Pages

Friday, September 20, 2013

state-sponsored espionage


UK's GCHQ blamed for cyber attack on Belgian telecoms company

The agency was named in the latest revelations from NSA whistleblower Edward Snowden



Britain is facing a damaging public clash with a European ally after GCHQ was blamed for a cyber attack on Belgium’s largest telecommunications company and the country’s prosecutors announced they were treating the incident as “state-sponsored espionage”.

The Cheltenham-based eavesdropping agency was named in the latest revelations from American whistleblower Edward Snowden as the origin of a sophisticated assault on Belgacom, whose customers include the European Commission and the European Parliament.

An alleged internal GCHQ presentation, marked “Top Secret” and leaked by Snowden, suggests that British intelligence officers targeted Belgacom employees over a number of years with sophisticated malware to gain access to key infrastructure, including the company’s international router.

Prosecutors in Brussels said that initial investigations showed there had been an attack on Belgacom which could only have been possible with “significant financial and logistical backing”. When combined with the complexity of the techniques deployed, this indicated an “international state-sponsored espionage operation,” investigators said.

The Belgian authorities and politicians yesterday stopped short of pointing the finger directly at Britain but the country’s prime minister said the revelations from former National Security Agency contractor Snowden, published by Der Spiegel, were being “closely examined” and warned of unspecified retaliation if the attack was proven.
Elio di Rupo said: “If the hypothesis involving another country is confirmed, we will of course undertake the necessary steps.”

The allegations are the latest in a raft of damaging revelations flowing from Snowden’s document cache, which has exposed the depth of Anglo-American operations to gain access to vast quantities of email and telecommunications traffic across the globe.

The NSA has been implicated in operations ranging from interception of the emails and phone calls of Brazilian president Dilma Rousseff to inserting “back doors” into computer hardware. But confirmation that Britain has been hacking the phone system of a close ally - and the host nation for key European Union institutions - would be also highly damaging.
GCHQ said last night that it had a “longstanding practice” of not commenting on leaks or intelligence matters.

But a spokesman added: “All GCHQ’s work is carried out in accordance with a strict legal and policy framework which ensures that its activities are authorised, necessary and proportionate, and that there is rigorous oversight.”

The latest documents from Snowden, which appear to date from around 2010, detail “Operation Socialist”, an assault on Belgacom’s “core GRX routers” - the hardware used by mobile phone companies to make calls between different networks and different countries possible.

The slideshow presentation states that GCHQ’s alleged aim was to undertake “Man in the Middle” or “MiTM” operations “against targets roaming using smart phones”.

Man in the Middle attacks are a highly-sophisticated deception which allows a third party to intervene in an electronic conversation and pretend to be each of the other two parties, obtaining valuable information or spreading disinformation without the targets realising.
One of the slides appears to confirm that several Belgacom networks have been compromised, boasting that access “continues to expand” and GCHQ is “getting close” to accessing the routers. The presentation concludes with a large logo featuring construction cranes and the word “success”.

Belgacom and one of its subsidiaries jointly owned by Swiss and South African companies, which also appears to have been targeted, confirmed it had been the victim of a “digital intrusion” on its internal computer network but insisted there was “no indication” that customer data including emails or conversations had been accessed.

There was speculation yesterday that although the company, which is partly state-owned, handles communications involving EU institutions, GCHQ’s alleged interest may have been in users of its international networks linked to Middle Eastern countries such as Syria and Yemen.

Belgian prosecutors, who were called in by Belgacom earlier this summer, said preliminary investigations showed several servers and work stations had been affected by the attack.
In a statement, the Federal Prosecutors office in Brussels said: “Based on the information currently available, the aim of the hacking seems to be more to gather strategic information and not to commit acts of sabotage or cause economic damage.”

