Showing posts with label cyberwarfare. Show all posts
Showing posts with label cyberwarfare. Show all posts

Saturday, December 23, 2017

Welcome To The Age Of The Information-Industrial Complex

Authored by James Cobett via The Corbett Report,


When WWII ended and the American deep state welded the national security establishment into place with the National Security Act, the world entered into a new era: the era of the military-industrial complex.


But when the Cold War ended and the “Clash of Civilizations” became the new existential threat, the deep state found an opening for another paradigm shift. As the all-pervasive threat of terrorism became the carte blanche for total surveillance, the powers-that-shouldn’t-be found the organizing principal of our age would not be military hardware, but data itself. Welcome to the age of the information-industrial complex.


“In the councils of government, we must guard against the acquisition of unwarranted influence, whether sought or unsought, by the military-industrial complex. The potential for the disastrous rise of misplaced power exists and will persist.”



It is not difficult to see why these words passed so quickly into the political lexicon. Think of their explanatory power.



Why did the US use inflated estimates of Russian missile capabilities to justify stockpiling a nuclear arsenal that was more than sufficient to destroy the planet several times over?


The military-industrial complex.


Why did America send 50,000 of its own to fight and die in the jungles of Vietnam, killing untold millions of Vietnamese (not to mention Cambodians)?


The military-industrial complex.


Why did the US use the public’s fear and anger over 9/11 and a phony panic over non-existent weapons of mass destruction to justify the illegal invasion and trillion-dollar occupation of Iraq?


The military-industrial complex.


Why did Nobel Peace Prize laureate Obama expand the fictitious “war on terror” into Pakistan and Yemen and Somalia, refuse to close Guantanamo despite his earlier promises to the contrary, commit US forces to “kinetic military action” in Libya without so much as seeking Congressional approval, and launch a new era of covert drone warfare?


The military-industrial complex.


Why has Trump not only continued but further expanded the US military presence in Africa, increased US aid to Israel and Saudi Arabiaactively enabled the war crimes in Yemen that have led to the largest cholera outbreak in human history, and killed more civilians in his first six months in office than former drone-king Obama killed in his entire eight-year presidency?


The military-industrial complex.


Image result for the information-industrial complex


When you think about it, it’s rather remarkable that such a phrase was ever uttered by a President of the United States, much less a former five-star general. Could you imagine any modern-day President talking about something like the “military-industrial complex” and its attempted “acquisition of unwarranted influence” without immediately dismissing the idea as a conspiracy theory? Over the decades there has been much speculation about Eisenhower’s use of the phrase, and what precisely he was warning against. Some have argued that the phrase was prompted by Eisenhower’s discovery that the Rand Corporation was grossly misrepresenting the Soviet’s military capabilities to John F. Kennedy, who ended up using the Rand invented (and completely fictitious) “missile gap” threat as a cornerstone of his 1960 presidential election campaign.


Whatever the case, it is perhaps time to revisit Eisenhower’s most famous speech. What Eisenhower is ultimately describing is the rise of American fascism; the merger of government and corporate power. What term can better capture the nature of early 21st century American political life? Is there any longer any doubt that the military-industrial complex has reached its ultimate expression in firms like Blackwater (aka “Xe” aka “Academi”) and its military contractor brethren? Is there any other word but “fascism” to describe a state of affairs when a Secretary of Defense can commission a study from a private contractor to examine whether the US military should be using more private contractors, only for that same Secretary of Defense to leave office and become president of the company that conducted the study, only to leave that company to become Vice President of the US and begin waging a war that relies heavily on no-bid contracts awarded to that same company based on the recommendation that it made in its original study? Yet this is precisely the case of Dick Cheney and Halliburton. It would be difficult to think of a more blatant example of the military-industrial complex fascism that Eisenhower was warning of.


But as it turns out, there was another warning about fascism embedded in that farewell address that has received far less attention than the “military-industrial complex” formulation, perhaps because there is no catchphrase hook to describe it:


“Today, the solitary inventor, tinkering in his shop, has been overshadowed by task forces of scientists in laboratories and testing fields. In the same fashion, the free university, historically the fountainhead of free ideas and scientific discovery, has experienced a revolution in the conduct of research. Partly because of the huge costs involved, a government contract becomes virtually a substitute for intellectual curiosity. For every old blackboard there are now hundreds of new electronic computers.”



