Inspector General Says NSA Still Hasn't Implemented Its Post-Snowden Internal Security Measures (techdirt.com)
An anonymous reader quotes a report form Techdirt: In the immediate aftermath of an NSA contractor springing numerous leaks back in 2013, the NSA vowed this would never happen again. It has happened again and it hasn't just been documents. It's also been software exploits, which contributed to a worldwide plague of ransomware. The NSA was going to make sure no one could just walk out of work with thousands of sensitive documents. It laid out a plan to exercise greater control over access and fail safe procedures meant to keep free-spirited Snowdens in check. The NSA is the world's most powerful surveillance agency. It is also a sizable bureaucracy. Over the past half-decade, the NSA has talked tough about tighter internal controls. But talk is cheap -- at least labor-wise. Actual implementation takes dedication and commitment. The NSA just doesn't have that in it, according to a recent Inspector General's report: "The nation's cyber spy agency is suffering from substantial cyber vulnerabilities, according to a first-of-its-kind unclassified audit overview from the agency's inspector general released Wednesday. Those vulnerabilities include computer system security plans that are inaccurate or incomplete, removable media that aren't properly scanned for viruses, and an inadequate process for tracking the job duties of National Security Agency cyber defenders to ensure they're qualified for the highest-level work they do, according to the overview."
most of the domains (including backchannel ones) are not secured via DNSSEC or have IPv6 address's which goes to show they cant run a network at the best of times...
(excuses about simpler or that they are subject to DDOS are pretty pathetic)
The NSA needs to keep the leaks going to find the leakers.
Add more contractors who got a job without security considerations? The buddy system?
Two contractors working together at all times? They both know one of them never got the needed security clearance?
10 contractors on site and what % cant be trusted? Get the buddy system wrong and risk two people totally lacking in security clearances working together?
One wants to sell NSA secrets? One wants to give away NSA secrets for politics? One is an anti war activist? One with split loyalty to another nation?
Split loyalty to their faith, cult?
Got a criminal past that some other nation has discovered? Another nation offering cash for secrets to cover a lifestyle well beyond any NSA contractor wage?
Full new security background investigations into all contractors and gov/mil workers starts to look like a good idea.
Dont hire for political correctness and to virtue signal. No getting past a security clearance on "demographics".
Dont allow politics leaders to demand security clearances are given to ensure demographics.
Advanced psychological testing would be another good pathway to discover people with problems who would want to become whistleblowers and feel the need to talk to the press.
People with lifestyle issues. In a cult? A faith group that is trying to place their workers deep in the US gov/mil. A person who needs money to enjoy a lifestyle that another nation could offer. Political internet use showing a change in personality? A worker looking for journalists who have worked with whistleblowers.
Rather than waiting for a journalist to search for projects after meeting whistleblowers, look for whistleblowers seeking journalists.
Walk the life story of all contractors and mil/gov staff. Their education, friends. university education, their political friends. In a cult, faith group? Politics? Criminal past? Deviant lifestyle that another nation could discover? A new friend who is too "perfect" and full of questions?
University politics and revolutionary friends on campus can really shape decades of later work. Journalists as friends?
Do what the FBI/mil/gov would have done in the 1950-1990's and ensure only the best and most loyal to the USA get any contractor/gov/mil jobs.
Hire for US security not diversity. History is full of decades of spies and low security hired people who got in due to rushed and failed security considerations.
Start looking over the pasts of every contractor and look into hops to interesting people, faiths, split loyalty, cash/loans spending patterns.
Domestic spying is now "Benign Information Gathering"
So what is the solution AC?
Keep things as they are now and watch for any interaction between journalists and whistleblowers? Thats a risk and the data could be published.
Collect on all US journalists who work on gov/mil stories for any sign of a new gov/mil contact?
Watch all US mil/gov workers, contractors for any political and lifestyle changes?
Do security clearances before accepting staff so people with security problems and any split loyalty problems never get a security clearance?
Think of the esprit de corps too AC. Never been trusted and never able to trust the buddy system is great for small groups of workers all over the world on a set wage.
Would a great wage and much better security prevent the need for whistleblowers to start conversations with journalists? Apart for political and faith reasons to share secrets.