Saturday, September 7, 2013

Hammer v nail: Syria crisis

7 September 2013 Last updated at 03:50

Syria begs question of America's role in the world

US President Barack Obama sits in front of an American flag at the G20 Summit in St. Petersburg on 6 September 2013President Obama has demonstrated reluctance to "go it alone" regarding strikes on Syria
The president is clearing his desk, going all-out to persuade for a vote that he has said is vital for America's credibility.
It is also a critical moment for American perception of itself as a power in the world. But in the details of the debate over Syria, the biggest questions and the larger picture are in danger of being lost.
In essence, it's whether the world needs a super cop. And whether the US should simply assume that role.
President Barack Obama - like UK PM David Cameron, like former US President George W Bush and former UK PM Tony Blair before them - has two main arguments for intervention in the Middle East. They overlap and intertwine, but they are distinct.
The first is national interest. Mr Obama says Syria does not pose an immediate threat to the US, but its willingness to use chemical weapons threatens its allies and bases in the region.
Less frequently his administration has suggested such weapons could fall into the hands of terrorists who could use them against America.
It is pretty obvious, the bigger the world power the more its vital interests may be harmed by something happening a long way away. If the whole Middle East is in uproar, it might not make a whole heap of difference to Paraguay or Latvia.
The argument for national interest is pretty clear. The desire to intervene for what you might call 'moral reasons', is far more murky.
Mr Obama and even more forcefully Secretary of State John Kerry have said that the world can't stand aside and witness such suffering. Particularly not when it breaches, if not international law, then international norms.
It is noticeable that it is senior politicians in the US, France and the UK who are keen on this argument of liberal interventionism. It is not just Russia that won't go along with it. China won't either.
China forcefully repeats that it wants the denuclearisation of its ally North Korea. But it is reluctant to force the issue.
But it is not just those in the communist country and the former communist empire which hold that view.
You hardly hear voices raised to demand military intervention from India or Brazil, Nigeria or Japan.
Countries on the doorstep of the various Middle East crises may want someone to do something, but look askance at the idea they might take on the task themselves.
A world policeman might have more moral authority if it wasn't one of the old imperial powers or the US, which while not technically the proud possessor of an empire, has a bigger footprint than any other country in the world.
I once put it to Tony Blair that the Iraq war might have been more credible if the call for action had come from Sweden. He made the obvious point: "Well, they couldn't do it, could they?"
Which makes me wonder about that old saying, "to a hammer, every problem is a nail". In this case, you have to wonder why the hammer was forged in the first place.
The British developed their military to defend a globe-spanning empire. The US developed its military might to intervene in Europe and then to challenge the USSR.
The absence of the original purpose has not eliminated an instinct to intervene.
Maybe the word "imperialism" makes you think of arguments "that it is all about oil" or crude land grabs.
But those Victorian imperialists really did think they were bringing civilisation and Christianity, order and the rule of law to people who couldn't climb to such dizzying heights on their own.
America's belief in its own mission is more universal and not driven by racism, but there is a similar zealous enthusiasm to remake the rest of the world in its image.
Of course, stopping the horror of chemical weapons is not the same as introducing democracy at the point of a gun.
But it raises the same question of who has the authority to make the judgment that norms have been violated, and who deals out the punishment.
The UN is meant to be the body that can order global cops into action. But the US says the Security Council is broken, because of the Russian veto.
While the Russian action does look cynical, it is a bit like a prosecutor saying the jury system doesn't work because he didn't get a conviction.
Or indeed, if David Cameron said parliament didn't work because of the "no" vote. President Obama understands how it looks to the rest of the world if the US goes it alone.
It is why he was so reluctant to take the lead over Libya, why he was so slow to develop a Syria strategy.
But he's decided now that even if no-one else (apart from France) is willing to step up to the plate, it is America's job to do so. Few at home or abroad seem to agree with him - but they don't have any other answer either.

