NSA Caught With The Cookies
zardo writes "The associated press is reporting that the NSA is putting cookies on visiting computers. Apparently it is unlawful for the government to put anything but a session cookie out unless it's expressed in the site's privacy policy." From the article: "Don Weber, an NSA spokesman, said in a statement Wednesday that the cookie use resulted from a recent software upgrade. Normally, the site uses temporary, permissible cookies that are automatically deleted when users close their Web browsers, he said, but the software in use shipped with persistent cookies already on. ... In a 2003 memo, the White House's Office of Management and Budget prohibits federal agencies from using persistent cookies _ those that aren't automatically deleted right away _ unless there is a 'compelling need.' A senior official must sign off on any such use, and an agency that uses them must disclose and detail their use in its privacy policy."
Clearly someone made a mistake. If the NSA wanted to track you, they wouldn't leave it to browser cookies. They try to make the 203x expiration date seem like a big deal, but that's how you do "permanent" cookies for logins and such.
"So either one or both agencies in question are simply incompetent, or lying to us"
I know, how dare they place a cookie on my machine! No other site in the intarweb does!!
Don't you think you overreacted just a little??
So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?
Never attribute malice to that which can be explained by stupidity.
I don't really think they'd gain much by putting cookies on the machines of web users. If terrorists do come to their site, their IP address will give them away far better than a cookie. Now if anyone finds an image on other sites pointing back to the NSA or CIA, then you may have found your smoking gun.
Javascript + Nintendo DSi = DSiCade
Cookies are easy to delete. This is hardly a "Your Rights Online" issue. Jeez.
The NSA is stamping your PC with the Mark of the Beast, a... cookie? So if you ever visit a NSA website again they'll know it's a return visit? This is useful... how?
Oh, this is all about riling up room-temperature-IQ journalists (I'll be charitable and note I mean Fahrenheit) into another hissy-fit over the fact that Bush is still president. Never mind. Go read some history.
yes, because the thing I fear most about the NSA, with their acres of listening stations, underground football fields worth of humming supercomputers, and small armies of intelligence agents, is the cookie that they placed on my computer while browsing their website....
need glasses, anyone?
ROFL
would be a perfect article for the onion, wouldn't it?
Ok. Let me get this straight. We don't want our government websites to contain persistent cookies, but every other website in the world (including sites with malicious intent) can have persistent cookies? Why is this a big deal? Don't like it? Then delete the cookie or disable cookies alltogether. It's not rocket science.
This is all messed up. We're basically giving more rights to malicious websites than we are to government agencies.
-Nick
"A plan fiendishly clever in its intricacies"- Homer Simpson
How come if the government breaks the law, they get off with stopping the action and an apology? I should try this when they accuse me of a crime.
"Sorry, officer. You're right, I was going to sell these 30 pounds of crack to some schoolkids. But it's okay, as long as I throw it away and promise not to do it again. Right?"
seriously...it's a freaking cookie. it's not like doubleclick where hundreds of thousands of websites have an iframe that is capable of reading your cookie and tracking your browsing habits. even if they decide to track it across all government owned websites, it's nothing they couldn't already do with simple logfile analysis.
i'm sure if the NSA wanted to track your every move 1) They already are 2) You don't know it and 3) There isn't anything you can do about it.
We're talking about a regime in the federal government which has made, "oops, well, the ends justify the means" a policy they depend upon.
I don't really think they'd gain much by putting cookies on the machines of web users. If terrorists do come to their site, their IP address will give them away far better than a cookie. Now if anyone finds an image on other sites pointing back to the NSA or CIA, then you may have found your smoking gun.
This is all rationalizing. The fact of the matter is they're using the "oo, i'm a baddd widdo boy =)" defense.
A feeling of having made the same mistake before: Deja Foobar
"The public does not need to be concerned that the CIA is tracking them. We're a bit busy to be doing that."
;-)
OK, does that quote from the 2002 case seem humorous to anyone else now with the recent revelation of what was keeping them so busy
"reality has a well-known liberal bias" - Steven Colbert
I've now seen a bunch of comments modded down as trolling despite their being reasonable comments by people who just happen not to wear tin foil hats. If this article freaks you out or upsets you and seems like an important rights issue, great! I'm glad you're interested in defending your rights and by extension all of our rights. Thank you! But, don't by modding suppress the opinion of many who feel this isn't some stunning/shocking/scary revelation. That many feel the issue isn't a major one is itself an important thing to know.
