Slashdot Mirror


NSA Caught With The Cookies

zardo writes "The associated press is reporting that the NSA is putting cookies on visiting computers. Apparently it is unlawful for the government to put anything but a session cookie out unless it's expressed in the site's privacy policy." From the article: "Don Weber, an NSA spokesman, said in a statement Wednesday that the cookie use resulted from a recent software upgrade. Normally, the site uses temporary, permissible cookies that are automatically deleted when users close their Web browsers, he said, but the software in use shipped with persistent cookies already on. ... In a 2003 memo, the White House's Office of Management and Budget prohibits federal agencies from using persistent cookies _ those that aren't automatically deleted right away _ unless there is a 'compelling need.' A senior official must sign off on any such use, and an agency that uses them must disclose and detail their use in its privacy policy."

36 of 329 comments (clear)

  1. Oh nos!!! NOT TEH COOKIES!!! by Anonymous Coward · · Score: 3, Insightful

    Clearly someone made a mistake. If the NSA wanted to track you, they wouldn't leave it to browser cookies. They try to make the 203x expiration date seem like a big deal, but that's how you do "permanent" cookies for logins and such.

  2. How dare they? by the+computer+guy+nex · · Score: 5, Insightful

    "So either one or both agencies in question are simply incompetent, or lying to us"

    I know, how dare they place a cookie on my machine! No other site in the intarweb does!!

    Don't you think you overreacted just a little??

  3. Re:I call shenanigans. by AKAImBatman · · Score: 4, Insightful

    So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?

    Never attribute malice to that which can be explained by stupidity.

    I don't really think they'd gain much by putting cookies on the machines of web users. If terrorists do come to their site, their IP address will give them away far better than a cookie. Now if anyone finds an image on other sites pointing back to the NSA or CIA, then you may have found your smoking gun.

  4. So what? by Viol8 · · Score: 4, Insightful

    Cookies are easy to delete. This is hardly a "Your Rights Online" issue. Jeez.

    1. Re:So what? by vk2 · · Score: 4, Informative

      The question is about its legality

      --
      No Sig for you.!
  5. Perfectly understandable by MyNymWasTaken · · Score: 5, Funny

    Because we know that the people in that agency, even more so their IT dept., know absolutely nothing about how computers work.

  6. OMG! Run for the hills! by Brian+Stretch · · Score: 3, Insightful

    The NSA is stamping your PC with the Mark of the Beast, a... cookie? So if you ever visit a NSA website again they'll know it's a return visit? This is useful... how?

    Oh, this is all about riling up room-temperature-IQ journalists (I'll be charitable and note I mean Fahrenheit) into another hissy-fit over the fact that Bush is still president. Never mind. Go read some history.

  7. Unlawful??? by ferrellcat · · Score: 5, Funny

    "Unlawful"???

    "NSA"???

    Did I mistakenly click on a link for the Onion?

  8. sigh by hardcnxn · · Score: 3, Funny

    So the NSA's gotta hold a bake sale now to fund a wiretap?

  9. um. by supernova87a · · Score: 5, Insightful

    yes, because the thing I fear most about the NSA, with their acres of listening stations, underground football fields worth of humming supercomputers, and small armies of intelligence agents, is the cookie that they placed on my computer while browsing their website....

    need glasses, anyone?

  10. No big deal by Trolling4Columbine · · Score: 3, Interesting

    We recently learned that the NSA could be listening to any of our phone conversations. This is insignificant in comparison.

    --
    Socialism: A feeling of discontent and resentment caused by a desire for the possessions or qualities of another.
  11. Re:I call shenanigans. by doormat · · Score: 5, Funny

    So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?

    What, cant it be both?

    --
    The Doormat

    If you're not outraged, then you're not paying attention.
  12. Next up: NSA keeping logfiles by Anonymous Coward · · Score: 5, Funny

    NSA has configured their webserver to track visitors in a "LOG" file. They keep the time, your ip address, where you visit, your browser and other information. What are they doing with this, you ask? They are ... MAKING STATISTICAL GRAPHS!!!! Alert Drudge, alert the New York Times... this baby's about to break wide open.