Syria crisis: No clear winner in Russia-US G20 duel


Vladimir Putin and Barack ObamaRussia's Vladimir Putin and US President Barack Obama failed to see eye to eye over Syria during the G20 summit
Both sides have claimed victory in this G20 gladiatorial contest over Syria, but identifying who is on which team is not straightforward.
So who backed Russia and who backed the United States?
According to President Vladimir Putin, the outcome was not a 50/50 split, but a balance of opinion in Russia's favour.
He claimed that, at the G20 dinner on Syria, only four countries - France, Turkey, Canada and Saudi Arabia (plus a British prime minister rebuffed by his own parliament) - had backed America.
Whereas siding with Russia in rejecting military strikes on Syria, he says, were seven nations: China, India, Indonesia, Argentina and Brazil, as well as South Africa and Italy.

Start Quote

The statement was carefully crafted to omit the controversial crux of the American plan: punitive airstrikes on Syria, to be led by the US, quite possibly without UN backing”
Yet not all the Russian president's views on Syria were endorsed by other G20 leaders.
Who else in St Petersburg publically declared, as he did, that Syria's "so-called chemical weapons attack" was in fact "a provocation staged by rebels, in hope of winning extra backing from their foreign backers"?
In making that categorical claim, the Russian leader left little room for compromise and ended up looking, perhaps, somewhat isolated.
Shifting sands
Meanwhile, President Barack Obama also declared he had enjoyed support from a majority of G20 participants, who were "comfortable" with American claims.
Eleven countries did indeed endorse a joint statementcirculated by the White House
  • to condemn the Syrian chemical weapons attack as a grave violation of the world's rules
  • to agree that the evidence pointed to Syrian government culpability
  • to call for a strong international response.

Syrian rebel (2 September 2013)
Alongside the US were, unsurprisingly, the two keenest cheerleaders when it comes to taking military action, French President Francois Hollande and Britain's David Cameron.
All other signatories were also longstanding US allies from around the world: Australia and Canada; from Asia, Japan and South Korea; from the Muslim world, Turkey and Saudi Arabia; and, from Europe, Spain and Italy. The last somehow got itself included in the tally on both sides of the divide.
But, tellingly, the list of Mr Obama's supporters did not include Chancellor Angela Merkel of Germany (perhaps she thought it too risky so close to a federal election).
And the statement was carefully crafted to omit the controversial crux of the American plan: punitive airstrikes on Syria, to be led by the US, quite possibly without UN backing.
'Surrender monkey'
So it is not clear-cut who backs whom - but a muddle.
Two entrenched positions from the United States and Russia bookmark opposite ends of the spectrum, with lots of vague, shifting sands in-between.
President Francois Hollande at the G20 summit (6 Sept 2013)President Hollande said he would wait for the result of a UN investigation
Even the French president - no longer castigated, as was his predecessor in the Iraq days of 2003, as a "cheese-eating surrender monkey" and now embraced as America's new best friend - has begun hedging the conditions under which France would take part in strikes
  • only if they targeted Syrian military installations in order to avoid civilian casualties
  • only once UN inspectors had been given time to report back
  • and should the UN Security Council fail to give authorisation, then so long as a broad international coalition was gathered.
So perhaps the better question to ask when it comes to this row over Syria is: who got what they wanted from this summit, and who walked away empty-handed?
If President Putin's aim was to block US plans for building international support, then he must be feeling quite pleased with himself.
He did his job as a spoiler. And he was reinforced in his views by strong expressions of concern from other quarters.
Raising their voices to object to an American plan they fear would undermine UN authority and unleash more bloodshed through "ill-advised" military action were two powerful figures of global legal and moral authority - the UN Secretary General, and the Catholic Pontiff.
Pope Francis's intervention came in a letter he emailed from Rome to appeal to G20 leaders not to succumb to "futile" violence.
Wobbly mood
And there is little doubt that President Obama left St Petersburg looking somewhat weakened.
Far from winning new converts to his cause, he failed to broaden the international coalition of nations prepared to back military action.
At times he sounded defensive and distracted.
And now he faces an added problem - that the lack of enthusiasm for using force without UN approval shown by some leaders around the G20 table may adversely affect the already wobbly mood of the American public, and therefore the appetite in Congress for military action in Syria.
When asked how he thought the mood at G20 might affect the chances of congressional support for his plan next week, President Obama said it could cut both ways: it might put people off, but it might also make Americans more likely to rally round their president.
Perhaps he will win the endorsement of Congress.
Perhaps, in time, the United States and its allies will build the international coalition they seek.
But it is also possible that we will look back on this G20 gathering in the months to come and say - along with the vote rejecting military action in the British parliament - that this was the moment when the appetite for international intervention for humanitarians goals faltered, and this was the turning point which showed that the rest of the world no longer wants the United States to step in as the world's policeman when other institutions fail to act - however great the crisis or grave the atrocity.