As for me, Carnivore and all the recent "unlawful" wire taps scare me, a permanent versus a session cookie, not so much.
Quincy
Don't vote for Eugene Papansanovich for Congress!
Security and encryption - to protect us from our own government.
Are you...Are you some kind of genius?
No, ma'am, I'm just a regular Slashdot reader.
So the NSA could use session cookies to track visitors to THEIR website across multiple vistis?
Big freaking deal.
Do people not get that? The cookie was issued by nsa.gov, and could only be read nsa.gov, and in no way could track a user's movements across "teh intarnets." The NSA could use it to see if you'd been to their site before.
If they NSA wants to know where you've been, they'll just subpoena Google. Their cookies are all over the place.
Maybe I'm lacking some information on cookie spcifications, but I was under the impression that cookies can only be read/written by the web site that you are visiting unless there are links to other sites, such as advertising sites, that manipulate cookies. This is of course how you can visit a site but then get cookies from 24/7 media, AdServer, and others. But the cookies cannot be arbitrarily read by other web sites unless there is some kind of partnership going on. Again, this is the impression that I was under regarding general cookie use. So, if that's correct the NSA cookie is not even an issue when you visit other web sites unless they're specifically looking for it -- like any of them would.
/. But this to me is nothing more than unnecessarily putting some fuel on an already smouldering dislike for the current administration, courtesy of an ill-informed and/or careless IT person at the NSA, in the hopes that a large, anti-NSA and more generally anti-current-administration fire will grow out of it.
Okay, so the NSA puts a permanent cookie on the system. Why is this an issue? It's not a security breach; it's not a cross-advertising cookie that tracks where you go. There's not one of us who has installed software and went over every configuration setting with a fine-toothed comb, particularly with off-the-shelf software, at one time or another. Cookies are also easily removed and can be blocked on future visits. Of course, the web logs themselves can get the IP address of everyone who visits, so even if you block cookies, the NSA can still tell exactly when a specific IP address contacted their site.
I realize that the U.S. government, particularly the current administration, is not a favorite of the Slashdot crowd and that this will be (and has already been) touted as "yet another flagrant policy violation!!!" by political opportunists here on
Just my two cents. Convert to your currency as necessary.
The Overrated mod is for reversing inappropriate, positive mods, not for voicing disagreement with a post.
First of all, their office of management and budget made this policy. A pencil pusher/bean counter policy that is hard to keep up with in the real world that their IT staff has to follow, not them. I agree 100% with the parent. They probably have a million regulations they have to follow, with many many employees spread all over the map, with software from 3rd parties, with countless people who probably don't even know this policy exists there.
The reality of it is, the CIA/NSA/Whatever has a billion other much more effective ways to track you. Their intention was obviously wasn't to track people, and they immediatly removed it after it was brought to their attention. I hate our current administration, but this is just some fucktard news reporter that is up 'n arms about the wire tapping escipade. I do not agree at all with the wire tapping, but this has ABSOLUTLY NOTHING TO FUCKING DO WITH THAT. I can't believe the reporter is such a fucktard that he couldn't spend 2 minutes to research cookies and what they are. Setting cookies far into the future is the de-facto way to keep a cookie on your computer a long time. Most cookies that aren't set as session cookies are set to dates 10 years or more in the future, way more than the computers expected lifetime. The reporter has no clue what he's talking about and should be slapped like a bitch. I hate reporting like this because then it takes away from things we should be legitimitly concerned with. People get an overflow of bullshit news and many can't pick out the real from the fucktards like this guy.
If an officer ever threatens to taze you, say you have a pacemaker.
This is obviously an attempt by the reporter to blow things out of proportion. The article is quite misleading to the non tech-savvy reader. A cookie sent to your computer by a website can be access only by that website. The cookie can only contain information from that website. Meaning that this limits NSA's ability to track you to which pages you have visited on THEIR site. Now, I understand how some people feel that even this is a violation of their privacy, but when my brother read the article, he got the impression that by the use of these cookies, NSA was able to track where he went online, not just on the NSA site.
So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?
Wow! The fact that you're even asking this is a clear indication that you have never worked in any government entity. All levels of government - federal, state, and local - are loaded with incompetency and attempt to lie to the public whenever such lying is "in the public interest" or covers their asses.