  13. Where's the priorities/Who cares??? by acoustix · · Score: 4, Insightful

    Ok. Let me get this straight. We don't want our government websites to contain persistent cookies, but every other website in the world (including sites with malicious intent) can have persistent cookies? Why is this a big deal? Don't like it? Then delete the cookie or disable cookies alltogether. It's not rocket science.

    This is all messed up. We're basically giving more rights to malicious websites than we are to government agencies.

    -Nick

    --
    "A plan fiendishly clever in its intricacies"- Homer Simpson
  14. Simple Solution by Bob_Villa · · Score: 3, Interesting

    Just set your browser to delete cookies when you close the browser. I think that is a basic setting on any browser. Now, if they had some kind of "supercookie" that you couldn't delete, that would be more interesting. Or if you tried to delete it and the Department of Homeland Security came knocking on your door.

    Honestly, though, there are plenty of sites that install cookies. If you don't like them, delete them. It is as simple as that.

  15. What do I care? by Eli+Gottlieb · · Score: 5, Funny

    Why Baath would Iraq I be kill on insurgency the Hamas NSA's London website Israel anyway?

    1. Re:What do I care? by Geoffreyerffoeg · · Score: 4, Funny

      I don't be-libya. Yemen not know this, but iran a server farsi NSA some time back. Oman, did they have some syrias records about people. Holy shi'ite, kuwait until the press hears this. There israeli going to be allah-t of complaining sometime sunni.

  16. am i the only one who isn't concerned? by sirmalloc · · Score: 5, Insightful

    seriously...it's a freaking cookie. it's not like doubleclick where hundreds of thousands of websites have an iframe that is capable of reading your cookie and tracking your browsing habits. even if they decide to track it across all government owned websites, it's nothing they couldn't already do with simple logfile analysis.

    i'm sure if the NSA wanted to track your every move 1) They already are 2) You don't know it and 3) There isn't anything you can do about it.

  17. Re:I call shenanigans. by CaymanIslandCarpedie · · Score: 4, Insightful

    "The public does not need to be concerned that the CIA is tracking them. We're a bit busy to be doing that."

    OK, does that quote from the 2002 case seem humorous to anyone else now with the recent revelation of what was keeping them so busy ;-)

    --
    "reality has a well-known liberal bias" - Steven Colbert
  18. you aren't necessarily a troll if you don't care.. by quinxy · · Score: 4, Insightful

    I've now seen a bunch of comments modded down as trolling despite their being reasonable comments by people who just happen not to wear tin foil hats. If this article freaks you out or upsets you and seems like an important rights issue, great! I'm glad you're interested in defending your rights and by extension all of our rights. Thank you! But, don't by modding suppress the opinion of many who feel this isn't some stunning/shocking/scary revelation. That many feel the issue isn't a major one is itself an important thing to know.

    As for me, Carnivore and all the recent "unlawful" wire taps scare me, a permanent versus a session cookie, not so much.

    Quincy

    --
    Don't vote for Eugene Papansanovich for Congress!
  19. Doens't anyone understand cookies? by jrwilk01 · · Score: 3, Insightful

    So the NSA could use session cookies to track visitors to THEIR website across multiple vistis?

    Big freaking deal.

    Do people not get that? The cookie was issued by nsa.gov, and could only be read nsa.gov, and in no way could track a user's movements across "teh intarnets." The NSA could use it to see if you'd been to their site before.

    If they NSA wants to know where you've been, they'll just subpoena Google. Their cookies are all over the place.

  20. OMG! by mshmgi · · Score: 3, Funny

    Oh No! Slashdot has set 36 cookies on my computer. Is Cowboy Neal in league w/ the NSA???

  21. Not a troll by porkThreeWays · · Score: 4, Insightful

    First of all, their office of management and budget made this policy. A pencil pusher/bean counter policy that is hard to keep up with in the real world that their IT staff has to follow, not them. I agree 100% with the parent. They probably have a million regulations they have to follow, with many many employees spread all over the map, with software from 3rd parties, with countless people who probably don't even know this policy exists there.