Pope Francis writes letter to President Putin of Russia ahead of G20 summit



(Vatican Radio) Pope Francis has written a letter to President Vladimir Putin of Russia as he prepares to host this year's G20 summit in St. Petersburg. Listen to Lydia O'Kane's report RealAudioMP3 

Below is the full text of the Pope's letter to President Putin.

To His Excellency
Mr Vladimir Putin
President of the Russian Federation


"In the course of this year, you have the honour and the responsibility of presiding over the Group of the twenty largest economies in the world. I am aware that the Russian Federation has participated in this group from the moment of its inception and has always had a positive role to play in the promotion of good governance of the world’s finances, which have been deeply affected by the crisis of 2008.


In today’s highly interdependent context, a global financial framework with its own just and clear rules is required in order to achieve a more equitable and fraternal world, in which it is possible to overcome hunger, ensure decent employment and housing for all, as well as essential healthcare. Your presidency of the G20 this year has committed itself to consolidating the reform of the international financial organizations and to achieving a consensus on financial standards suited to today’s circumstances. However, the world economy will only develop if it allows a dignified way of life for all human beings, from the eldest to the unborn child, not just for citizens of the G20 member states but for every inhabitant of the earth, even those in extreme social situations or in the remotest places. 


From this standpoint, it is clear that, for the world’s peoples, armed conflicts are always a deliberate negation of international harmony, and create profound divisions and deep wounds which require many years to heal. Wars are a concrete refusal to pursue the great economic and social goals that the international community has set itself, as seen, for example, in the Millennium Development Goals. Unfortunately, the many armed conflicts which continue to afflict the world today present us daily with dramatic images of misery, hunger, illness and death. Without peace, there can be no form of economic development. Violence never begets peace, the necessary condition for development. 


The meeting of the Heads of State and Government of the twenty most powerful economies, with two-thirds of the world’s population and ninety per cent of global GDP, does not have international security as its principal purpose. Nevertheless, the meeting will surely not forget the situation in the Middle East and particularly in Syria. It is regrettable that, from the very beginning of the conflict in Syria, one-sided interests have prevailed and in fact hindered the search for a solution that would have avoided the senseless massacre now unfolding. The leaders of the G20 cannot remain indifferent to the dramatic situation of the beloved Syrian people which has lasted far too long, and even risks bringing greater suffering to a region bitterly tested by strife and needful of peace. To the leaders present, to each and every one, I make a heartfelt appeal for them to help find ways to overcome the conflicting positions and to lay aside the futile pursuit of a military solution. Rather, let there be a renewed commitment to seek, with courage and determination, a peaceful solution through dialogue and negotiation of the parties, unanimously supported by the international community. Moreover, all governments have the moral duty to do everything possible to ensure humanitarian assistance to those suffering because of the conflict, both within and beyond the country’s borders. 