You also seem to have some notion that as soon as you become a government employee that you are going to somehow assume and retain all legal ramifications based on all existing laws just by being hired. Management changes happen. Staff changes happen. The notion that all government employees of all levels will be aware of all rules and regulations regarding all functions is highly naive. For all we know, the installation of this supposed "off-the-shelf" software was the first task of a new, NSA intern in the IT department.
I know that you dislike (hate?) the current administration, but this is absolutely a "mountain out of molehill" scenario in the grand scheme of things.
The Overrated mod is for reversing inappropriate, positive mods, not for voicing disagreement with a post.
Because it is against the law.
Prosecuting the "lying about blowjobs" was all about maintaining the "rule of law" for Republicans a half-decade ago.
But maintaining the "rule of law" no longer applies with Republican administration? That's what I'm getting from you in your post.
If the NSA did this, they broke the law. Doesn't matter if it is a stupid law. All my conservative friends told me in 1999 that the "rule of law" reigns supreme, no matter how minimal the offense.
Sorry... I'm not letting the Bush-apologists off the hook when the tables are turned.
"I have as much authority as the pope, I just
don't have as many people who believe it" - George Carlin
What's the big deal here?
There's no story and who cares if a site leaves a persistent cookie?
Much more can be obtained by perusing the logfiles on the hosted server.
if you steal from one source, that is plagiarism, if you steal from many, well, that's just research.
If NSA needs a cookie to figure that out (and if Abdul is visiting nsa.gov from Afghanistan and DC), then neither Abdul nor NSA are doing their respective jobs.
I'm going with neglect on the part of the website administrator here. Stupid default settings in applications, plus benign neglect in the brains of users, equals embarassment. Always has, always will. Unless...
~adjusts phase coil on tinfoil hat~ /dev/null /dev/null, and where NSA complied with my orders only under protest.
If, however, I was trying to divert attention from a serious abuse I'd performed, I'd release a story exactly like this. It's got the word "cookie", which is about as high-tech as Joe Sixpack ever gets about security, so he can get all upset -- and it's simultaneously a non-issue, which means everyone from the Blogosphere to Dan Rather can trot out an "expert" to tell Joe Sixpack that if this is the NSA at its most dastardly, then he has nothing to fear even if he's got something to hide
~readjusts phase coils~
and the story I'd release would be the same, whether or not I was NSA, looking to divert attention from the fact that I wanted to trawl through the set of data originally destined for
~tweaks fnord emitter~
or whether I was the Party official who ordered NSA to do stop dumping all that good stuff into
They don't call it the puzzle palace for nothing.
It's not against the law. It's against White House policy, "In a 2003 memo, the White House's Office of Management and Budget prohibits federal agencies from using persistent cookies ... blah blah blah." Wow, so the Bush Administration, whom you are so keen to slam as soon as you see an opening, was who set the policy that those cookies *weren't* supposed to be persistent.
I stole this
Comment is incredibly insightfull. Aside from the fact that if you check your browser there will hundreds to thousands of persistent cookies, Aside from the fact that cookie management is widely regarded to be the responsibility of the user, This is completely a non issue unless someone can proove that the NSA went to the trouble to track the cookies outside of their website.
Once again it prooves the left has gone completely bonkers. If the NIH found that Sarin or BZ could cure cancer the story would read Bush administration makes unwise use of chemical weapons.
So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?
You're kidding, right? NSA and CIA are separate Federal agencies with tens of thousands of employees. Their web masters and IT departments probably pay about as much attention to what the other does as Ford Motor Company & Dodge. And this is hardly the first time that a Federal agency has handed out persistent cookies against policy. Do you think CIA & NSA are in cahoots with the Office of Personnel Management, Ames Laboratory, and Bureau of Labor Statistics?
I think that a more likely and equally plausible explanation is that NSA's sys admins, web developers, and IT staff are in about the same boat as most people in IT: overworked, understaffed, plagued by too many meetings, dealing with more hacking attempts than you could imagine, struggling with a software upgrade, and simply missed flipping one of a growing number of switches in software which changed a relatively minor behavior in the software. (Another possibility is that government employees are all 10 feet tall, super geniuses that never make mistakes. I think previous discussions on Slashdot have largely deprecated that possibility.)
Besides, if you were really concerned about avoiding their scrutiny, you wouldn't visit their web site any way.
