U.S. Senate Committee Backs Use of Force in Syria

September 4th, 2013

I’m baffled by this situation. There is a very long and sickening history of the Executive doing whatever it wants when it comes to the use of military force (see: Presidential War Power by Louis Fisher). I don’t know why Mr. Nobel Peace Prize winner Obomb-ya is bothering with Congress to get America’s next war started.

Is there some sort of legislative Trojan horse here?

Via: BBC:

A US Senate panel has approved the use of military force in Syria, in response to an alleged chemical weapons attack.

By 10-7, the Committee on Foreign Relations moved the measure to a full Senate vote, expected next week.

The proposal allows the use of force in Syria for 60 days with the possibility to extend it for 30 days. It prevents the use of US troops on the ground.

President Barack Obama is battling to build support at home and abroad for military action.

Despite Wednesday’s vote, the bill’s ultimate fate in the wider Senate is unclear. And the US House of Representatives must also approve the measure.


‘School Is a Prison’

September 4th, 2013

I hope that everyone who sees this post clicks through and reads the whole piece.

Also, here’s the book: Free to Learn: Why Unleashing the Instinct to Play Will Make Our Children Happier, More Self-Reliant, and Better Students for Life by Peter Gray

Via: Salon:

Parents send their children to school with the best of intentions, believing that’s what they need to become productive and happy adults. Many have qualms about how well schools are performing, but the conventional wisdom is that these issues can be resolved with more money, better teachers, more challenging curricula and/or more rigorous tests.

But what if the real problem is school itself? The unfortunate fact is that one of our most cherished institutions is, by its very nature, failing our children and our society.

School is a place where children are compelled to be, and where their freedom is greatly restricted — far more restricted than most adults would tolerate in their workplaces. In recent decades, we have been compelling our children to spend ever more time in this kind of setting, and there is strong evidence (summarized in my recent book) that this is causing serious psychological damage to many of them. Moreover, the more scientists have learned about how children naturally learn, the more we have come to realize that children learn most deeply and fully, and with greatest enthusiasm, in conditions that are almost opposite to those of school.

Compulsory schooling has been a fixture of our culture now for several generations. It’s hard today for most people to even imagine how children would learn what they must for success in our culture without it. President Obama and Secretary of Education Arne Duncan are so enamored with schooling that they want even longer school days and school years. Most people assume that the basic design of schools, as we know them today, emerged from scientific evidence about how children learn best. But, in fact, nothing could be further from the truth.

Schools as we know them today are a product of history, not of research into how children learn. The blueprint still used for today’s schools was developed during the Protestant Reformation, when schools were created to teach children to read the Bible, to believe scripture without questioning it, and to obey authority figures without questioning them. The early founders of schools were quite clear about this in their writings. The idea that schools might be places for nurturing critical thought, creativity, self-initiative or ability to learn on one’s own — the kinds of skills most needed for success in today’s economy — was the furthest thing from their minds. To them, willfulness was sinfulness, to be drilled or beaten out of children, not encouraged.

When schools were taken over by the state and made compulsory, and directed toward secular ends, the basic structure and methods of schooling remained unchanged. Subsequent attempts at reform have failed because, though they have tinkered some with the structure, they haven’t altered the basic blueprint. The top-down, teach-and-test method, in which learning is motivated by a system of rewards and punishments rather than by curiosity or by any real, felt desire to know, is well designed for indoctrination and obedience training but not much else.


Think Of Tor As A Honeypot

September 4th, 2013

This is .mil laughing out loud at Tor heads.

“Tor is known to be insecure against an adversary that can observe a user’s traffic entering and exiting the anonymity network.”

