Slashdot Mirror


FBI Wiretapping Audit Secrets Uncovered Via Ctrl+C

mytrip notes a story in Wired's Threat Level blog on the latest boneheaded government moves with redaction. (We've been discussing redaction follies here for years.) This time it's an FBI report (PDF) on implementing CALEA — you can select text from redacted areas, copy it, and paste into a text editor, as University of Pennsylvania professor Matt Blaze discovered. From Wired: "Once again, supposedly sensitive information blacked out from a government report turns out to be visible by computer experts armed with the Ctrl+C keys — and that information turns out to be not very sensitive after all... [Among] the tidbits considered too sensitive to be aired publicly: The FBI paid Verizon $2,500 apiece to upgrade 1,140 old telephone switches. Oddly the report didn't redact the total amount paid to the telecom — slightly more than $2.9 million dollars — but somehow the bad guys will win if they knew the number of switches and the cost paid."

49 of 231 comments (clear)

  1. Let me guess... by Phyrexicaid · · Score: 4, Funny

    If they were running a website, they would use:
    <FONT
    style="BACKGROUND-COLOR: black">Top Secret!</FONT>

    --
    The meme is dead, long live the meme!
    1. Re:Let me guess... by Slashdot+Suxxors · · Score: 4, Funny

      Come on, at least make your top secret docs standards compliant. :(

    2. Re:Let me guess... by Phyrexicaid · · Score: 5, Funny

      Come on, at least make your top secret docs standards compliant. :(</quote>
      I wanted it to be realistic :P

      --
      The meme is dead, long live the meme!
  2. Too much UNIX for me by mikael_j · · Score: 5, Funny

    The headline and summary made took a minute for me to grasp, I just couldn't understand how you could get data out of something by halting execution.

    Then my brain woke up and I realized they were thinking of the Windows command Ctrl+C which copies the marked text..

    /Mikael

    --
    Greylisting is to SMTP as NAT is to IPv4
    1. Re:Too much UNIX for me by hackstraw · · Score: 5, Funny

      Then my brain woke up and I realized they were thinking of the Windows command Ctrl+C which copies the marked text..

      Right. Me too. I don't use windows, so I think Ctrl+C == SIGINT.

      I saw a similar thing on another article here where they had Ctrl+Z in the article, and that took me a minute to figure out as well. I thought, WTF does suspending a task have to do with anything??? I then had to figure out that Ctrl+Z is the undo command in windows.

    2. Re:Too much UNIX for me by SharpFang · · Score: 5, Funny

      very simply...

      Welcome To FBI Info Booth.
      Please press:
      1 to open contact form
      2 to learn about the organization
      3 to get the latest news
      4 to access the current most wanted list
      5 to access other FBI resources
      Your choice: _ [ctrl+C]
      Terminated.
      root@booth975.fbi.gov# cat ./wiretaps.txt

      --
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    3. Re:Too much UNIX for me by Tim+C · · Score: 4, Informative

      Ctrl+C, Ctrl+X and Ctrl+V were increasingly common shortcuts in Linux apps the last time I used Linux on the desktop, which is going back a good few years now.

      Yes, they still do "different" things in a terminal, but they're by no means "Windows commands" any more.

    4. Re:Too much UNIX for me by Anonymous Coward · · Score: 2, Insightful

      yeah, you're 100%.

      those guys were just involved in a dick-measuring "biggest nerd" contest.

    5. Re:Too much UNIX for me by mikael_j · · Score: 3, Interesting

      I think my problem is that for regular *nix I don't use KDE or Gnome and thus I'm still using what I'm used to (mark + middle click to paste) from when I started using X11, and for macs I find myself either drag'n'dropping or using cmd+c which has become differentiated from ctrl+c in my mind (as I use ctrl+c to shut down processes, not copy data).

      /Mikael

      --
      Greylisting is to SMTP as NAT is to IPv4
    6. Re:Too much UNIX for me by dbitch · · Score: 5, Informative

      These are the IBM Common User Access commands. So, they were never "Windows commands" to begin with.

      Funny how history works, huh?

    7. Re:Too much UNIX for me by sqldr · · Score: 3, Informative

      There's actually two pasteboards. Selecting it puts it into the X11 pasteboard, ctrl+c puts it into the gnome/kde pasteboard. There are differences, eg. the gnome/kde one has metadata and can contain images, links etc. It also seems to be more limitless - pasting 50000 lines from the X11 buffer rarely works.

