem with this tactic, codenamed WILLOWVIXEN: According to the documents, the spam method has become less successful in recent years, as Internet users have become wary of unsolicited emails and less likely to click on anything that looks suspicious.
Consequently, the NSA has turned to new and more advanced hacking techniques. These include performing so-called “man-in-the-middle” and “man-on-the-side” attacks, which covertly force a user’s internet browser to route to NSA computer servers that try to infect them with an implant.
To perform a man-on-the-side attack, the NSA observes a target’s Internet traffic using its global network of covert “accesses” to data as it flows over fiber optic cables or satellites. When the target visits a website that the NSA is able to exploit, the agency’s surveillance sensors alert the TURBINE system, which then “shoots” data packets at the targeted computer’s IP address within a fraction of a second.
In one man-on-the-side technique, codenamed QUANTUMHAND, the agency disguises itself as a fake Facebook server. When a target attempts to log in to the social media site, the NSA transmits malicious data packets that trick the target’s computer into thinking they are being sent from the real Facebook. By concealing its malware within what looks like an ordinary Facebook page, the NSA is able to hack into the targeted computer and covertly siphon out data from its hard drive. A top-secret animation demonstrates the tactic in action.



The documents show that QUANTUMHAND became operational in October 2010, after being successfully tested by the NSA against about a dozen targets.
According to Matt Blaze, a surveillance and cryptography expert at the University of Pennsylvania, it appears that the QUANTUMHAND technique is aimed at targeting specific individuals. But he expresses concerns about how it has been covertly integrated within Internet networks as part of the NSA’s automated TURBINE system.
“As soon as you put this capability in the backbone infrastructure, the software and security engineer in me says that’s terrifying,” Blaze says.
“Forget about how the NSA is intending to use it. How do we know it is working correctly and only targeting who the NSA wants? And even if it does work correctly, which is itself a really dubious assumption, how is it controlled?”
In an email statement to The Intercept, Facebook spokesman Jay Nancarrow said the company had “no evidence of this alleged activity.” He added that Facebook implemented HTTPS encryption for users last year, making browsing sessions less vulnerable to malware attacks.
Nancarrow also pointed out that other services besides Facebook could have been compromised by the NSA. “If government agencies indeed have privileged access to network service providers,” he said, “any site running only [unencrypted] HTTP could conceivably have its traffic misdirected.”
A man-in-the-middle attack is a similar but slightly more aggressive method that can be used by the NSA to deploy its malware. It refers to a hacking technique in which the agency covertly places itself between computers as they are communicating with each other.
This allows the NSA not only to observe and redirect browsing sessions, but to modify the content of data packets that are passing between computers.
The man-in-the-middle tactic can be used, for instance, to covertly change the content of a message as it is being sent between two people, without either knowing that any change has been made by a third party. The same technique is sometimes used by criminal hackers to defraud people.
A top-secret NSA presentation from 2012 reveals that the agency developed a man-in-the-middle capability called SECONDDATE to “influence real-time communications between client and server” and to “quietly redirect web-browsers” to NSA malware servers called FOXACID. In October, details about the FOXACID system were reported by the Guardian, which revealed its links to attacks against users of the Internet anonymity service Tor.
But SECONDDATE is tailored not only for “surgical” surveillance attacks on individual suspects. It can also be used to launch bulk malware attacks against computers.
According to the 2012 presentation, the tactic has “mass exploitation potential for clients passing through network choke points.”
Blaze, the University of Pennsylvania surveillance expert, says the potential use of man-in-the-middle attacks on such a scale “seems very disturbing.” Such an approach would involve indiscriminately monitoring entire networks as opposed to targeting individual suspects.
“The thing that raises a red flag for me is the reference to ‘network choke points,’” he says. “That’s the last place that we should be allowing intelligence agencies to compromise the infrastructure – because that is by definition a mass surveillance technique.”
To deploy some of its malware implants, the NSA exploits security vulnerabilities in commonly used Internet browsers such as Mozilla Firefox and Internet Explorer.
The agency’s hackers also exploit security weaknesses in network routers and in popular software plugins such as Flash and Java to deliver malicious code onto targeted machines.