Gee, I wonder who might be capable of doing something like that: NSA Laughs at PCs, Prefers Hacking Routers and Switches

Via: ohmygodel .PDF:

Tor is a volunteer-operated anonymity network that is estimated to protect the privacy of hundreds of thousands of daily users [13, 22]. However, Tor is known to be insecure against an adversary that can observe a user’s traffic entering and exiting the anonymity network. Quite simple and efficient techniques can correlate traffic at these separate locations by taking advantage of identifying traffic patterns [29]. As a result, the user and his destination may be identified, completely subverting the protocol’s security goals.

The traffic correlation problem in Tor has seen much attention in the literature. Prior Tor security analyses often consider entropy or similar statistical measures as metrics of the security provided by the system at a static point in time. In addition, while prior metrics of security may provide useful information about overall usage, they typically do not tell users how secure a type of behavior is. Further, similar previous work has thus far only considered adversaries that control either a subset of the members of the Tor network, a single autonomous system (AS), or a single Internet exchange point (IXP). These analyses have missed important characteristics of the network, such as that a single organization often controls several geographically diverse ASes or IXPs. That organization may have malicious intent or undergo coercion, threatening users of all network components under its control.

Given the severity of the traffic correlation problem and its security implications, we develop an analysis framework for evaluating the security of various user behaviors on the live Tor network and show how to concretely apply this framework by performing a comprehensive evaluation of the security of the Tor network [41] against the threat of complete deanonymization. To enable such an analysis, we develop a detailed model of a network adversary that includes (i) the largest and most accurate system for AS path inference yet applied to Tor and (ii) a thorough analysis of the threat of Internet exchange points and IXP coalitions. We also develop realistic metrics that inform this analysis, considering the network topology as it evolves over time, for example, as new relays are
introduced and others go offline.

Our analysis shows that 80% of all types of users may be deanonymized by a relatively moderate Tor-relay adversary within six months. Our results also show that against a single AS adversary roughly 100% of users in some common locations are deanonymized within three months (95% in three months for a single IXP). Further, we find that an adversary controlling two ASes instead of one reduces the median time to the first client de-anonymization by an order of magnitude: from over three months to only 1 day for a typical web user; and from over three months to roughly one month for a BitTorrent user. This clearly shows the dramatic effect an adversary that controls multiple ASes can have on security.

Related:

Tor Is Less Anonymous Than You Think

High-Traffic Colluding Tor Routers in Washington, D.C., and the Ugly Truth About Online Anonymity

Feds Pay for 60 Percent of Tor’s Development


NSA Laughs at PCs, Prefers Hacking Routers and Switches

September 4th, 2013

“No one updates their routers” ???

I always updated the routers, switches and firewalls that I was responsible for.

Ah well, these kids today…

Via: Wired:

The NSA’s focus on routers highlights an often-overlooked attack vector with huge advantages for the intruder, says Marc Maiffret, chief technology officer at security firm Beyond Trust. Hacking routers is an ideal way for an intelligence or military agency to maintain a persistent hold on network traffic because the systems aren’t updated with new software very often or patched in the way that Windows and Linux systems are.

“No one updates their routers,” he says. “If you think people are bad about patching Windows and Linux (which they are) then they are … horrible about updating their networking gear because it is too critical, and usually they don’t have redundancy to be able to do it properly.”

He also notes that routers don’t have security software that can help detect a breach.

“The challenge [with desktop systems] is that while antivirus don’t work well on your desktop, they at least do something [to detect attacks],” he says. “But you don’t even have an integrity check for the most part on routers and other such devices like IP cameras.”

Hijacking routers and switches could allow the NSA to do more than just eavesdrop on all the communications crossing that equipment. It would also let them bring down networks or prevent certain communication, such as military orders, from getting through, though the Post story doesn’t report any such activities. With control of routers, the NSA could re-route traffic to a different location, or even alter it for disinformation campaigns, such as planting information that would have a detrimental political effect or altering orders to re-route troops or supplies in a military operation.

According to the budget document, the CIA’s Tailored Access Programs and NSA’s software engineers possess “templates” for breaking into common brands and models of routers, switches and firewalls.