Given that this warning came in 1961, before the age of communications satellites or personal computers or the internet, it was a remarkably prescient observation. If scientific research half a century ago was dominated by federal grants and expensive computer equipment, how much more true is that for us today, half a century later?


So what is the problem with this? As Ike explained:


“Yet, in holding scientific research and discovery in respect, as we should, we must also be alert to the equal and opposite danger that public policy could itself become the captive of a scientific-technological elite.”



Here, again, the warning is of fascism. But instead of the military-industrial fascism that dominated so much of the 20th century, he was describing here a new fascistic paradigm that was but barely visible at the time that he gave his address: a scientific-technological one. Once again, the threat is that the industry that grows up around this government-sponsored activity will, just like the military-industrial complex, begin to take over and shape the actions of that same government. In this case, the warning is not one of bombs and bullets but bits and bytes, not tanks and fighter jets but hard drives and routers. Today we know this new fascism by its innocuous sounding title “Big Data,” but in keeping with the spirit of Eisenhower’s remarks, perhaps it would be more fitting to call it the “information-industrial complex.”


The concept of an information-industrial complex holds equally explanatory power for our current day and age as the military-industrial complex hypothesis held in Eisenhower’s time.


Why is a company like Google going to such lengths to capture, track and database all information on the planet?


The information-industrial complex.


Why were all major telecom providers and internet service providers mandated by federal law to hardwire in back door access to American intelligence agencies for the purpose of spying on all electronic communications?


The information-industrial complex.


Why would government after government around the world target encryption as a key threat to their national security, and why would banker after banker call for bitcoin and other cryptocurrencies to be banned even as they plan to set up their own, central bank-administered digital currencies?


The information-industrial complex.


The effects of this synthesis are more and more felt in our everyday lives. Every single day hundreds of millions of people around the world are interfacing with Microsoft software or Apple hardware or Amazon cloud services running on chips and processors supplied by Intel or other Silicon Valley stalwarts. Google has become so ubiquitous that its very name has become a verb meaning “to search for something on the internet.” The 21st century version of the American dream is encapsulated in the story of Mark Zuckerberg, a typical Harvard whizkid whose atypical rise to the status of multi-billionaire was enabled by a social networking tool by the name of “Facebook” that he developed.


But how many people know the flip side of this coin, the one that demonstrates the pervasive government influence in shaping and directing these companies’ rise to success, and the companies’ efforts to aid the government in collecting data on its own citizens? How many know, for instance, that Google has a publicly acknowledged relationship with the NSA? Or that a federal judge has ruled that the public does not have the right to know the details of that relationship? Or that Google Earth was originally the brainchild of Keyhole Inc., a company that was set up by the CIA’s own venture capital firm, In-Q-Tel, using satellite data harvested from government Keyhole-class reconnaissance satellites? Or that the former CEO of In-Q-Tel, Gilman Louie, sat on the board of the National Venture Capital Association with Jim Breyer, head of Accel Partners, who provided $12 million of seed money for Facebook? Or that, in 1999, a back door for NSA access was discovered in Microsoft’s Windows operating system source code? Or that Apple founder Steve Jobs was granted security clearance by the Department of Defense for still-undisclosed reasons while heading Pixar in 1988, as was the former head of AT&T and numerous others in the tech industry?


The connections between the IT world and the government’s military and intelligence apparatus run deep. In fact, the development of the IT industry is intimately intertwined with the US Air Force, the Department of Defense and its various branches (including, famously, DARPA), and, of course, the CIA. A cursory glance at the history of the rise of companies like Mitre Corporation, Oracle, and other household electronics and software firms should suffice to expose the extent of these relations and the existence of what we might dub an “information-industrial complex.”


But what does this mean? What are the ramifications of such a relationship?