The implants can circumvent anti-virus programs, and the NSA has gone to extreme lengths to ensure that its clandestine technology is extremely difficult to detect. An implant named VALIDATOR, used by the NSA to upload and download data to and from an infected machine, can be set to self-destruct – deleting itself from an infected computer after a set time expires.
In many cases, firewalls and other security measures do not appear to pose much of an obstacle to the NSA. Indeed, the agency’s hackers appear confident in their ability to circumvent any security mechanism that stands between them and compromising a computer or network. “If we can get the target to visit us in some sort of web browser, we can probably own them,” an agency hacker boasts in one secret document. “The only limitation is the ‘how.’”
 Covert Infrastructure
The TURBINE implants system does not operate in isolation.
It is linked to, and relies upon, a large network of clandestine surveillance “sensors” that the agency has installed at locations across the world.
The NSA’s headquarters in Maryland are part of this network, as are eavesdropping bases used by the agency in Misawa, Japan and Menwith Hill, England.
The sensors, codenamed TURMOIL, operate as a sort of high-tech surveillance dragnet, monitoring packets of data as they are sent across the Internet.
When TURBINE implants exfiltrate data from infected computer systems, the TURMOIL sensors automatically identify the data and return it to the NSA for analysis. And when targets are communicating, the TURMOIL system can be used to send alerts or “tips” to TURBINE, enabling the initiation of a malware attack.
The NSA identifies surveillance targets based on a series of data “selectors” as they flow across Internet cables. These selectors, according to internal documents, can include email addresses, IP addresses, or the unique “cookies” containing a username or other identifying information that are sent to a user’s computer by websites such as Google, Facebook, Hotmail, Yahoo, and Twitter.
Other selectors the NSA uses can be gleaned from unique Google advertising cookies that track browsing habits, unique encryption key fingerprints that can be traced to a specific user, and computer IDs that are sent across the Internet when a Windows computer crashes or updates.
What’s more, the TURBINE system operates with the knowledge and support of other governments, some of which have participated in the malware attacks.
Classification markings on the Snowden documents indicate that NSA has shared many of its files on the use of implants with its counterparts in the so-called Five Eyes surveillance alliance – the United Kingdom, Canada, New Zealand, and Australia.
GCHQ, the British agency, has taken on a particularly important role in helping to develop the malware tactics. The Menwith Hill satellite eavesdropping base that is part of the TURMOIL network, located in a rural part of Northern England, is operated by the NSA in close cooperation with GCHQ.
Top-secret documents show that the British base – referred to by the NSA as “MHS” for Menwith Hill Station – is an integral component of the TURBINE malware infrastructure and has been used to experiment with implant “exploitation” attacks against users of Yahoo and Hotmail.
In one document dated 2010, at least five variants of the QUANTUM hacking method were listed as being “operational” at Menwith Hill. The same document also reveals that GCHQ helped integrate three of the QUANTUM malware capabilities – and test two others – as part of a surveillance system it operates codenamed INSENSER.
GCHQ cooperated with the hacking attacks despite having reservations about their legality. One of the Snowden files, previously disclosed by Swedish broadcaster SVT, revealed that as recently as April 2013, GCHQ was apparently reluctant to get involved in deploying the QUANTUM malware due to “legal/policy restrictions.” A representative from a unit of the British surveillance agency, meeting with an obscure telecommunications standards committee in 2010, separately voiced concerns that performing “active” hacking attacks for surveillance “may be illegal” under British law.
In response to questions from The Intercept, GCHQ refused to comment on its involvement in the covert hacking operations. Citing its boilerplate response to inquiries, the agency said in a statement that “all of GCHQ’s work is carried out in accordance with a strict legal and policy framework which ensures that our activities are authorized, necessary and proportionate, and that there is rigorous oversight.”
Whatever the legalities of the United Kingdom and United States infiltrating computer networks, the Snowden files bring into sharp focus the broader implications. Under cover of secrecy and without public debate, there has been an unprecedented proliferation of aggressive surveillance techniques. One of the NSA’s primary concerns, in fact, appears to be that its clandestine tactics are now being adopted by foreign rivals, too.
“Hacking routers has been good business for us and our 5-eyes partners for some time,” notes one NSA analyst in a top-secret document dated December 2012. “But it is becoming more apparent that other nation states are honing their skillz [sic] and joining the scene.”
———
Documents published with this article:

Tuesday, February 26, 2013

The Return Of COINTELPRO



By TOM MCNAMARA
Courtesy Of "CounterPunch"


“Democracies die behind closed doors” – Judge Damon J. Keith
For 15 years (1956-1971) the Federal Bureau of Investigation (FBI) ran a broad and highly coordinated domestic intelligence / counterintelligence program known as COINTELPRO (COunter INTELligence PROgrams). What was originally deemed as a justifiable effort to protect the US during the Cold War from Soviet and Communist threats and infiltration, soon devolved into a program for suppressing domestic dissent and spying on American citizens. Approximately 20,000 people were investigated by the FBI based only on their political views and beliefs. Most were never suspected of having committed any crime.
The reasoning behind the program, as detailed in a 1976 Senate report, was that the FBI had “the duty to do whatever is necessary to combat perceived threats to the existing social and political order.” The fact that the “perceived threats” were usually American citizens engaging in constitutionally protected behaviour was apparently overlooked. The stated goal of COINTELPRO was to “expose, disrupt, misdirect, discredit, or otherwise neutralize” any individual or group deemed to be subversive or a threat to the established power structure.
The FBI’s techniques were often extreme, with the agency being complicit in the murder and assassination of political dissidents, or having people sent away to prison for life. Some of the more “moderate” actions that were used were blackmail, spreading false rumors, intimidation and harassment. It has been argued that the US is unique in that it is the only Western industrialized democracy to have engaged in such a wide spread and well organized domestic surveillance program. It finally came to an end in 1971 when it was threatened with public exposure.
Or did it?
In a stunning revelation from the Partnership for Civil Justice Fund (PCJF), it appears that COINTELPRO is alive and well. Through a Freedom of Information Act (FOIA) request, PCJF was able to obtain documents showing how the FBI was treating the Occupy Wall Street (OWS) movement, from its inception, as a potential criminal and domestic terrorist threat. This despite the FBI’s own acknowledgement that the OWS organizers themselves planned on engaging in peaceful and popular protest and did not “condone the use of violence.”
The documents, while heavily redacted, give a clear picture of how the FBI was using its offices and agents across the country as early as August 2011 to engage in a massive surveillance scheme against OWS. This was almost a month before any actual protests took place or encampments were set up (the most famous being the one in New York City’s Zuccotti Park).
The FBI’s documents show a government agency at its most paranoid. It considered all planned protests, and the individuals involved, as potential threats. Most disturbing of all, there is talk (p. 61) of the government being ready to “engage in sniper attacks against protesters in Houston, Texas, if deemed necessary” and perhaps needing to formulate a plan “to kill the leadership [of the protest groups] via suppressed sniper rifles.”
Furthermore, the documents reveal a close and intricate partnership between the federal government on one side and banks and private businesses on the other.
On August 19, 2011, the FBI met with representatives of the New York Stock Exchange in order to discuss OWS protests that wouldn’t happen for another four weeks. In September of that year, even before OWS got into full swing, the FBI was notifying local businesses that they might be affected by protests. It is not clear if, while on Wall Street, the FBI investigated the criminal and irresponsible behavior engaged in by some of the largest banks on the planet, behavior which led directly to the financial crisis of 2008.
We are also introduced to a creature named the “Domestic Security Alliance Council” which, according to the federal government, is “a strategic partnership between the FBI, the Department of Homeland Security and the private sector.” A DSAC report tells us that any information shared between US intelligence agencies and their corporate partners should not be released to “the media, the general public or other personnel.”
In a curious coincidence, nine days after the PCJF’s embarrassing release of FBI documents, the New York Post ran a story about how a 27 year old woman and her “Harvard grad and Occupy Wall Street” boyfriend, Aaron Greene, were arrested by officers from the New York City Police Department (NYPD) after an alleged cache of weapons and bomb making explosives were found in their Greenwich Village apartment.