The article doesn’t say it, but this would likely involve pre-written scripts or backdoor tools and root kits for attacking known but unpatched vulnerabilities in these systems, as well as for attacking zero-day vulnerabilities that are yet unknown to the vendor and customers.

In 2005, security researcher Mike Lynn found a serious vulnerability in Cisco IOS, the operating system running on millions of Cisco routers around the world.

Lynn discovered the vulnerability after his employer, Internet Security Systems, asked him to reverse-engineer the Cisco operating system to see if he could find security problems with it. Cisco makes the majority of the routers that operate the backbone of the internet as well as many company networks and critical infrastructure systems. The Cisco IOS is as ubiquitous in the backbone as the Windows operating system is on desktops.

The vulnerability Lynn found, in a new version of the operation system that Cisco planned to release at the time, would have allowed someone to create a router worm that would shut down every Cisco router through which it passed, bringing down a nation’s critical infrastructure. It also would have allowed an attacker to gain complete control of the router to sniff all traffic passing through a network in order to read, record or alter it, or simply prevent traffic from reaching its recipient.

Once Lynn found the vulnerability, it took him six months to develop a working exploit to attack it.

Lynn had planned to discuss the vulnerability at the Black Hat security conference in Las Vegas, until Cisco intervened and forced him to pull the talk under threat of a lawsuit.

But if Lynn knew about the vulnerability, there were likely others who did as well — including intelligence agencies and criminal hackers.

Source code for Cisco’s IOS has been stolen at least twice, either by entities who were interested in studying the software to gain a competitive advantage or to uncover vulnerabilities that would allow someone to hack or control them.


Can’t Get Enough of China’s Ghost Cities

September 4th, 2013

Macro scale madness.

Via: io9:

China’s building boom has created a ton of abandoned cities and massive ruins — most of which are brand new, and have never had people living in them. Here are the deserted Chinese cities, mostly built in the last 10 years, which could be sets for your next dystopian movie.


With Camera Sales Slowing, Canon Looks to Surveillance Sector for Growth

September 4th, 2013

Via: Reuters:

Nosy governments and nervous homeowners, among other drivers of the surveillance society, may soon upstage amateur photographers as the focus for big camera makers such as Canon Inc who spot growing opportunities in the security market.

Canon, the industry leader, has been hit with a sudden downturn in shipments of its top-end digital cameras, an increasingly saturated market sensitive to the recent slowdown in emerging economies and with a receding pace of innovation.

Add to that a compact camera market that has been battered by smartphones with increasingly high-resolution cameras, and companies like Canon have been left scrambling for new markets.

“A major focus for the next phase is increasing our business-to-business (B2B) sales, and of course security cameras – which is a huge market – is part of that,” Canon President and CEO Fujio Mitarai said in an interview.


Readers Keep Cryptogon Going in September

September 3rd, 2013

Thank you.

Pookie $75
CM €10
MW $25

Thanks also go out to the person who signed up for hosting with BlueHost. I received $90 as a result.

I’m happy to mention your domains when you sign up for hosting with BlueHost, but as people become more apprehensive about being associated with Cryptogon in any way, I don’t want to cause trouble for people who support me! If you sign up for hosting with BlueHost AND you want me to mention your domain, just let me know.


Snowden Reportedly Used High-Ranking Official’s Profiles to Troll NSA’s Intranet

September 3rd, 2013

Something had to be very wrong on that network. Snowden must have pretty much had top level access to pull this off. Even so, it boggles the mind that something like disabling multi factor authentication didn’t generate some sort of notification at the next level up the pyramid.

I’ve been out of the sysadmin game since 2005, but does this make any sense to any of you who are currently involved with that stuff?

Via: Ars Technica:

The National Security Agency (NSA) is the font of information security wisdom for the US defense and intelligence communities. But apparently, the NSA’s own network security is so weak that a single administrator was able to hijack the credentials of a number of NSA employees with high-level security clearances and use them to download data from the agency’s internal networks. That administrator was Edward Snowden.