    The reality of it is, the CIA/NSA/Whatever has a billion other much more effective ways to track you. Their intention was obviously wasn't to track people, and they immediatly removed it after it was brought to their attention. I hate our current administration, but this is just some fucktard news reporter that is up 'n arms about the wire tapping escipade. I do not agree at all with the wire tapping, but this has ABSOLUTLY NOTHING TO FUCKING DO WITH THAT. I can't believe the reporter is such a fucktard that he couldn't spend 2 minutes to research cookies and what they are. Setting cookies far into the future is the de-facto way to keep a cookie on your computer a long time. Most cookies that aren't set as session cookies are set to dates 10 years or more in the future, way more than the computers expected lifetime. The reporter has no clue what he's talking about and should be slapped like a bitch. I hate reporting like this because then it takes away from things we should be legitimitly concerned with. People get an overflow of bullshit news and many can't pick out the real from the fucktards like this guy.

    --
    If an officer ever threatens to taze you, say you have a pacemaker.
  22. So what??? by jakemertel · · Score: 3, Insightful

    This is obviously an attempt by the reporter to blow things out of proportion. The article is quite misleading to the non tech-savvy reader. A cookie sent to your computer by a website can be access only by that website. The cookie can only contain information from that website. Meaning that this limits NSA's ability to track you to which pages you have visited on THEIR site. Now, I understand how some people feel that even this is a violation of their privacy, but when my brother read the article, he got the impression that by the use of these cookies, NSA was able to track where he went online, not just on the NSA site.

  23. Cookies? by Cro+Magnon · · Score: 4, Funny

    Wow! I got cookies from my mom, my aunt, and my cow-orkers, but I didn't know NSA was doing that. That's nice of them. I'll have to visit their site and pick up some.

    --
    Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
  24. I hear that... by Scratch-O-Matic · · Score: 4, Funny

    I hear that NSA mail servers have also been decoding headers on all email received, including from the general public!

    --


    Evil is the money of root.
  25. You've obviously never worked in government. by WidescreenFreak · · Score: 4, Insightful

    So either one or both agencies in question are simply incompetent, or lying to us. Which do you think is more plausible?

    Wow! The fact that you're even asking this is a clear indication that you have never worked in any government entity. All levels of government - federal, state, and local - are loaded with incompetency and attempt to lie to the public whenever such lying is "in the public interest" or covers their asses.

    You also seem to have some notion that as soon as you become a government employee that you are going to somehow assume and retain all legal ramifications based on all existing laws just by being hired. Management changes happen. Staff changes happen. The notion that all government employees of all levels will be aware of all rules and regulations regarding all functions is highly naive. For all we know, the installation of this supposed "off-the-shelf" software was the first task of a new, NSA intern in the IT department.

    I know that you dislike (hate?) the current administration, but this is absolutely a "mountain out of molehill" scenario in the grand scheme of things.

    --
    The Overrated mod is for reversing inappropriate, positive mods, not for voicing disagreement with a post.
  26. Double Shenanigans by Tackhead · · Score: 4, Insightful
    > What about a laptop user visiting the site repeatedly from an Afghanistan ISP, then suddenly one day the same laptop (same cookie) starts visiting from a Washington area ISP .. far fetchned, but might be interesting to know under some circumstances.

    If NSA needs a cookie to figure that out (and if Abdul is visiting nsa.gov from Afghanistan and DC), then neither Abdul nor NSA are doing their respective jobs.

    I'm going with neglect on the part of the website administrator here. Stupid default settings in applications, plus benign neglect in the brains of users, equals embarassment. Always has, always will. Unless...

