Showing posts with label cyber-security. Show all posts
Showing posts with label cyber-security. Show all posts

Tuesday, October 11, 2011

Turley: Obama "devastating" for civil liberties

Civil libertarians have long had a dysfunctional relationship with the Democratic Party, which treats them as a captive voting bloc with nowhere else to turn in elections. - J Turley

http://articles.latimes.com/2011/sep/29/opinion/la-oe-turley-civil-liberties-20110929

http://www.npr.org/2011/10/10/141213273/op-ed-obama-devastating-for-civil-liberties

I know we discussed this in the past about Obama's campaign pledges to promote civil rights and gov. transparency, but as president he has actually increased secrecy and expanded the powers of the US terrorism-industrial-complex (even over Bush levels), sometimes at the expense of the rules of war, civil liberties, and other laws/values. I guess the calculation was simple for Obama: it was more important to get the support of the military-intel community than the civil libertarians, so he made decisions to favor the former. Especially with the economy/jobs front-and-center, I guess his people felt that civil rights won't be a critical issue in 2012, especially when his yet-unnamed GOP rival would probably endorse and harsher stance on executive privilege and the security-vs-rights debate.

So that's where we stand: the GOP isn't mad at Obama because terror plots are being thwarted and Al Qaeda leaders are getting whacked. Though I'm sure they'd prefer to get the credit, and probably feel that Obama is just the lucky executor of the good Bush-neocon policies that are now bearing fruit. Any consolidation of executive power and trimming of Congressional/legal/regulatory red tape is probably good for them. They know they'll recapture the White House at some point, and then it's pedal to the metal.

But from the left, Turley likens it to Stockholm Syndrome. We've fallen in love with our captor, just because he's the first black president, a young, handsome, charismatic chap, the game-changer, the chosen one, whatever other superlative. We aren't happy with what he's doing, but we just can't allow ourselves to oppose him and admit that we were wrong. So like a kid without discipline, he keeps taking and pulling, and taking and pulling, because we do nothing. The Dems bet big on this guy, and now we're stuck with him. It's very hard for a parent to admit that their kid is a bad seed because they still love him.

Yes it's true that campaigning is different than leading, so maybe Obama is under more constraints now and exposed to different information, which has changed his views. But any leader under crisis has experienced that, and some still decided to stand up for their beliefs despite the political consequences, while others folded like cowards and played it safe. Some things he has done are just flat wrong, and it's not like lives were imminently at stake. Yes it's possible that a GOP president may be worse. But if we were voting between Hitler and Napoleon, would we be content supporting Napoleon because he was just slightly better? And let's remember that Obama has in fact exceeded Bush on many secrecy and rights violations issues. We've dug ourselves into quite a hole with this one.

We can't allow Obama to get away with making a blanket promise to not prosecute any Bush-era people or CIA employees/affiliates for torture or other abuses, and squash any private investigations. I know closing Gitmo didn't work out for him (he was naive to think it would be easy), and these terror issues are a legal nightmare. Yes, justice is hard work, but that's what separates us from cave men. Would we rather condone abuses power, shadow governments, and selective application of the law like the enemy regimes we routinely denounce? People must be held accountable for their crimes, or there's no deterrent for future criminality. Poking around at the CIA and Pentagon is going to cause some problems for a president, but sometimes avoiding conflict and failing to do the right thing is worse. Same thing with the Wall St. investigations, no one goes to jail or gets punished, so what incentive do they have to shape up? Our democracy and republic exist and survive because of checks-and-balances on power. If the president shirks that responsibility, and even blocks Congress from intervening, what is to stop the security establishment from running amok, like they have always done in similar loose situations throughout history?

US soldiers are standing trial for abusing or killing civilians during our wars. They are on the front lines fighting for their country, paid slave wages, and still have to answer for crimes if they err. Why should CIA sociopaths, reckless Blackwater mercenaries, and neocon paper-pushers be exempt? I have particular contempt for the fat suits drafting policies in DC. These chickenhawks mostly never sacrificed an ounce of sweat for America, yet they are making decisions that are destroying innocent families and creating all sorts of unanticipated blowback for us, in between their tee times and K St. power lunches. Such patriots. The hubris. And now Obama, the Peace Prize Laureate, has thrown his hat in with them.

Wednesday, September 28, 2011

Interesting story of the Conficker worm

http://www.npr.org/2011/09/27/140704494/the-worm-that-could-bring-down-the-internet

The author of "Black Hawk Down" recently published a book about internet security and the Conficker worm, the most successful malware program known to date. I am not an IT guy, but from the interview, it seems that Conficker was written by expert hackers in Ukraine (who still remain anonymous) to tunnel into millions of Windows PCs and subtly control some of their processing resources, and then answer to a mother computer. Their aim seems to be the creation of a massive "botnet" of 10-12M slave computers worldwide that basically aggregate their processors to become the most powerful supercomputer in the world (even better than our best, expensive NSA comps). It's like those movies with the little nano-machines piling up to become a huge scary monster.