The systems accessed by Snowden limit access by user role, so he could not have used his own credentials on them without overriding access controls. Officials familiar with the case told NBC that Snowden had obtained the “profiles” of a number of NSA employees that have been identified through forensic examination of logs, finding periods when the employees were traveling but their accounts were still used to access the intranet. If Snowden used administrative privileges to reset their passwords, failed logins might have flagged a problem—but they might have simply been shrugged off as passwords forgotten over vacation.

In order to pull this off without raising alarms, Snowden would have needed access to the full credentials of the users whose identities he borrowed. He would have needed to somehow either gain access to the public key infrastructure (PKI) keys found in their user authentication or he would have needed to override multi-factor authentication to gain access to the systems. He also would have needed to avoid detection by audit logs in making those changes (or delete the record of changes after the fact). He managed to do all of these things, download the content, and get it past the NSA’s physical security.


Israel Confirms Missile Test in Mediterranean

September 3rd, 2013

Interesting time and place for a “missile test.”

So, what was this, really?

Via: Al Jazeera:

Russia has announced that its missile early warning system detected the launch of two missiles from the central part of the Mediterranean Sea fired towards the sea’s eastern coastline, and later confirmed in an Israel statement by Reuters news agency.

Israel initially denied knowledge of the missile launch, but soon after said in a statement to Reuters that it had carried out one joint missile test with the US, of an “anchor” target missile used in anti-missile systems, the news agency reported on Tuesday.

Israel said it carried out a test of a missile, used as a target in a US-funded anti-missile system, in the Mediterranean at (9:15am) 06:15GMT, around the same time quoted by Russian state-run news agency, RIA.

An official from the Israeli Defence Ministry later confirmed that both Israel and the US carried a joint missile test in the Mediteranean today.

Al Jazeera’s Paul Brennen, reporting from Jerusalem, said that the confirmation by Israel was unusual.

“It’s is highly unusual that Israel should be involved in this joint exercise, as it could draw Israel into the conflict.”


Fukushima: Japanese Government to Build Ice Wall in Desperate Attempt to Contain Leaks of Contaminated Water

September 3rd, 2013

For a moment, let’s just assume that this will work. I doubt that it will work, but let’s pretend that will.

What happens to all of the frozen slop when the grid goes down during the next disaster and the “ice wall” thaws out?

Have a nice day!

Via: AP:

The Japanese government announced Tuesday it is funding a costly, untested subterranean ice wall in a desperate step to stop leaks of radioactive water from the crippled Fukushima nuclear plant after repeated failures by the plant’s operator.

Public funding is part of several measures the government adopted Tuesday. Most had already been announced but they are widely seen as a safety appeal before the International Olympic Committee votes on which city will host the 2020 Olympics. Tokyo is a front-runner.

“Instead of leaving this up to TEPCO [Tokyo Electric Power Company], the government will step forward and take charge,” Prime Minister Shinzo Abe said after adopting the outline. “The world is watching if we can properly handle the contaminated water but also the entire decommissioning of the plant.”

The government plans to spend an estimated $470 million US through the end of 2014 on two projects — the ice wall and upgraded water treatment units that is supposed to remove all radioactive elements but tritium — according to energy agency official Tatsuya Shinkawa.

The government is not paying for urgently needed water tanks and other equipment that TEPCO is using to stop leaks.

The ice wall would freeze the ground to a depth of up to 30 metres through a system of thin pipes carrying a coolant as cold as minus -40 C. It would thus block contaminated water from escaping the facility’s immediate surroundings, as well as keep underground water from entering the reactor and turbine buildings, where most contaminated radioactive water has collected.

The project, which TEPCO and the government proposed in May, is set for completion by March 2015.

Related: Fukushima Radiation Levels 18 Times Higher than Previously Admitted


« Previous PageNext Page »