      It's actually really useful to have two paste buffers in certain issues - ctrl-v to paste one, middle to paste the other.

      --
      I wrote my first program at the age of six, and I still can't work out how this website works.
    8. Re:Too much UNIX for me by Anonymous Coward · · Score: 2, Informative

      those guys were just involved in a dick-measuring "biggest nerd" contest.

      The above explains the run that Home Depot had on tweezers and magnifying glasses.

    9. Re:Too much UNIX for me by _xeno_ · · Score: 4, Informative

      These are the IBM Common User Access commands. So, they were never "Windows commands" to begin with.

      No, they're not. The Wikipedia article even lists the correct keys that actually were in the CUA. They were the ever-so-intuitive:

      Copy: Ctrl-Ins
      Cut: Shift-Del
      Paste: Shift-Ins
      Undo: Alt-Backspace

      These were the CUA shortcuts. The new Ctrl-Z/X/C/V shortcut set was stolen off the Mac, because unlike the CUA set, it makes sense. Unlike the CUA, it's always Control-Something. X and C make perfect sense for Cut and Copy. Z and V make less sense unless you think of them as little icons, in which case the Z is a Zig-Zag backwards and the V is a down-arrow pasting into the document. Ultimately, though, they're used because they're next to each other on the keyboard. All your common edit actions in a nice little row.

      If you want a non-Wikipedia source, you can try this page. The CUA keys still work in most Windows applications, it's just that the Mac keys also work since they don't overlap. Alt-F4 remains as probably the most-used CUA shortcut.

      --
      You are in a maze of twisty little relative jumps, all alike.
    10. Re:Too much UNIX for me by SL+Baur · · Score: 2, Insightful

      It's more like they are very common hot-keys for any GUI app. C-SPC, C-w/M-w, C-y work just fine for me and we were using those keys before there was a Microsoft Windows, Linux or even modern Unix.

      Now get off my lawn!
  3. It's easy... by johannesg · · Score: 5, Interesting

    Look, the point of blacking out is not just to remove critical information, it is also to get you used to large parts of documents being blacked out. It is a way of hiding a signal within a lot of noise.

    By randomly blacking out stuff, you will never know if there is vital information hiding underneath the black text. And you will become more and more accepting of documents that have barely any text at all.

    The purpose is, of course, to allow more and more freedom to the agencies doing the blacking out. And less and less to you.

    1. Re:It's easy... by PatboyX · · Score: 2, Funny

      Washington Irving at it again!

    2. Re:It's easy... by FudRucker · · Score: 2, Funny

      lol, they might as well publish everything with lorem ipsum on it...

      ---TOP SECRET--- "Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum."

      --
      Politics is Treachery, Religion is Brainwashing
  4. No suprises by Lumpy · · Score: 2, Informative

    Most of the time something deemed "secret" rarely is. Also when I was last in the public Sector, IT was woefully underfunded and overall employee training was even worse. Things like this will continue to be a major mess.

    --
    Do not look at laser with remaining good eye.
  5. Secrets Kept to avoid Embarrassment by curmudgeon99 · · Score: 5, Insightful

    This is a classic example of secrecy being used not for national security but to avoid embarrassment. There are likely thousands of these types of secrets that cost money to keep but that are for no reason at all. Ass clowns.

  6. Entertaining to whom? by Anonymous Coward · · Score: 2, Insightful

    Can we get a new category, like "Gallows Humor"?

    Besides, we shouldn't be reporting on this stuff-- our only defense against this government anymore is its own monumental stupidity.

  7. Implementation by Graywolf · · Score: 5, Informative

    "Redacted" was apparently implemented by covering the area with a white rectangle. Since the PDF has real text/vector graphics (as opposed to a bitmap), the information is still present in the file and even the standard Acrobat viewer can access it. Someone "Failed at Behaving Intelligently"

  8. Who's responsible..? by ricebowl · · Score: 4, Insightful

    "Once again, supposedly sensitive information blacked out from a government report turns out to be visible by computer experts armed with the Ctrl+C keys

    What confuses me is that, and I might be too generous in my assumption, I assume that there's an IT professional somewhere that looks over these released files prior to their release? I know that common sense is entirely too uncommon these days, but if I were to release a digital file (whether to an individual or the public) I'd make sure that someone from the IT department looked it over before release.

