NSA Caught With The Cookies
zardo writes "The associated press is reporting that the NSA is putting cookies on visiting computers. Apparently it is unlawful for the government to put anything but a session cookie out unless it's expressed in the site's privacy policy." From the article: "Don Weber, an NSA spokesman, said in a statement Wednesday that the cookie use resulted from a recent software upgrade. Normally, the site uses temporary, permissible cookies that are automatically deleted when users close their Web browsers, he said, but the software in use shipped with persistent cookies already on. ... In a 2003 memo, the White House's Office of Management and Budget prohibits federal agencies from using persistent cookies _ those that aren't automatically deleted right away _ unless there is a 'compelling need.' A senior official must sign off on any such use, and an agency that uses them must disclose and detail their use in its privacy policy."
"So either one or both agencies in question are simply incompetent, or lying to us"
I know, how dare they place a cookie on my machine! No other site in the intarweb does!!
Don't you think you overreacted just a little??
So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?
Never attribute malice to that which can be explained by stupidity.
I don't really think they'd gain much by putting cookies on the machines of web users. If terrorists do come to their site, their IP address will give them away far better than a cookie. Now if anyone finds an image on other sites pointing back to the NSA or CIA, then you may have found your smoking gun.
Javascript + Nintendo DSi = DSiCade
Cookies are easy to delete. This is hardly a "Your Rights Online" issue. Jeez.
yes, because the thing I fear most about the NSA, with their acres of listening stations, underground football fields worth of humming supercomputers, and small armies of intelligence agents, is the cookie that they placed on my computer while browsing their website....
need glasses, anyone?
Ok. Let me get this straight. We don't want our government websites to contain persistent cookies, but every other website in the world (including sites with malicious intent) can have persistent cookies? Why is this a big deal? Don't like it? Then delete the cookie or disable cookies alltogether. It's not rocket science.
This is all messed up. We're basically giving more rights to malicious websites than we are to government agencies.
-Nick
"A plan fiendishly clever in its intricacies"- Homer Simpson
seriously...it's a freaking cookie. it's not like doubleclick where hundreds of thousands of websites have an iframe that is capable of reading your cookie and tracking your browsing habits. even if they decide to track it across all government owned websites, it's nothing they couldn't already do with simple logfile analysis.
i'm sure if the NSA wanted to track your every move 1) They already are 2) You don't know it and 3) There isn't anything you can do about it.
"The public does not need to be concerned that the CIA is tracking them. We're a bit busy to be doing that."
;-)
OK, does that quote from the 2002 case seem humorous to anyone else now with the recent revelation of what was keeping them so busy
"reality has a well-known liberal bias" - Steven Colbert
I've now seen a bunch of comments modded down as trolling despite their being reasonable comments by people who just happen not to wear tin foil hats. If this article freaks you out or upsets you and seems like an important rights issue, great! I'm glad you're interested in defending your rights and by extension all of our rights. Thank you! But, don't by modding suppress the opinion of many who feel this isn't some stunning/shocking/scary revelation. That many feel the issue isn't a major one is itself an important thing to know.
As for me, Carnivore and all the recent "unlawful" wire taps scare me, a permanent versus a session cookie, not so much.
Quincy
Don't vote for Eugene Papansanovich for Congress!
First of all, their office of management and budget made this policy. A pencil pusher/bean counter policy that is hard to keep up with in the real world that their IT staff has to follow, not them. I agree 100% with the parent. They probably have a million regulations they have to follow, with many many employees spread all over the map, with software from 3rd parties, with countless people who probably don't even know this policy exists there.
The reality of it is, the CIA/NSA/Whatever has a billion other much more effective ways to track you. Their intention was obviously wasn't to track people, and they immediatly removed it after it was brought to their attention. I hate our current administration, but this is just some fucktard news reporter that is up 'n arms about the wire tapping escipade. I do not agree at all with the wire tapping, but this has ABSOLUTLY NOTHING TO FUCKING DO WITH THAT. I can't believe the reporter is such a fucktard that he couldn't spend 2 minutes to research cookies and what they are. Setting cookies far into the future is the de-facto way to keep a cookie on your computer a long time. Most cookies that aren't set as session cookies are set to dates 10 years or more in the future, way more than the computers expected lifetime. The reporter has no clue what he's talking about and should be slapped like a bitch. I hate reporting like this because then it takes away from things we should be legitimitly concerned with. People get an overflow of bullshit news and many can't pick out the real from the fucktards like this guy.
If an officer ever threatens to taze you, say you have a pacemaker.
So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?
Wow! The fact that you're even asking this is a clear indication that you have never worked in any government entity. All levels of government - federal, state, and local - are loaded with incompetency and attempt to lie to the public whenever such lying is "in the public interest" or covers their asses.
You also seem to have some notion that as soon as you become a government employee that you are going to somehow assume and retain all legal ramifications based on all existing laws just by being hired. Management changes happen. Staff changes happen. The notion that all government employees of all levels will be aware of all rules and regulations regarding all functions is highly naive. For all we know, the installation of this supposed "off-the-shelf" software was the first task of a new, NSA intern in the IT department.
I know that you dislike (hate?) the current administration, but this is absolutely a "mountain out of molehill" scenario in the grand scheme of things.
The Overrated mod is for reversing inappropriate, positive mods, not for voicing disagreement with a post.
If NSA needs a cookie to figure that out (and if Abdul is visiting nsa.gov from Afghanistan and DC), then neither Abdul nor NSA are doing their respective jobs.
I'm going with neglect on the part of the website administrator here. Stupid default settings in applications, plus benign neglect in the brains of users, equals embarassment. Always has, always will. Unless...
~adjusts phase coil on tinfoil hat~ /dev/null /dev/null, and where NSA complied with my orders only under protest.
If, however, I was trying to divert attention from a serious abuse I'd performed, I'd release a story exactly like this. It's got the word "cookie", which is about as high-tech as Joe Sixpack ever gets about security, so he can get all upset -- and it's simultaneously a non-issue, which means everyone from the Blogosphere to Dan Rather can trot out an "expert" to tell Joe Sixpack that if this is the NSA at its most dastardly, then he has nothing to fear even if he's got something to hide
~readjusts phase coils~
and the story I'd release would be the same, whether or not I was NSA, looking to divert attention from the fact that I wanted to trawl through the set of data originally destined for
~tweaks fnord emitter~
or whether I was the Party official who ordered NSA to do stop dumping all that good stuff into
They don't call it the puzzle palace for nothing.
No, we're talking about a cookie. A device used by almost every website in existence. We're talking about some guy running the NSA website not being aware that a memo from the White House's Office of Management and Budget made a guideline (not a law) to not use a universally acceptable website statistical tracking device. I wouldnt even attribute this to stupidity. Just forgot about some silly guideline. Anyone making a big deal out of this is doing so out of total computer illiteracy or being intellectually dishonest as to their true motive for their outrage.
"In the game of life, someone always has to lose. To me, if life were fair, that someone would always be Oklahoma." -DKR