Although the signs have been there for decades, perhaps the most startling example of what lies at the heart of this relationship has been revealed by the whistleblowers at the heart of the National Security Agency, one of the most secretive arms of the American intelligence apparatus. While Edward Snowden has received the most attention with his “revelation” of the PRISM program, much of the information about the NSA’s ability to surveil all electronic communications has been revealed over the past decade by NSA whistleblowers like Russ TiceWilliam Binney, Thomas Drake and J. Kirk Wiebe, third-party contractors like Snowden and AT&T whistleblower Mark Klein, and independent journalists like James Bamford. Together, the story they tell is of a truly Orwellian society in which all communications are being captured and analyzed by the NSA, and, with the advent of facilities like the new data center in Utah, presumably stored indefinitely for use at any future time in any future investigation for any pretense by anyone with authorization to access that data. According to Snowden, this includes lowly third-party contractors like himself operating at NSA subcontractors like Booz Allen Hamilton in the vast (and expanding) private intelligence industry that has grown up around the information-industrial complex in the exact same way as private military contractors like Blackwater formed around the military-industrial complex.


In some ways, this information-industrial complex is even more insidious than its military-industrial counterpart. For all of the ills caused by the military-industrial complex (and there are many), at the very least it required some sort of excuse to drain the American people’s resources, and its failures (like the Vietnam quagmire or the debacle in Iraq) happened in the clear light of day. In the information-industrial complex, where vast spying programs happen in the shadows and under the cover of “national security,” it takes whistleblowers and insiders willing to risk it all even to find out what is being done by these shadowy agencies and their private-sector contractors. Even worse, the entire Orwellian spy grid is being run on the flimsiest of pretenses (the “war on terror”) that has no defined end point, and “justifies” turning that spy grid inward, on the American people themselves.


Surely Eisenhower never envisaged the monstrosity that this information-industrial complex has become, but the foresight he had in identifying its early stages over half a century ago is remarkable. The problem is that we are even further away from heeding the warning that he delivered in that 1961 address than we were at that time:


“It is the task of statesmanship to mold, to balance, and to integrate these and other forces, new and old, within the principles of our democratic system—ever aiming toward the supreme goals of our free society.”



If only this were the rhetoric that was shaping today’s debate on the issue, instead of the well-worn canard that we must “strike a balance” between freedom and security. Sadly, until such time as the National Security Act of 1947 is repealed and the cover of national security is lifted from the dark actors that populate this sector, the information-industrial complex is unlikely to be quashed—or even hampered—anytime soon.









Wednesday, December 20, 2017

North Korea Amassing Bitcoin To Fund Cyberattacks According To Crowdstrike CEO


Content originally published at iBankCoin.com


The CEO of cybersecurity firm Crowdstrike, George Kurtz, says North Korea is "absolutely" accumulating a giant pile of bitcoin to fund cyberattacks.

"They"re building a cache of bitcoin, if you think about it. It"s an anonymous currency, it can easily bypass any sort of sanctions because there are none on bitcoin, and the value has increased dramatically," Kurtz told CNBC"s "Squawk Alley." "It"s the perfect currency for North Korea to be hoarding." -CNBC



Can someone say "prohibited country" regulations?


The opinion comes on the heels of an op-ed in the WSJ by Homeland Security advisor Tom Bossert, who says North Korea was behind the WannaCry ransomware hack earlier this year, which demanded ransom in bitcoin.


The U.S. government has assessed with a "very high level of confidence" that a hacking entity known as Lazarus Group, which works on behalf of the North Korean government, carried out the WannaCry attack, said the official, who spoke on condition of anonymity to discuss details of the government"s investigation. -CNBC



The WannaCry hack is said to have cost billions, crippling hospitals, banks and companies around the world - and "highlights the capabilities that North Korea has in cyber," according to Kurtz.



Crowdstrike CEO on 2018 cyber threat outlook from CNBC.


Crowdstrike is the firm which analyzed the DNC servers and determined that Russia hacked them - however the Irvine, CA company came under fire in late 2016 when they had to retract a botched report on Russian hacking of Ukrainian artillery using the same "fancy bear" malware they also say the Kremlin used on the DNC servers.


The government of Ukraine issued a statement after the artillery report came out, calling it Fake News:


In connection with the emergence in some media reports which stated that the alleged “80% howitzer D-30 Armed Forces of Ukraine removed through scrapping Russian Ukrainian hackers software gunners,” Land Forces Command of the Armed Forces of Ukraine informs that the said information is incorrect.