Domestic spying is now "Benign Information Gathering"
NSA continues to spy on the rest of the world, with the help of 5 eyes countries. 5 Eyes countries are protected by 'agreements'. Agreements like 'trade-agreements', are not enforceable when dealing with a bad-actor. If he won't abide by trade-agreements, why would him and his boss in Moscow abide by no-spy agreements?
https://www.usatoday.com/story/news/2017/01/26/report-arrested-russian-intel-officer-allegedly-spied-us/97094696/
This is what happened to US spies, 6 days after Trump got to power, and got access to the unredacted names of the spies mentioned in the pee pee memos, he passed the names over to Putin as revenge:
"A senior Russian intelligence officer and cybersecurity investigator arrested last month on treason charges allegedly was passing information to U.S. intelligence services, according to Russian media outlets. Sergei Mikhailov, who worked for the FSB, the successor to the KGB, was arrested in December, along with Ruslan Stoyanov, a top manager for Russia's largest cybersecurity firm, according to the economic newspaper Kommersant. Stoyanov was also charged with suspicion of treason. In addition, two other people, including Major Dmitry Dokuchaev, also an FSB officer, were arrested in connection with the case, according to Russia's REN-TV. The fourth person was not identified."
Once you start stripped away the privacy protections and replace checks and balances with faith and trust, it only takes one bad actor in the right position to undermine the whole system. One foreign puppet and that's all it takes to flip a nation. Because the nation already did the work needed, and they'll always be people who'll sell out their country in pursuit of their party flag. Fox News (Hannity-Cohen payments), One America News (old man Robert Herring invited to Russia, married a hot sexy Russian woman and turned his news network into a pro-Russia fluff cable network) etc, etc,.
You let NSA spy on everyone on a promise not to look at some of the data, and then you put someone above them who always lies, has dodgy foreign friends, and never keeps promises.
What is up with you deplorables being so obsessed with pedophilia and child sex rings? Methinks we'd find kiddie porn on your computer...
Seeing what I have seen in regards to security vulnerabilities reported to institutions and the general paralysis that ensues when anyone brings up real security in just about any organization...none of this surprises me...at all. In fact, I would have predicted nothing would be done, especially given the tell where the institution focuses on a single perpetrator or incident when in fact that is not at all the problem. When their security sucks, and they don't get it and can't fix it because they suck, they spin the focus on Snowden or whatever evil hacker dujour.
I object to power without constructive purpose. --Spock
“The nation's cyber spy agency is suffering from substantial cyber vulnerabilities .. removable media that aren't properly scanned for viruses”
:]
Jesus tapdancing Christ on rollerskates, the FSB must be laughing into their soup
And don't forget, kids: this is the agency which is constantly telling us we can safely backdoor encryption!
(Well, maybe that's mainly the FBI, instead. But I still trust them just as much as I'd trust the NSA.)
Too busy pursuing their mission outside the mission itself and the bounds of constitutional practice.
That said, I have trouble believing this, or really any offer of information to the public from government agencies. Sounds like a honeypot, or a false reveal of vulnerability. Who trusts any of them at face value?
I hear the best person is available, he just needs a green light from the US to come back from Russia.
Slashdot, fix the reply notifications... You won't get away with it...
... are there other circumstances hidden from the public?
To me as an outsider it seems most government digital security agencies are more prioritized on spying civilians than actually securing the state they're operating for.
So securing their own assets is not on top of the list as it is described in the article.
But also contractors might have a deal in this, as soon as the security has been tightened they might not be able to perform duties or they're not necessary anymore.
Perhaps a combination of a multitude of factors prevent improvement, including funding and administration?
Bach says it all.
Truthspace: We are each reflections of both god and demon, thus cursed with the emergent gift of free will. The choices are yours alone. Choose wisely.
They already do those things mentioed above, and maybe have best friend snitch awards, and concern lines.
THE problem is the gig economy. Both Employer and employee have no loyalty other than collecting a paycheck for as long as possible. No career stability or promotions? Screw that, and some splinter of SJW may pop into ones head.