Mr President, in the hope that these thoughts may be a valid spiritual contribution to your meeting, I pray for the successful outcome of the G20’s work on this occasion. I invoke an abundance of blessings upon the Summit in Saint Petersburg, upon the participants and the citizens of the member states, and upon the work and efforts of the 2013 Russian Presidency of the G20.
While requesting your prayers, I take this opportunity to assure you, Mr President, of my highest consideration."


From the Vatican, 4 September 2013

(Signed)
Francis



Text from page http://en.radiovaticana.va/news/2013/09/05/pope_francis_writes_letter_to_president_putin_of_russia_ahead_of_g20/en1-725816
of the Vatican Radio website 

Friday, September 6, 2013

A guide to staying secure

http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance

NSA surveillance: A guide to staying secure

The NSA has huge capabilities – and if it wants in to your computer, it's in. With that in mind, here are five ways to stay safe

• Explaining the latest NSA revelations – Q&A
A patron works on his laptop during the Tech Crunch Disrupt conference in San Francisco, California, September 11.
'Trust the math. Encryption is your friend. That's how you can remain secure even in the face of the NSA.' Photograph: Beck Diefenbach/Reuters
Now that we have enough details about how the NSA eavesdrops on the internet, including today's disclosures of the NSA's deliberate weakening of cryptographic systems, we can finally start to figure out how to protect ourselves.
For the past two weeks, I have been working with the Guardian onNSA stories, and have read hundreds of top-secret NSA documents provided by whistleblower Edward Snowden. I wasn't part of today's story – it was in process well before I showed up – but everything I read confirms what the Guardian is reporting.
At this point, I feel I can provide some advice for keeping secure against such an adversary.
The primary way the NSA eavesdrops on internet communications is in the network. That's where their capabilities best scale. They have invested in enormous programs to automatically collect and analyze network traffic. Anything that requires them to attack individual endpoint computers is significantly more costly and risky for them, and they will do those things carefully and sparingly.
Leveraging its secret agreements with telecommunications companies – all the US and UK ones, and many other "partners" around the world – the NSA gets access to the communications trunks that move internet traffic. In cases where it doesn't have that sort of friendly access, it does its best to surreptitiously monitor communications channels: tapping undersea cables, intercepting satellite communications, and so on.
That's an enormous amount of data, and the NSA has equivalentlyenormous capabilities to quickly sift through it all, looking for interesting traffic. "Interesting" can be defined in many ways: by the source, the destination, the content, the individuals involved, and so on. This data is funneled into the vast NSA system for future analysis.
The NSA collects much more metadata about internet traffic: who is talking to whom, when, how much, and by what mode of communication. Metadata is a lot easier to store and analyze than content. It can be extremely personal to the individual, and is enormously valuable intelligence.
The Systems Intelligence Directorate is in charge of data collection, and the resources it devotes to this is staggering. I read status report after status report about these programs, discussing capabilities, operational details, planned upgrades, and so on. Each individual problem – recovering electronic signals from fiber, keeping up with the terabyte streams as they go by, filtering out the interesting stuff – has its own group dedicated to solving it. Its reach is global.
The NSA also attacks network devices directly: routers, switches, firewalls, etc. Most of these devices have surveillance capabilitiesalready built in; the trick is to surreptitiously turn them on. This is an especially fruitful avenue of attack; routers are updated less frequently, tend not to have security software installed on them, and are generally ignored as a vulnerability.
The NSA also devotes considerable resources to attacking endpoint computers. This kind of thing is done by its TAO –Tailored Access Operations – group. TAO has a menu of exploits it can serve up against your computer – whether you're running Windows, Mac OS, Linux, iOS, or something else – and a variety of tricks to get them on to your computer. Your anti-virus software won't detect them, and you'd have trouble finding them even if you knew where to look. These are hacker tools designed by hackers with an essentially unlimited budget. What I took away from reading the Snowden documents was that if the NSA wants in to your computer, it's in. Period.