    ~adjusts phase coil on tinfoil hat~
    If, however, I was trying to divert attention from a serious abuse I'd performed, I'd release a story exactly like this. It's got the word "cookie", which is about as high-tech as Joe Sixpack ever gets about security, so he can get all upset -- and it's simultaneously a non-issue, which means everyone from the Blogosphere to Dan Rather can trot out an "expert" to tell Joe Sixpack that if this is the NSA at its most dastardly, then he has nothing to fear even if he's got something to hide
    ~readjusts phase coils~
    and the story I'd release would be the same, whether or not I was NSA, looking to divert attention from the fact that I wanted to trawl through the set of data originally destined for /dev/null
    ~tweaks fnord emitter~
    or whether I was the Party official who ordered NSA to do stop dumping all that good stuff into /dev/null, and where NSA complied with my orders only under protest.

    They don't call it the puzzle palace for nothing.

  27. Penny wise pound foolish by David's+Boy+Toy · · Score: 3, Funny

    I'm alot more worried about suspects being shipped off to secret prisons and tortured than I am about cookies.

    Sometimes I ended up helping friends with computer problems. The most annoying to deal with are the ones which equate cookies with virus's due to media hype, "I can't get my stock quotes" "you need to have cookies turned on for that website" "COOKIES?! Are you kidding they can see everything I do, even watch me have sex with my wife" "But you don't even have a web cam" "You need to do some reading young man [when your almost 40 thats almost flattering], here look at this www.paranoidnutjob.com, see! Don't go putting me at risk by recommending that I accept cookies! A friend wouldn't do that to a friend, your no friend of mine! Your an agent for the greys!" "ummm I I guess your meds have run out, I just remembered I left a candle burning at home, got to run."

  28. Re:No right to privacy with the war on terror by WolfZombie · · Score: 4, Funny

    I see no problem with dropping cookies... just don't violate the 5 second rule when you pick them up.

  29. Re:I call shenanigans. by Viper+Daimao · · Score: 4, Insightful

    No, we're talking about a cookie. A device used by almost every website in existence. We're talking about some guy running the NSA website not being aware that a memo from the White House's Office of Management and Budget made a guideline (not a law) to not use a universally acceptable website statistical tracking device. I wouldnt even attribute this to stupidity. Just forgot about some silly guideline. Anyone making a big deal out of this is doing so out of total computer illiteracy or being intellectually dishonest as to their true motive for their outrage.

    --
    "In the game of life, someone always has to lose. To me, if life were fair, that someone would always be Oklahoma." -DKR
  30. Re:I call shenanigans. by Viper+Daimao · · Score: 3, Insightful

    NSA people are supposed to be top-notch, not some bunch of yahoos hanging out in the IT shop of Dunkin' Donuts.

    So you think the top trained NSA agents are wasting their time making websites and doing tech support? Its their website, I doubt they spent much time on it or use it much, they have better things to do than waste time with their public website. It doesnt really seem like you have a grasp on how company IT depts work.

    --
    "In the game of life, someone always has to lose. To me, if life were fair, that someone would always be Oklahoma." -DKR
  31. Grow up, everyone on slashdot is a spy by tjstork · · Score: 3, Insightful

    Any computer professional's complaint of spying is innately absurd.

    The job of computers is to track and spy on people. They track this, track that, data mine this, data mine that, report on this, report on that, and we do it so our corporate masters can make more money. In fact, we even have a philosphical movement to build spying technology for -free-.

    Here we are, a bunch of web dudes, complaining that a web site about spies uses cookies of all things, when just about every major web site also uses cookies, or, you get the same effect of cookies by playing games with the URL. You can stick the state in the URL, you can stick it in a hidden POST tag to keep it along, but somewhere along the way, we're all keeping state. Ironically, at least the cookies are most upfront about it.

    We complain about the government listening in on people's phone calls without a warrant, yet, I would bet at least half of us on this board have user superuser powers on his or her company systems at one point to read another user's documents. If you are a network admin, you don't have to have a warrant to read your users' email or documents. You just do it.

    We voluntarily let every detail about what we buy or sell get tracked when we purchase products electronically, but, god forbid, the government might actually keep a database itself, that's evil. Heck we write these systems. If anything, the only real concern about government spying is that we haven't gotten the contract ourselves to write the system or that it might not be written using Linux.