The you have envy. Contractors geting big bucks for the same work, stealing credit or in the way of a career path.
Treating your employees well is a good start, but ride them hard with KPI shit, and demonstrate job expendability - well they will gather insurance. Usually the brains can memorise a lot, near photographic memories, so walking out with usb sticks is no guarantee of anything.
Go back to the days of all employees, and contractors 1:100. That worked before.
The fact they still are using "removeable media" and that Snowden was able to exfiltrate all that data to "consumer formats" tells us all we need to know. They do not even have their own file format's, and if they do have created a way to export them into format's that you or I can read which should be impossible considering they should be encrypted six ways to Sunday with the only way to view the content through highly specialized software locked behind their wall of security. The other thing is they still think "software" if the way to secure themselves and our most important critical assets. No they need entirely proprietary CPU and hardware designs. Think like x86 architecture on steroids that unless you had the cookbook of its instruction set, would never even be able to write "hello world" without extensive effort. The fact they don't have 100% confidence in the bits and bytes going over the network. They should only allow very specific and purposeful traffic on their networks, that fits a very tight "DNA profile's" as far as network traffic goes. The whole CPU architecture needs a rework on the consumer side. The network data structuring needs to have an industry adopted format on how applications communicate.NSA should have every application in use profiled for its normal behavior and analytics run on that software to spot a single bit that should not be transmitted. At least for software that runs on .gov and .mil and its partners.
There should also be extensive code auditing and chain of custody for the software. If it is not audited, it does not get deployed - PERIOD. They should be using the worlds most restrictive API's to develop that software, and its underlying library the most heavily researched software API int he world for vulnerabilities.
I mean that should of been the goal 30 years ago.
Their focus seems to be on "haha we can read emails and text messages we are l33t".
The summary contains a list of features, not bugs.
Inspector General Says NSA Still Hasn't Implemented Its Post-Snowden Internal Security Measures
Hey now, they've been pretty busy gathering intel on non standard presidential candidates and stuff.
Sheesh, what's your hurry?
See subject: You WISH you were me & that you HAVE NO BALLS since you won't face me directly you loser who impersonates me.
* Face facts: You CANNOT stop me posting here, & you certainly can't get the better of me on technical points (especially on hosts files).
APK
P.S.=> Accept it - you FAIL, loser... apk
Impersonating me AGAIN? I see you copy where I caught arseholetechnica's GOD & ManWithNoHead using same email lol proving they do "sockpuppets" like pussies & losers do - ah, yes - seems the "ArSeHoLeS" STILL can't stand I blew them away @ Windows IT Pro forums + DROVE THEM OUT OF THEIR OWN IRC CHATROOMS, lol (when you can code you can design your OWN floodbots to do it is how/why). Only reason their site was DESTROYED by me is the law - the ONLY thing that protected them was that on that note.
* You're just another one of those TOTAL losers obviously...
APK
P.S.=> Thanks - for what? Letting me relive a past triumph over a pack of wannabe do-nothing DILDOS in arseholetechnica - home of the UNDERACHIEVER all talk do-nothing "ne'er-do-well" online (all they have is BITCH TACTICS like yours, impersonating me)... apk
The US security services and armed forces did a huge, expensive effort to provide military-grade confidentiality years ago, implemented on Multics, and later on Solaris and HP-UX. More recently, on Linux. Thy even had an example of the 'net, Dockmaster.MIL
They they decided not to use it, because it took a week course to learn how to administer a Trusted Solaris system.
Too much work; didn't do.
davecb@spamcop.net
See subject: I know you understand the loser impersoating &/or STALKING me nigh constantly by UNIDENTIFIABLE anonymous on /. for YEARS now - they KNOW they're SHIT & have ZERO to show for themselves - hence why they resort to BITCH TACTICS (because they truly ARE what I call "not-men" (alias bitches, lol)).
* Do-nothing MERE "ne'er-do-well" ZEROS who don't have anything BETTER to do than play bitch games!