    Otherwise it's like having a flu vaccine released by managers that went nowhere near an immunologist or virologist.

    Still, I'm sure that, sometime soon, MS will remove the Ctrl+C combination. For national security, of course.

    1. Re:Who's responsible..? by MrMr · · Score: 4, Insightful

      ...assume that there's an IT professional somewhere that looks over these released files prior to their release?

      Apparently you have never worked for a government department.

      Otherwise it's like having a flu vaccine released by managers that went nowhere near an immunologist or virologist.

      or in the pharmaceutical industry.

    2. Re:Who's responsible..? by Bushcat · · Score: 2, Insightful

      No, the "IT professional", if any, will have been excluded by the "incredibly thick underlings" thinking they actually have a clue. I've worked in such environments: the thicker the person, the more that person thinks s/he knows, and the more important that person believes s/he is.

    3. Re:Who's responsible..? by Thanshin · · Score: 4, Funny

      ...assume that there's an IT professional somewhere that looks over these released files prior to their release?

      Apparently you have never worked for a government department.

      Otherwise it's like having a flu vaccine released by managers that went nowhere near an immunologist or virologist.

      or in the pharmaceutical industry. It's not lack of knowledge, it's optimism. Don't pop the pink bubble.
  9. Not everything is censorship. by R2.0 · · Score: 5, Informative

    Sometimes items are redacted because of contractual commitments or confidentiality agreements. Take the example in the story; now, all Verizon's competition needs to do is bid $2,499 per switch and they get the job. So what if they could have supplied the switches at $2,200 and still made a healthy profit - they just need to be low. So that's $299 extra per switch that the government (aka, taxpayers) will have to pay because the competitive bid environment has been contaminated.

    But hey, they made their point about evil government masterminds being wholly incompetent, so what does logic matter?

    --
    "As God is my witness, I thought turkeys could fly." A. Carlson
    1. Re:Not everything is censorship. by morgan_greywolf · · Score: 2, Interesting

      Correct. All non-classified government contracts can be had through FOIA request. Some agencies even post information about some of their contracts online on their website -- no FOIA required.

  10. LOL! by sm62704 · · Score: 4, Insightful

    visible by computer experts armed with the Ctrl+C keys

    The FBI is trying to trick me into thinking they're all stupid so they can find out where I've got the 500 acre marijuana farm with its fiftten thousand tons of marijuana in the barn, 500 beautiful hookers and the casino downstairs, where you can buy white lightning and moonshine.

    Meanwhile, Osama's still loose.

    Attention FBI: Look, dumbasses, print the damned thing out, black out the parts that embarrass the President and your Director with a magic marker and scan it to a TIF file (that's a graphics format, guys. Pay attention!) and "print" THAT to PDF.

    But you already know that, you're trying to find my pot gambling hooker farm!

    --
    mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
    1. Re:LOL! by Thanshin · · Score: 3, Funny

      print the damned thing out, black out the parts that embarrass the President and your Director with a magic marker and scan it to a TIF file (that's a graphics format, guys. Pay attention!) and "print" THAT to PDF. WRONG!

      The official method is:

      1 - Print the document.
      2 - Cut the private parts away with a cutter.
      3 - If you've not castrated yourself, you should have a paper with holes. Put it in a wooden table.
      4 - Make a photo of said table.
      5 - Load the photo in a power point.
      6 - publish the ppt file.
    2. Re:LOL! by genderbunny · · Score: 2, Funny

      I'm also inept. Now where might this farm be located?

    3. Re:LOL! by TummyX · · Score: 2


      Meanwhile, Osama's still loose.


      I don't mean to be nitpicky but isn't Osama most likely outside of the US? Somewhere outside the jurisdiction of the FBI?

  11. The New Math by nqz · · Score: 2, Interesting

    Maybe the FBI should stick to something, like wiretapping for example, rather than performing simple math for a report ... 1140 x $2,500 $2.9 million (see the reverse pacman sign)

  12. Copy & Paste Reveals FBI Wiretapping Audit Sec by FlameWise · · Score: 5, Informative

    Honestly, same here. Some of those headlines are becoming really hard to read.

    "Wiretapping": verb. The FBI is wiretapping something. "is" omitted as in many headlines.

    "Audit": verb. The FBI's act of wiretapping is auditing something (Huh?)