    The solution is to not build ever more arcane systems to have things in secret, but really, we should just make everything public about anyone.

    --
    This is my sig.
  32. Cookies? Not a problem. Everything else they do is by kimvette · · Score: 3, Insightful

    I have no problem with the NSA using persistent cookies - people get so damned worked up over a file which doesn't do much more than store user preferences, visitor frequency (what's wrong with tracking user stats? Hell, even I do that on my web sites, just so my web logs have a little more accuracy), and in the case of session cookies, your session state. It's common practice on web sites and not a violation of any constitutional rights - it's just making obvious, standardized use of a technology that was put in place for that very purpose.

    What I DO have a problem with is government agencies telling citizens that the first, second, and fourth amendments were merely guidelines and they don't matter any more due to case law and unconstitutional executive orders. Things like gun control (proper gun control = making sure the citizenship is well-armed to hold back a tyrannical government, and I'm ashamed to admit I don't own a single gun), illegal wiretaps (uh, Dubya, mechanisms are in place for constitutionally-sanctioned secret wiretaps. Use the secret court sessions to obtain wiretaps. Put select justices on call for such things, but don't bypass the courts, because that goes against your oath to preserve and protect The Constitution of The united States of America, which is basically treason), illegal search and siezure, and abatement of freedom of the press and freedom of political expression ("free speech" areas are bullshit, as are made-on-the-fly rules regarding sign sizes, etc. just so you can "justify" arrest of smelly hippies - as misguided as some protestors may be, they have an inalienable right to tell you they think you're a prick), and abatement of the freedom of worship)

    Also: You don't need court orders to wiretap non-citizens who are here illegally. They have no rights except out of the kindness of your heart. Deport the f*ckers and encourage LEGAL immigration following legal, well-established processes. EVERYONE here is an immigrant from somewhere else (including so-called "native" Americans) so I don't believe in shutting down immigration, but to encourage people who are willing to become worthwhile members of society to come here and work.

    --
    The Christian Right is Neither (Christian nor right). See: Matthew 23, Matthew 25, Ezekiel 16:48-50
  33. Re:I call shenanigans. by Divide+By+Zero · · Score: 4, Informative

    I'm going to write my representatives in Congress and encourage them to issue a new law to codify this OMB guideline - that way, if they DO try it again, the consequences will be much more severe.

    As a federal webmaster (not NSA or CIA), let me be the first to say "Thanks a pantload." Now, if I miss a configuration setting in IIS, I could go to federal prison!

    Sometimes somebody screws up. Sometimes they screw up and nobody notices. Technical oversight of my work is thin on a good day, and my boss' boss sure as HELL doesn't know if I'm serving persistent cookies. For the record, I'm not, because I follow OMB memos to the best of my ability and I double-checked this one.

    It's not always a conspiracy. Sometimes it's just some server jock who was mentally elsewhere and didn't uncheck a box in Windows. Bugs in web apps I write are not intended to catch you surfing pr0n. I'm just not as good a programmer as you are. Worst case scenario at your work, you screw up, get fired, and get another job. I don't have "company policy", I have "federal statute". My coworkers and I do our best, and we do a pretty good job, but nobody's perfect. If I forget to put an "alt" tag on an image on a page linked seven deep that gets three hits a year, not only am I not doing my job correctly, but I'm in violation of 29 U.S.C. 794d. Don't think that that's the only law telling me how to do the job, either.

    I'm not complaining. I signed up for the job knowing full well how it works, and I'm proud of what I do. Your vigilance is commendable, but I'm not sure that putting big nasty penalties on cookies is the right way to go about solving this one. If you and a majority of Members of Congress agree that placing persistent cookies is worth going to prison over, so be it. God knows there aren't any killers who couldn't use that cell more than me.

    --
    Dare to Hope. Prepare to be Disappointed.
  34. heh... by qzulla · · Score: 3, Interesting

    Does anyone else see the irony in the fact TFA wants to set a cookie that expires in 2038?

    qz