Ministry of Defence of Ukraine asks journalists to publish only verified information received from the competent official sources. Spreading false information leads to increased social tension in society and undermines public confidence in the Armed Forces of Ukraine. –mil.gov.ua (translated) (1.6.2017)



So DHS"s Tom Bossert drops an op-ed on a North Korean hacking operation which only takes Bitcoin, and the CEO of Crowdstrike follows up with a stark warning on Bitcoin hoarding by Pyongyang. 




Follow on Twitter @ZeroPointNow § Subscribe to our YouTube channel


Friday, December 15, 2017

South Korea Braces For Terrorism At The 2018 Winter Games

It’s difficult not to empathize with South Korea right now: The country is preparing to host the Pyeongchang winter games in February – a moment of immense national pride – as the risks of a terrorist attack (not to mention nuclear annihilation) have intensified.


To wit, Reuters reports that the South Korean government is taking precautions to assuage the international community’s fears. Police conducted a series of security drills on Tuesday to prepare against terror attacks ranging from a hostage situation, a vehicle ramming a stadium and a bomb-attached to a drone.


South Korea Police and firemen were among around 420 personnel participating in the exercise, held in front of the Olympic Stadium at Pyeongchang, just 80 km (50 miles) from the heavily fortified border with North Korea as SWAT team members rehearsed a scenario where they shot down a drone with a bomb attached that was flying toward a bus carrying athletes.


In another situation, a terrorist takes a bus full of tourists hostage and tries to ram the vehicle into the stadium before being gunned down by police. Officers in gas masks also practiced removing a chemical bomb.



Anxiety on the Korean Peninsula has been rising in recent months due to a series of missile tests by North Korea as it continues its pursuit of nuclear weapons in defiance of UN sanctions and warnings from the US.


“Please keep in mind that accidents always happen where no one has expected,” South Korean Prime Minister Lee Nak-yon said.


 


“Please check until the last minute whether there are any security loopholes."



Lee did not mention North Korea, but South Korea’s Defense Ministry on Friday flagged risks that North Korea could resort to terrorist or cyber attacks to spoil international events.


Some 5,000 armed forces personnel will be deployed at the Winter Games, according to South Korean government officials and documents reviewed by Reuters.


Hacking is also a risk that the South Korean government is preparing for.


Pyeongchang’s organizing committee for the 2018 Games (POCOG) has also hired a private cyber security company to guard against a hacking attack from the North, tender documents show.


To minimize the risk of provoking an aggressive North Korean reaction during the games, South Korea has asked Washington to delay regular joint military exercises until after the Olympics, the Financial Times reported. The latest headlines suggest this request has been accepted and joint drills have been delayed until April.









Wednesday, December 13, 2017

Cyberattacks: The Biggest Threat To OPEC

Authored by Irina Slav via OilPrice.com,


Oil and cybersecurity in one sentence certainly makes for a thrilling read, and there will be an increasing amount of information on the topic as the Internet of Things expands and the global oil industry adopts automation and digital technology.



OPEC is no exception in this digitalization drive, but unlike its non-OPEC counterparts, the cartel has emerged as much more vulnerable to cybersecurity threats.


An analysis of data collected from 134 countries by the International Telecommunication Union has revealed that some of the world’s biggest oil producers, including Iraq, Saudi Arabia, Venezuela, Iran, and the UAE, are lacking in the cybersecurity department. This means that, compared to European producers and the United States, OPEC members are pretty much unprepared for a major cyberthreat.


What is the likelihood of such a threat actually materializing? Well, the general opinion in cybersecurity circles is that everything that can be hacked will be hacked at some point. Saudi Arabia’s oil and gas industry, for example, has been a favorite target for numerous attacks over the last few years, including the Shamoon virus, which in 2012 wiped clean the disks of more than 30,000 computers at Aramco, and according to reports from the cybersecurity industry, reared its ugly head again in 2016.


Overall, about half of all cyberattacks in the Middle East target the oil and gas industry, which suggests the answer to the above question is “Pretty high,” but the worse thing is that this likelihood is only going to get higher in the future. Related: Brent Spikes As This Major Pipeline Breaks Down


Middle Eastern producers are following in the footsteps of their non-OPEC counterparts in adopting digital technology and automation to improve efficiencies in the post-2014 world, where efficiency has come to the fore in oil and gas. The problem, of course, is that the more you digitalize, the more vulnerable you become to attacks through digital channels.