    "Secrets": verb. The Audit of the FBI's wiretapping is leaking something. Wait isn't "secrete" writting with an extra "e"?

    "Uncovered": verb, passive. By now I'm sort doubtful I got it right in the fourth attempt.

    "Via Ctrl+C": By what?

    It took me reading the link in the original post to figure they meant a key press and not a screen name or a publication I wasn't familiar with, also helped me sort the four verbs into some semblance of legal grammar.

    How about: "Copy & Paste Reveals FBI Wiretapping Audit Secrets"?

    Remember school: Passive is bad for you.

  13. Re:Copy & Paste Reveals FBI Wiretapping Audit by FlameWise · · Score: 4, Funny

    Right, I had one moment where I thought that hitting Ctrl+C would somehow reveal that the FBI is auditing you, too.

  14. The mosaic effect by Anonymous Coward · · Score: 3, Insightful

    Now, I'm all up for good gov't conspiracy, and working for the gov't, I know how they spend inappropriately.

    But there is something called the mosaic effect. The short of it is that you have two (or more) documents. None of them by themselves are sensitive, but as a group, they become sensitive because they give you a complete picture. It's quite possible that this redacted info gives that picture.

    In addition, gov't entities regularly leave out the specifics like the number of switches because they do not want to demonstrate the scope of their operations. Not for any malicious reasons, but for what they perceive as a security risk. It might be a false risk, but it's not malicious.

  15. Follow the evil overlord tips by vecctor · · Score: 4, Insightful
    When I read this, the first thing I thought of were the evil overlord rules - specifically this one:

    One of my advisors will be an average five-year-old child. Any flaws in my plan that he is able to spot will be corrected before implementation. They just need to have some intern to sit around and spot obvious flaws in document security. Any idiot giving this doc a cursory examination would have found this.

    --
    Why, yes I have been touched by His noodly appendage. And I plan to sue.
  16. It looks like you're trying to redact a document! by Halo- · · Score: 5, Informative

    For me, the best part of the article was the link to the NSA redaction guidelines. Interesting reading I suppose, but the fact that throughout the entire paper the screencaps of MS Word had that damn Clippy-substitute cat sitting in the corner was classic. I'm not sure I'd trust someone (even at the NSA) to give me advice on MS Word options and settings when they can't even turn of the animated assistant.

  17. How much!!! by JaJ_D · · Score: 4, Insightful

    The FBI paid Verizon $2,500 apiece to upgrade 1,140 old telephone switches. Oddly the report didn't redact the total amount paid to the telecom â" slightly more than $2.9 million dollars â" but somehow the bad guys will win if they knew the number of switches and the cost paid.

    It's more likely that the total number is large and people go "ok must be a lot" but at 2.5k usd per switch people would go "how fucking much!!!" - that's what they may want to avoid

    Jaj

  18. this just goes to show by v1 · · Score: 4, Insightful

    how abused and misapplied all those "in the interest of national security" procedures are when there is no oversight in place. When will the legislators ever learn, anything that can be abused or misused, will be abused and misused in the absence of oversight? It's not even "might" or "is very likely". It always happens. It's human nature to take advantage for personal gain without risk. They censor anything that they want to, for any agenda, because they can. And this just exposes that truth.

    Now watch how they react to it. Do they straighten up their censorship policies? of course not. They'll simply make the abuse harder to discover.

    --
    I work for the Department of Redundancy Department.
  19. Be happy its still number of switches by AHuxley · · Score: 3, Interesting

    In the USA you still only have to do the math on the 'number' and 'quality' of roving witetaps.
    The use of public or released data to see what police forces are doing is interesting.
    In India you have to count the number of dead.
    "The records show that Durgiyana Mandir ground was one of three cremation sites in Amritsar
    illegally used by the police.
    It takes about 300kg of wood to burn a single body and each wood purchase is written in a register.
    The police subverted the system, by burning more than one body on each pyre.

    http://news.sbs.com.au/dateline/india__who_killed_the_sikhs_130052 [sbs.com.au]

    --
    Domestic spying is now "Benign Information Gathering"
  20. You idiots... by rpp3po · · Score: 2, Funny

    this is reverse psychology! Hide some nonsense behind CRTL+C and the people point at you laughing about hiding such nonsense. Give 'em nothing but black bars and they will be afraid what terrible things are behind them and shout for more transparency.