The NSA deals with any encrypted data it encounters more by subverting the underlying cryptography than by leveraging any secret mathematical breakthroughs. First, there's a lot of bad cryptography out there. If it finds an internet connection protected by MS-CHAP, for example, that's easy to break and recover the key. It exploits poorly chosen user passwords, using the samedictionary attacks hackers use in the unclassified world.
As was revealed today, the NSA also works with security product vendors to ensure that commercial encryption products are broken in secret ways that only it knows about. We know this has happened historically: CryptoAG and Lotus Notes are the most public examples, and there is evidence of a back door in Windows. A few people have told me some recent stories about their experiences, and I plan to write about them soon. Basically, the NSA asks companies to subtly change their products in undetectable ways: making the random number generator less random, leaking the key somehow, adding a common exponent to a public-key exchange protocol, and so on. If the back door is discovered, it's explained away as a mistake. And as we now know, the NSA has enjoyed enormous success from this program.
TAO also hacks into computers to recover long-term keys. So if you're running a VPN that uses a complex shared secret to protect your data and the NSA decides it cares, it might try to steal that secret. This kind of thing is only done against high-value targets.
How do you communicate securely against such an adversary? Snowden said it in an online Q&A soon after he made his first document public: "Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on."
I believe this is true, despite today's revelations and tantalizing hints of "groundbreaking cryptanalytic capabilities" made by James Clapper, the director of national intelligence in another top-secret document. Those capabilities involve deliberately weakening the cryptography.
Snowden's follow-on sentence is equally important: "Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it."
Endpoint means the software you're using, the computer you're using it on, and the local network you're using it in. If the NSA can modify the encryption algorithm or drop a Trojan on your computer, all the cryptography in the world doesn't matter at all. If you want to remain secure against the NSA, you need to do your best to ensure that the encryption can operate unimpeded.
With all this in mind, I have five pieces of advice:
1) Hide in the network. Implement hidden services. Use Tor to anonymize yourself. Yes, the NSA targets Tor users, but it's work for them. The less obvious you are, the safer you are.
2) Encrypt your communications. Use TLS. Use IPsec. Again, while it's true that the NSA targets encrypted connections – and it may have explicit exploits against these protocols – you're much better protected than if you communicate in the clear.
3) Assume that while your computer can be compromised, it would take work and risk on the part of the NSA – so it probably isn't. If you have something really important, use an air gap. Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good.
4) Be suspicious of commercial encryption software, especially from large vendors. My guess is that most encryption products from large US companies have NSA-friendly back doors, and many foreign ones probably do as well. It's prudent to assume that foreign products also have foreign-installed backdoors. Closed-source software is easier for the NSA to backdoor than open-source software. Systems relying on master secrets are vulnerable to the NSA, through either legal or more clandestine means.
5) Try to use public-domain encryption that has to be compatible with other implementations. For example, it's harder for the NSA to backdoor TLS than BitLocker, because any vendor's TLS has to be compatible with every other vendor's TLS, while BitLocker only has to be compatible with itself, giving the NSA a lot more freedom to make changes. And because BitLocker is proprietary, it's far less likely those changes will be discovered. Prefer symmetric cryptography over public-key cryptography. Prefer conventional discrete-log-based systems over elliptic-curve systems; the latter have constants that the NSA influences when they can.
Since I started working with Snowden's documents, I have been using GPGSilent CircleTailsOTRTrueCryptBleachBit, and a few other things I'm not going to write about. There's an undocumented encryption feature in my Password Safe program from the command line); I've been using that as well.
I understand that most of this is impossible for the typical internet user. Even I don't use all these tools for most everything I am working on. And I'm still primarily on Windows, unfortunately. Linux would be safer.
The NSA has turned the fabric of the internet into a vast surveillance platform, but they are not magical. They're limited by the same economic realities as the rest of us, and our best defense is to make surveillance of us as expensive as possible.
Trust the math. Encryption is your friend. Use it well, and do your best to ensure that nothing can compromise it. That's how you can remain secure even in the face of the NSA.