And what exactly led the police to this apartment? Was it credible actionable intelligence gathered from the FBI’s massive domestic surveillance program? Did some agent acquire this information by bravely infiltrating the potential domestic terrorist group known as OWS? Hardly. The NYPD was simply executing a routine search warrant related to a credit card-theft case.
But in a story about the exact same event that appeared in the New York Times, it was reported that “police said they did not believe that Mr. Greene was active in any political movements” and that no “evidence of a planned terrorist attack” had been found . Furthermore, police hadn’t “made a connection to any known plot or any connection to any known terrorists.” No mention was made of the suspect’s alleged ties to the OWS movement, an item that had been prominently reported in the New York Post’s version of events.
Oddly, a more recent New York Post story stated that Mr. Greene was now a “Nazi-loving Harvard grad” and a reported “Adolf Hitler-wannabe.” No mention was made of his suspected ties to OWS. This author made several attempts to contact the New York Post, and the writers of the 2 articles, in an effort to find out how they knew that Mr. Greene was an OWS member and activist. Attempts were also made to try to find out if the New York Post still believed that Mr. Greene was an active OWS member, or if they now simply thought that he was just an “Adolf Hitler-wannabe.”
As of the writing of this article, no response has been received from the New York Post.
The FBI’s stated mission regarding America’s security is to “develop a comprehensive understanding of the threats and penetrate national and transnational networks that have a desire and capability to harm us.”
The American people would be far better served by their government if, instead of wasting millions of dollars and thousands of man-hours harassing peaceful protesters, it spent a fraction of that time and money investigating, and bringing to justice, the people responsible for the engineered destruction of the American economy, and by extension, American society.
You know. The real terrorists.
Tom McNamara is an Assistant Professor at the ESC Rennes School of Business, France, and a Visiting Lecturer at the French National Military Academy at Saint-Cyr, Coëtquidan, France.
Sources
“COINTELPRO: The FBI’s Covert Action Programs Against American Citizens” Supplementary Detailed Staff Reports on Intelligence Activities and the Rights of Americans, Book III, Final report of the Select Committee to Study Governmental Operations with respect to Intelligence Activities, United States Senate, April 23, 1976. Accessed at:
“COINTELPRO: The Untold American Story”, by Paul Wolf with contributions from Robert Boyle, Bob Brown, Tom Burghardt, Noam Chomsky, Ward Churchill, Kathleen Cleaver, Bruce Ellison, Cynthia McKinney, Nkechi Taifa, Laura Whitehorn, Nicholas Wilson, and Howard Zinn. Presented to U.N. High Commissioner for Human Rights Mary Robinson at the World Conference Against Racism in Durban, South Africa by the members of the Congressional Black Caucus attending the conference: Donna Christianson, John Conyers, Eddie Bernice Johnson, Barbara Lee, Sheila Jackson Lee, Cynthia McKinney, and Diane Watson, September 1, 2001. Accessed at:
“FBI Documents Reveal Secret Nationwide Occupy Monitoring” The Partnership for Civil Justice Fund (PCJF), December 22, 2012. Accessed at:
http://www.justiceonline.org/commentary/fbi-files-ows.html
“Greenwich Village couple busted with cache of weapons, bombmaking explosives: sources” by Jamie Schram, Antonio Antenucci and Matt McNulty, December 31, 2012, The New York Post.   Accessed at:
“Manhattan Couple Stored Bomb-Making Items, Police Say” by Wendy Ruderman, December 31, 2012, The New York Times. Accessed at:
“More About FBI Spying” The American Civil Liberties Union (ACLU), June 25, 2010. Accessed at:
“NYC couple arrested after explosive substance find” December 31, 2012, CBS/AP. Accessed at:
“Revealed: how the FBI coordinated the crackdown on Occupy” by Naomi Wolf, December 29, 2012, The Guardian. Accessed at:
“The Federal Bureau of Investigation – Mission” The Federal Bureau of Investigation. Accessed at:
“Village ‘bomber’ planned to blow up Washington Sq. Arch with high-grade explosives: cops” by Jamie Schram and Jessica Simeone, January 10, 2013, The New York Post. Accessed at:

Saturday, September 22, 2012

The "Stellar Wind" Program





By Laura Poitras


filmmaker Laura Poitras profiles William Binney, a 32-year veteran of the National Security Agency who helped design a top-secret program he says is broadly collecting Americans’ personal data.

It took me a few days to work up the nerve to phone William Binney. As someone already a “target” of the United States government, I found it difficult not to worry about the chain of unintended consequences I might unleash by calling Mr. Binney, a 32-year veteran of the National Security Agency turned whistle-blower. He picked up. I nervously explained I was a documentary filmmaker and wanted to speak to him. To my surprise he replied: “I’m tired of my government harassing me and violating the Constitution. Yes, I’ll talk to you.”

Two weeks later, driving past the headquarters of the N.S.A. in Maryland, outside Washington, Mr. Binney described details about Stellar Wind, the N.S.A.’s top-secret domestic spying program begun after 9/11, which was so controversial that it nearly caused top Justice Department officials to resign in protest, in 2004.

“The decision must have been made in September 2001,” Mr. Binney told me and the cinematographer Kirsten Johnson. “That’s when the equipment started coming in.” In this Op-Doc, Mr. Binney explains how the program he created for foreign intelligence gathering was turned inward on this country. He resigned over this in 2001 and began speaking out publicly in the last year. He is among a group of N.S.A. whistle-blowers, including Thomas A. Drake, who have each risked everything — their freedom, livelihoods and personal relationships — to warn Americans about the dangers of N.S.A. domestic spying.

To those who understand state surveillance as an abstraction, I will try to describe a little about how it has affected me. The United States apparently placed me on a “watch-list” in 2006 after I completed a film about the Iraq war. I have been detained at the border more than 40 times. Once, in 2011, when I was stopped at John F. Kennedy International Airport in New York and asserted my First Amendment right not to answer questions about my work, the border agent replied, “If you don’t answer our questions, we’ll find our answers on your electronics.”’ As a filmmaker and journalist entrusted to protect the people who share information with me, it is becoming increasingly difficult for me to work in the United States. Although I take every effort to secure my material, I know the N.S.A. has technical abilities that are nearly impossible to defend against if you are targeted.

The 2008 amendments to the Foreign Intelligence Surveillance Act, which oversees the N.S.A. activities, are up for renewal in December. Two members of the Senate Select Committee on Intelligence, Senators Ron Wyden of Oregon and Mark Udall of Colorado, both Democrats, are trying to revise the amendments to insure greater privacy protections. They have been warning about “secret interpretations” of laws and backdoor “loopholes” that allow the government to collect our private communications. Thirteen senators have signed a letter expressing concern about a “loophole” in the law that permits the collection of United States data. The A.C.L.U. and other groups have also challenged the constitutionality of the law, and the Supreme Court will hear arguments in that case on Oct. 29.


Laura Poitras is a documentary filmmaker who has been nominated for an Academy Award and whose work was exhibited in the 2012 Whitney Biennial. She is working on a trilogy of films about post-9/11 America. This Op-Doc is adapted from a work in progress to be released in 2013.

This video is part of a series by independent filmmakers who have received grants from the BRITDOC Foundation and the Sundance Institute. 