  21. according to TFA... by DragonTHC · · Score: 2, Interesting

    the FBI had spent $500 Million for these sort of upgrades. If verizon only cost them $2.9 million, and the other carriers cost only slightly more, where's the other $475 million dollars?

    --
    They're using their grammar skills there.
  22. Linux makes things even easier! by 1336 · · Score: 2, Informative

    In Ubuntu if you use the default PDF viewer (Evince), you can see the "sensitive information" in the tables by simply HIGHLIGHTING the text.

    No need to even use the keyboard to copy/paste the data! ;)

  23. Not really by Anonymous Coward · · Score: 3, Interesting

    The calia network as outlined originally, would have used a fraction of the switches. That number of switches indicates that they were monitoring a LOT more. IOW, this was not about wireless but about the entire world wide network. FBI is tapping all of Verizon.

    The one big embarrassment out of that, is that it shows that they had total access to the network, and yet 9/11 occurred. So, does that mean that this was not being used for terrorism, or does this indicate that we did know and ignored what was to happen.

  24. The naivete! by wfolta · · Score: 5, Interesting

    It hurts my brain. The person who (incompetently) redacted the document was probably just following guidelines. My guess is that there's a guideline that says that specific numbers and costs cannot be published in reference to secure systems used by an intelligence or law enforcement agency. Only aggregate costs, as necessary to inform the public and lawmakers.

    No conspiracy. No corruption. No deeper meaning than a guideline that requires sticking your neck out and making a case if you want to violate it.

    Makes sense, actually, as most intelligence gathering is probably not about sentences like, "John Doe is our super-secret mole in the office of the director", but rather "the phone system has 1100 switches for all of North America, and is taken down every 2 weeks at 1 am for maintenance."

    And this leaves me wondering if those who are laughing or outraged at the attempted redaction (as opposed to the incompetence in implementing it) are also the same people who insist that they must have military-grade encryption and anonymous re-routing, using spread-spectrum wireless transmissions to public access facilities, in order to protect their private emails to grandmother. Sigh.

  25. this actually makes some sense... by virmaior · · Score: 3, Insightful

    from an information security standpoint, this actually makes some sense. Allow me to explain. First, the high value number is going to show up in budgets anyway, so anyone who wants that number could already find it. It's hard to not have a few million dollars show up in the accounting somehow. Second, the reason the exact dollar value per part is usually redacted is that this is a giant clue as to the identity of the part used in the infrastructure. E.g. if I tell you I have a $300 mp3 player, then you know that I have an IPOD. But if I tell you that I bought a bunch of mp3 players and spent $100,000 then you don't know whether I've bought Zens, Zunes, ipods, sansas, or something else. And the problem with telling people what your infrastructure is made of who shouldn't know is that it enables them to focus on vulnerabilities for just that one device. caveat: I actually have a $10 mp3 player.

  26. "Sorry to bust your bubble"or"The Mundane Answer" by Specter · · Score: 2, Insightful

    The actual cost of performing the service was likely redacted, not as a matter of national security, but because the pricing is contractually considered proprietary information .

    Most companies include this as a standard clause in their master service agreements so that Joe's Barber shop isn't upset that Big Government Office is getting a different (presumably better) price for exactly the same service.

  27. Re:Sheesh by Opportunist · · Score: 2, Funny

    Can you geeks only complain? First you complain that we try to keep information secret, then, when we're too dumb to do it right and the info gets out, you complain again.

    Is there a way to satisfy you? Jeesh...

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  28. Why the cost per switch would be redacted by gizmonic · · Score: 2, Insightful

    The reason to hide the cost per switch is to keep the negotiations invisible from other providers. Sure, you can report $2.9 million to Verizon, but AT&T doesn't know how many switches that was or the cost per switch. Maybe they worked out a cheaper deal with AT&T for, say, $2,000 per switch instead of $2,500. If AT&T knew what Verizon was getting paid, they'd hold out for more themselves. While it may seem silly to hide the details, doing so probably saves a little cash in the long run.

    Of course, now, if they ever need to do more switches, I am betting every vendor will be holding out for the highest publicized price (or their own private price, if it's higher still). So, yeah, sometimes disseminating what you think is non-critical information will in fact cost us more in the long run. Revealing it may not make "the bad guys win" but it can definitely make the taxpayer lose.

    Just my unredacted $0.02.

    --
    WWJD?
    JWRTFM!