With this asset, the masters of Conficker may be able to brute-force crack computer encryption, presumably to guess passwords to steal money and/or secrets. 128-bit encryption technology can maybe produce gazillions of possible passwords (>10^38), which would take too long for even modern supercomputers to plow through. But the Conficker botnet can do this much quicker, and it's masters are now "leasing" the botnet resources to other criminals seeking to steal something. In theory, the penetration of Conficker is so great that its masters would be able to shut down the global internet if they wanted, but they seem more inclined to use it to steal, so it's left unharmed.

How the heck does Conficker infect PCs? Good ol' Microsoft did not make Windows XP very secure, and their engineers eventually discovered a vulnerability for remote access. So they issued a typical software update/patch to close the hole, and anyone who regularly updates their Windows OS should be safe. But the problem is that most PCs running Windows worldwide are using pirated versions that are not eligible for updating (another consequence of OS piracy: exposing the whole internet and trillions of wealth to crime; thanks a lot, China). So those users are totally exposed unless they download antivirus software or a free anti-Conficker program written pro bono by the "Conficker working group" near Stanford (calling themselves "the cabal," a team of volunteer cyber-security experts who recognized the danger of Conficker and are trying to stop it on their own time and own dime, because gov'ts are way behind the curve and doing nothing).

The irony is that Conficker started infecting PCs after this Windows patch. It's possible that the hackers analyzed the patch to reverse-engineer and discover what the Windows vulnerability was, so MS gave the bad guys a free how-to guide to hack Windows! By trying to fix their product, MS brought about the Conficker infection (in addition to many other similar malwares that have been since identified, and lord knows what we haven't found yet). Another consequence of monopoly: concentrated risk. And even though Conficker doesn't affect Mac or Linux, that's not to say that those OS's are any more secure. The Conficker masters just see less value in infecting the much smaller global population of Macs and Linuxes, which would create a much wimpier botnet. So take that, Apple snobs (and FYI, iOS has been hacked repeatedly so far).

Why can't we identify and shut down Conficker? Infected PCs show virtually no symptoms of infection, and are blocked from receiving any new updates, so it is a very clever parasite (and as I said, most of the infected PCs are not in the West). It just uses the processor selectively without slowing down your normal apps. But all the slave comps must answer to the mother comp for instructions, right? Why not just use that communication to locate the criminals and shut it down? Well, Conficker is elusive and doesn't just route all slave communications to one IP address. Then it would be easy to track, like a phone trace. But each day Conficker commandeers 250 IP domains, so it requires more effort to track down, and recent Conficker strains now use 2,500 domains and even 5 "high level" domains that are very secure. The hackers know that the poorly-funded cabal is the only group trying to stop them, so they just needed to make Conficker communications too costly to trace and block.

So where the hell is the gov't in all this? Isn't our security and economy at risk? Conficker seems a lot more of a concern than a couple of Taliban fighters with AKs. Obama just started a US Cyber Command within the NSA, a whole year after Conficker was discovered, but I surmise that they are grossly unprepared for the challenges ahead. Russia crashed Georgia's e-infrastructure with a worm/virus prior to its military invasion. McAfee pretty much implicated China in hacking some major US websites too, so the writing is on the wall. Hasn't anyone seen "Live Free or Die Hard?" We need McClane to rescue us.

The cabal approached the Pentagon and NSA to ask for help to fight Conficker, and maybe even sequester their computing resources. But they were summarily turned down, possibly over territorial or state secrets issues. I am sure that the NSA has a couple interns working on this (what else could be a higher priority for them, Mugabe's cell calls?), but clearly they are not winning (like Charlie Sheen). Here's another hilarious side-story. Remember how the US and Israel crashed Iran's computers controlling their uranium enrichment program? It set them back like a year. It's quite possible that our spooks hired the Conficker botnet to do that, or at least created our own similar worm inspired by Conficker.

Corporate and gov't cyber security is not up to task, but in this climate of austerity, it may be a hard sell to demand more investment in this area. No one cares to protect themselves until after the first disaster strikes (even though a few have already struck, but we just didn't care). I am sure the Ukrainian gang is a super-talented bunch of hackers, but they should be nothing compared to the resources that China or Facebook (no connection suggested) can devote to cyber-security, or cyber-warfare. Modern states already know that the best way to bring each other down (besides nukes) is to crash our e-infrastructure that we so depend on and take for granted. And even so, a cyber attack could disable our nukes and military. The internet was developed by idealistic engineers who wanted a free flow of information, so unfortunately it's structure is inherently vulnerable. We take the good with the bad, but ignoring the problem to this degree is just unacceptable. Fortunately, the likelihood of worms directly stealing our passwords and meager e-weath is still quite low. But what's the value of our little savings account if our national financial system gets wiped out?