Monday, September 10, 2012

FBI Installing NGI System Across The Nation


Birthmarks, be damned: the FBI has officially started rolling out a state-of-the-art face recognition project that will assist in their effort to accumulate and archive information about each and every American at a cost of a billion dollars.
The Federal Bureau of Investigation has reached a milestone in the development of their Next Generation Identification (NGI) program and is now implementing the intelligence database in unidentified locales across the country, New Scientist reports in an article this week. The FBI first outlined the project back in 2005, explaining to the Justice Department in an August 2006 document (.pdf) that their new system will eventually serve as an upgrade to the current Integrated Automated Fingerprint Identification System (IAFIS) that keeps track of citizens with criminal records across America .
“The NGI Program is a compilation of initiatives that will either improve or expand existing biometric identification services,” its administrator explained to the Department of Justice at the time, adding that  the project, “will accommodate increased information processing and sharing demands in support of anti-terrorism.”
“The NGI Program Office mission is to reduce terrorist and criminal activities by improving and expanding biometric identification and criminal history information services through research, evaluation and implementation of advanced technology within the IAFIS environment.”
The agency insists, “As a result of the NGI initiatives, the FBI will be able to provide services to enhance interoperability between stakeholders at all levels of government, including local, state, federal, and international partners.” In doing as such, though, the government is now going ahead with linking a database of images and personally identifiable information of anyone in their records with departments around the world thanks to technology that makes fingerprint tracking seem like kids' stuff.
According to their 2006 report, the NGI program utilizes “specialized requirements in the Latent Services, Facial Recognition and Multi-modal Biometrics areas” that “will allow the FnewBI to establish a terrorist fingerprint identification system that is compatible with other systems; increase the accessibility and number of the IAFIS terrorist fingerprint records; and provide latent palm print search capabilities.”
Is that just all, though? During a 2010 presentation (.pdf) made by the FBI’s Biometric Center of Intelligence, the agency identified why facial recognition technology needs to be embraced. Specifically, the FBI said that the technology could be used for “Identifying subjects in public datasets,” as well as “conducting automated surveillance at lookout locations” and “tracking subject movements,” meaning NGI is more than just a database of mug shots mixed up with fingerprints — the FBI has admitted that this their intent with the technology surpasses just searching for criminals but includes spectacular surveillance capabilities. Together, it’s a system unheard of outside of science fiction.
New Scientist reports that a 2010 study found technology used by NGI to be accurate in picking out suspects from a pool of 1.6 million mug shots 92 percent of the time. The system was tested on a trial basis in the state of Michigan earlier this year, and has already been cleared for pilot runs in Washington, Florida and North Carolina. Now according to this week’s New Scientist report, the full rollout of the program has begun and the FBI expects its intelligence infrastructure to be in place across the United States by 2014.
In 2008, the FBI announced that it awarded Lockheed Martin Transportation and Security Solutions, one of the Defense Department’s most favored contractors, with the authorization to design, develop, test and deploy the NGI System. Thomas E. Bush III, the former FBI agent who helped develop the NGI's system requirements, tells NextGov.com, "The idea was to be able to plug and play with these identifiers and biometrics." With those items being collected without much oversight being admitted, though, putting the personal facts pertaining to millions of Americans into the hands of some playful Pentagon staffers only begins to open up civil liberties issues.
Jim Harper, director of information policy at the Cato Institute, adds to NextGov that investigators pair facial recognition technology with publically available social networks in order to build bigger profiles. Facial recognition "is more accurate with a Google or a Facebook, because they will have anywhere from a half-dozen to a dozen pictures of an individual, whereas I imagine the FBI has one or two mug shots," he says. When these files are then fed to law enforcement agencies on local, federal and international levels, intelligence databases that include everything from close-ups of eyeballs and irises to online interests could be shared among offices.
The FBI expects the NGI system to include as many as 14 million photographs by the time the project is in full swing in only two years, but the pace of technology and the new connections constantly created by law enforcement agencies could allow for a database that dwarfs that estimate. As RT reported earlier this week, the city of Los Angeles now considers photography in public space “suspicious,” and authorizes LAPD officers to file reports if they have reason to believe a suspect is up to no good. Those reports, which may not necessarily involve any arrests, crimes, charges or even interviews with the suspect, can then be filed, analyzed, stored and shared with federal and local agencies connected across the country to massive data fusion centers. Similarly, live video transmissions from thousands of surveillance cameras across the country are believed to be sent to the same fusion centers as part of TrapWire, a global eye-in-the-sky endeavor that RT first exposed earlier this year.
“Facial recognition creates acute privacy concerns that fingerprints do not,” US Senator Al Franken (D-Minnesota) told the Senate Judiciary Committee’s subcommittee on privacy, technology and the law earlier this year. “Once someone has your faceprint, they can get your name, they can find your social networking account and they can find and track you in the street, in the stores you visit, the government buildings you enter, and the photos your friends post online.”
In his own testimony, Carnegie Mellon University Professor Alessandro Acquisti said to Sen. Franken, “the convergence of face recognition, online social networks and data mining has made it possible to use publicly available data and inexpensive technologies to produce sensitive inferences merely starting from an anonymous face.”
“Face recognition, like other information technologies, can be source of both benefits and costs to society and its individual members,” Prof. Acquisti added. “However, the combination of face recognition, social networks data and data mining can significant undermine our current notions and expectations of privacy and anonymity.”
With the latest report suggesting the NGI program is now a reality in America, though, it might be too late to try and keep the FBI from interfering with seemingly every aspect of life in the US, both private and public. As of July 18, 2012, the FBI reports, “The NGI program … is on scope, on schedule, on cost, and 60 percent deployed.”