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
(Disclaimer: Yes, I am aware that the CIA and the NSA are different agencies. However, that shouldn't preclude one learning from the other's foul-ups.)
Yes, it should. These are huge, independent agencies. (DHS is a mess, there is *no* meaningful interaction, even now). Why would they "learn" from each other? Especially about something so minor. Seriously, I'd much rather the NSA and CIA compare notes about terrorist plots, than constantly coordinate to make sure that they synch up on minor bits of policy. I'm not giving them a license to break the law, just saying that one screwing up should in no way be an indictment of the other.
Then kindly quote the law which was approved by the House, approved by the Senate, and signed by any President that makes the usage of permanent cookies on any government web site a violation of federal law. I know of no law and thus far none of the anti-Bush, or in your apparent case anti-Republican, crowd has been able to bring forth the bill that placed that restriction into law.
Clinton lied under oath. That is a violation of established law. But unless you can bring forth the bill from Congress that made permanent cookies illegal, the phrase "no President is above the law" doesn't apply at all.
The Overrated mod is for reversing inappropriate, positive mods, not for voicing disagreement with a post.
Yes, it's just like them "forbidding government offices from reading caller ID from incoming calls"
It is the principle of the matter.
pre-9/11 some people used to think a minimally invasive government was a good idea. The country was founded on the idea of state and personal autonomy from the government.
technically involving "privacy" issues is the exact same thing as 'actually' involving privacy issues. Potentially invasive laws (or laws that specifically don't prohibit certain behaviors) usually means it is a matter of 'when' and not 'if' they will be abused.
I'll say it again: It is the principle of the matter.
[Fuck Beta]
o0t!
No, we're talking about a cookie. A device used by almost every website in existence. We're talking about some guy running the NSA website not being aware that a memo from the White House's Office of Management and Budget made a guideline (not a law) to not use a universally acceptable website statistical tracking device. I wouldnt even attribute this to stupidity. Just forgot about some silly guideline. Anyone making a big deal out of this is doing so out of total computer illiteracy or being intellectually dishonest as to their true motive for their outrage.
"In the game of life, someone always has to lose. To me, if life were fair, that someone would always be Oklahoma." -DKR
From TFA: The House on Wednesday is expected to adopt the compromise version of a fiscal 2002 Treasury-Postal Service bill, H.R. 2590, that would expand privacy protections for people visiting federal Web sites and provide funds for crime-fighting technology.
It's an article from 2001 that states that the House is expected to adopt this provision. Please provide the document that states that this particular clause not only made it into the bill, but that the bill was approved by both houses of Congress and that President Bush actually signed it.
After that, please show me the test that all government employees have to take proving that they are fluent and fully-versed in the millions upon millions of rules and regulations to which they need to adhere and the ramifications thereof for violating any such rules and ramifications.
I also expect to see that various documents thus proving that all levels of management are also refreshed on a regular basis of the policies and violation ramifications. After all, we would not want them to forget any of the millions of laws and policies that they have to adhere to, would we?
It was wrong when the Republicans went on a witch hunt against Clinton who admitted to breaking the law - lying under oath. Just because the tables are turned does not make it less of a witch hunt nor does it make said witch hunt "less wrong".
The Overrated mod is for reversing inappropriate, positive mods, not for voicing disagreement with a post.
NSA people are supposed to be top-notch, not some bunch of yahoos hanging out in the IT shop of Dunkin' Donuts.
So you think the top trained NSA agents are wasting their time making websites and doing tech support? Its their website, I doubt they spent much time on it or use it much, they have better things to do than waste time with their public website. It doesnt really seem like you have a grasp on how company IT depts work.
"In the game of life, someone always has to lose. To me, if life were fair, that someone would always be Oklahoma." -DKR
"Never attribute malice to that which can be explained by stupidity."
The problem with that is the volume of catastrophic mistakes that seem to "oops" happen over the last several years. When do you stop letting the baby(s) play with the gun? When the baby(s) gets advanced and secret oks and advice from folks who like accidents to happen, and when the baby(s) uses stealth means to acuire the guns anyway, dont you have to wonder at the baby's innocence?
In my opinion you couldnt do this much damage to national wellbeing by accident.
Let's be good parents and put the kids in the playpen, and lock away their access to guns before more accidents "happen".
C.
"Doctor, it's not the voices I hear in MY head, but the voices I hear in YOUR head that really frighten me."
