Slashdot Mirror


To Avoid Detection, Terrorists Made Messages Seem Like Spam

HughPickens.com writes: It's common knowledge the NSA collects plenty of data on suspected terrorists as well as ordinary citizens, but the agency also has algorithms in place to filter out information that doesn't need to be collected or stored for further analysis, such as spam emails. Now Alice Truong reports that during operations in Afghanistan after 9/11, the U.S. was able to analyze laptops formerly owned by Taliban members. According to NSA officer Michael Wertheimer, they discovered an email written in English found on the computers contained a purposely spammy subject line: "CONSOLIDATE YOUR DEBT."

According to Wertheimer, the email was sent to and from nondescript addresses that were later confirmed to belong to combatants. "It is surely the case that the sender and receiver attempted to avoid allied collection of this operational message by triggering presumed "spam" filters (PDF)." From a surveillance perspective, Wertheimer writes that this highlights the importance of filtering algorithms. Implementing them makes parsing huge amounts of data easier, but it also presents opportunities for someone with a secret to figure out what type of information is being tossed out and exploit the loophole.

4 of 110 comments (clear)

  1. Spam Mimic by Rick+Richardson · · Score: 3, Informative

    http://www.spammimic.com/

  2. Re:Stupid by aix+tom · · Score: 3, Informative

    Of course, never in History, not even in WW1 and 2 has any spy agency tried do collect ALL information that was there. Like every letter sent, every phone call made, every conversation made in public, etc... like spy organisations these days seem to try.

    Former East Germany came closest in the last century I guess. Then again, they probably had 20% of the population working at least part-time as undercover agents to spy on the rest.

  3. Re:I actually warned the FBI... by Carnildo · · Score: 3, Informative

    You alerted them to actual spam.

    The purpose of the suffix was to evade simple subject-line spam filters, while the "word salad" was an effort to evade word-classifier spam filters by drowning out the "spam-like" words with "non-spam" words, or to poison the classifiers and render them useless by loading up the "spam" wordlists with words that usually appear in non-spam messages.

    --
    "They redundantly repeated themselves over and over again incessantly without end ad infinitum" -- ibid.
  4. There is a technical cryptographic term for this by slashdot_commentator · · Score: 3, Informative

    Its called steganography.

    --
    There is no America. There is no democracy. There is only IBM and AT&T and DuPont, Dow, General Electric, and Exxon