APK
P.S.=> What causes them to act this way (per your statement to that effect)? Trying to "take me on" (especially in tech where they delude themselves they're any good @ it (they're not)) & LOSING - it "injures" their "pride" (which they have almost NONE of hiding behind FAKE NAMES ONLINE) - they don't have enough SENSE to NOT mess w/ their betters - especially me... apk
I see you also copied where I caught arseholetechnica's GOD & ManWithNoHead using same email lol proving they do "sockpuppets" like pussies & losers do - ah, yes:
Seems the "ArSeHoLeS" STILL can't stand I blew them away @ Windows IT Pro forums + DROVE THEM OUT OF THEIR OWN IRC CHATROOMS, lol (when you can code you can design your OWN floodbots to do it is how/why).
Only reason their site wasn't DOWNED & DESTROYED by me is the law - the ONLY thing that protected them was that on that note for the bullshit they pulled.
* You're just another one of those TOTAL losers obviously.
APK
P.S.=> Thanks - for what? Letting me relive a past triumph over a pack of wannabe do-nothing DILDOS in arseholetechnica - home of the UNDERACHIEVER all talk do-nothing "ne'er-do-well" online (all they have is BITCH TACTICS like yours, impersonating me)... apk
Your posting style is definitely more recognizeable. I cannot be decieved by imposters.
"First they came for the slanderers and i said nothing."
Sure thing, pedo.
Given that low level people can access info beyond their pay grade, I'd assume spies are everywhere within the system.
If Snowden exposed anything - it's how poor the security is and that people could easily steal data and give it to foreign governments. Should the person desire to do that of course.
Whoever's doing it is one SAD fuck, no questions asked. Don't you have anything BETTER to do? Apparently not. It's not MY fault you're a f'd in the head WASTE of life you know - it's yours.
* GROW UP!
APK
P.S.=> Look - I know what your problem is: You tried to "take me on" in tech & got BLOWN away - learn a lesson - don't mess w/ your betters (me), ok? You did that to yourself (hence why you STALK me constantly HIDING behind UNIDENTIFIABLE anonymous posts since I can show I dusted you under your MANY sockpuppet fake /. accounts FAKE NAMES &/or WHY you IMPERSONATE me as well - it only makes YOU look the fool all the more - again: GROW UP, get over your obsession & butthurt you caused for yourself since your FRAGILE "ego" is damaged)... apk
I am APK the great "LORD of HOSTS", a.k.a. AlecStaar or Alexander Peter Kowalski.
See subject & APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / I . a m . a . f u c k i n g / a s s h o l e . r e t a r d . z i p (remove spaces between characters & download).
I am the godlike creator of various GUI front-ends for other people's configuration files.
Watch as I claim I win every argument when in reality I know I lost but that won't stop me from proclaiming my victory.
When presented with facts I rebut them with wild speculations, false support, and out of context quotes
All of my accomplishments revolve around me being proven to be an annoying spamming asshole
See me be proud of my inability to be a functional adult
Bask in my debilitating mental illness
Hear me tell stories about me living large drinking miller lite in my ramshackle duplex with a roommate at age 54.
Watch me spew some word salad because I can't string 2 words together in a coherent manner.
I just don't understand why every site I post on everyone makes fun of me, it can't be because I am a shit stick but instead because they are all Ne'er-do-well SOYboy Jealous JOWIEs.
Witness my descent into madness
APK
Why would a Cyber/Spy/Security Federal Institution use Windows in the first place? Stupid or Red Tape?
They have to go back to basics, Why? They are very stupid...
Trying to type and U messing with my keyboard, why? stupid or what?
If they where running Linux/Unix, they would of not been in this mess.
See my subject & answer that: & Why do you also STALK me by UNIDENTIFIABLE anonymous posts as well? AFRAID to stand behind your lies??
* THIS I have to hear, lol - it WILL truly be a classic I'm sure!
(CAT GOT YOUR TONGUE SUDDENLY? You wouldn't answer LAST TIME I ASKED IT + YOU DOWNMOD "HID" IT (the sure sign of YOUR total SELF-defeat) https://it.slashdot.org/commen... )
APK
P.S.=> You only do this to yourself & it makes me laugh... apk
But then again they don't blame themselves for their own mistakes, so we're going to be saying "The Bomb's not falling" and truly believing it.