>What we're talking about here, isn't stupidity or lack of seeing a memo. It's Strategic Stupidity
A cookie is pretty obvious, not exactly the high-end technology secret spy stuff. Erasing/blocking it is easy and done everyday. If you would go through all the trouble of having a "hidden agenda/top-secret", why have something that points directly to yourself, easily detected, well-known and is trival to defended against?
And exactly what would they get out of it? You need to have a motive for doing things.
The surprise isn't how often we make bad choices; the surprise is how seldom they defeat us.
Any computer professional's complaint of spying is innately absurd.
The job of computers is to track and spy on people. They track this, track that, data mine this, data mine that, report on this, report on that, and we do it so our corporate masters can make more money. In fact, we even have a philosphical movement to build spying technology for -free-.
Here we are, a bunch of web dudes, complaining that a web site about spies uses cookies of all things, when just about every major web site also uses cookies, or, you get the same effect of cookies by playing games with the URL. You can stick the state in the URL, you can stick it in a hidden POST tag to keep it along, but somewhere along the way, we're all keeping state. Ironically, at least the cookies are most upfront about it.
We complain about the government listening in on people's phone calls without a warrant, yet, I would bet at least half of us on this board have user superuser powers on his or her company systems at one point to read another user's documents. If you are a network admin, you don't have to have a warrant to read your users' email or documents. You just do it.
We voluntarily let every detail about what we buy or sell get tracked when we purchase products electronically, but, god forbid, the government might actually keep a database itself, that's evil. Heck we write these systems. If anything, the only real concern about government spying is that we haven't gotten the contract ourselves to write the system or that it might not be written using Linux.
The solution is to not build ever more arcane systems to have things in secret, but really, we should just make everything public about anyone.
This is my sig.
Gamingmuseum.com: Give your 3D accelerator a rest.
I have no problem with the NSA using persistent cookies - people get so damned worked up over a file which doesn't do much more than store user preferences, visitor frequency (what's wrong with tracking user stats? Hell, even I do that on my web sites, just so my web logs have a little more accuracy), and in the case of session cookies, your session state. It's common practice on web sites and not a violation of any constitutional rights - it's just making obvious, standardized use of a technology that was put in place for that very purpose.
What I DO have a problem with is government agencies telling citizens that the first, second, and fourth amendments were merely guidelines and they don't matter any more due to case law and unconstitutional executive orders. Things like gun control (proper gun control = making sure the citizenship is well-armed to hold back a tyrannical government, and I'm ashamed to admit I don't own a single gun), illegal wiretaps (uh, Dubya, mechanisms are in place for constitutionally-sanctioned secret wiretaps. Use the secret court sessions to obtain wiretaps. Put select justices on call for such things, but don't bypass the courts, because that goes against your oath to preserve and protect The Constitution of The united States of America, which is basically treason), illegal search and siezure, and abatement of freedom of the press and freedom of political expression ("free speech" areas are bullshit, as are made-on-the-fly rules regarding sign sizes, etc. just so you can "justify" arrest of smelly hippies - as misguided as some protestors may be, they have an inalienable right to tell you they think you're a prick), and abatement of the freedom of worship)
Also: You don't need court orders to wiretap non-citizens who are here illegally. They have no rights except out of the kindness of your heart. Deport the f*ckers and encourage LEGAL immigration following legal, well-established processes. EVERYONE here is an immigrant from somewhere else (including so-called "native" Americans) so I don't believe in shutting down immigration, but to encourage people who are willing to become worthwhile members of society to come here and work.
The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
Not, really, as it's happened before. [...]
So either one or both agencies in question are simply incompetent, or lying to us.
I noticed you made a grammatical error above with an unnecessary comma. So are you incompetent or are you just lying to us? False dilemmas suck... try to avoid their use.
Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
>This is the government which is keeping terrabytes of data on everything and wants the ability to snoop and record every packet which goes over the internet.
If they keep track of every packet over the Internet, why do they need cookies?
The surprise isn't how often we make bad choices; the surprise is how seldom they defeat us.
The only motive Slashdotters need for outrage or intellectual dishonesty are 4 letters: B-U-S-H.
Good heavens Miss Sakamoto - you're beautiful!
Congratulations, Divide by Zero! Best post of the day - Somebody throw some mod points his way! Damn, I'd hate to get caught in the middle of the religious wars going on between the Rushies and the MoveOn.Org-ans.... This one should be a +5 insightful.