A recent study from Siemens and Ponemon Institute found that as digital tech adoption in the Middle East oil industry rises, so does cyber risk. What’s more, this risk is no longer limited to IT operations: the operational technology area is gaining prominence as a preferred target for cybercriminals.


The reason, according to Siemens and Ponemon Institute, is the convergence between IT and OT in the oil and gas industry. “Attackers have identified this convergence of IT and OT as a key opportunity to penetrate an organisation. As a result, an emerging trend of cyberattacks is designed to disrupt physical devices or processes used in operations. In a digital environment, industrial cyber is the new risk frontier,” says Siemens’ Vice President and Global Head of Industrial Cyber, Leo Simonovich.


The cybersecurity industry is sounding an alarm and it seems those in the Middle East that can afford it are hearing it and heeding the warning to improve their cybersecurity capabilities.


The UAE has a Dubai Cyber Security Strategy. Earlier this year, Saudi Arabia launched a National Cyber Security Center, and last month announced the set-up of a National Authority for Cyber Security, seeking to utilize international expertise and best practices to prop up government and critical infrastructure defenses. Iraq is seriously lagging behind and Iran is seen by cybersecurity insiders as more a source of cyberthreats than as a potential victim.


This sounds all well and good, but the trends in cybercrime point to a desperate need to do more. Cybercriminals do not sit on their hands while potential victims work to improve their defenses. While cybersecurity service providers continue to warn businesses and other organizations that they need to become more pro-active with regard to their cybersecurity measures, the hackers are coming up with new ways to undermine existing defenses. This is true for all industries, but it is especially true for oil and gas in the Middle East—national energy infrastructures are called critical for a reason, after all.









Wednesday, November 15, 2017

"FALLCHILL": DHS, FBI Release Details On North Korean Hacking Tools

As tensions between the U.S. and North Korea mount, the DHS and FBI have just issued a pair of technical alerts about cyber attacks which they say are sponsored by the North Korean government and that have been targeting the aerospace, telecommunications and financial industries since 2016.  According to the alert, North Korean hackers have used a type of malware referred to as “FALLCHILL” to gain entry to computer systems and compromise network systems.








Today, DHS and FBI released a pair of Joint Technical Alerts (TA17-318A and TA17-318B) that provide details on tools and infrastructure used by North Korea to target the media, aerospace, financial, and critical infrastructure sectors in the United States and globally.


 


The North Korean government malicious cyber activity noted in these alerts is part of a long-term campaign of cyber-enabled operations that impact the U.S. Government and its citizens. Working closely with our interagency, industry and international partners, DHS is constantly working to arm network defenders with the tools they need to identify, detect and disrupt state and non-state actors targeting the networks and systems of our country and our allies.



Per the pair of techinical alerts, the FALLCHILL malware provides hackers with wide latitude to monitor and disrupt infected networks. The malware typically gains access to systems as a file sent via other North Korean malware or when users unknowingly downloaded it by visiting sites compromised by the hackers.








FBI has high confidence that HIDDEN COBRA actors are using the IP addresses—listed in this report’s IOC files—to maintain a presence on victims’ networks and to further network exploitation. DHS and FBI are distributing these IP addresses to enable network defense and reduce exposure to any North Korean government malicious cyber activity.


 


This alert includes IOCs related to HIDDEN COBRA, IP addresses linked to systems infected with FALLCHILL malware, malware descriptions, and associated signatures. This alert also includes suggested response actions to the IOCs provided, recommended mitigation techniques, and information on reporting incidents. If users or administrators detect activity associated with the FALLCHILL malware, they should immediately flag it, report it to the DHS National Cybersecurity and Communications Integration Center (NCCIC) or the FBI Cyber Watch (CyWatch), and give it the highest priority for enhanced mitigation.


 


According to trusted third-party reporting, HIDDEN COBRA actors have likely been using FALLCHILL malware since 2016 to target the aerospace, telecommunications, and finance industries. The malware is a fully functional RAT with multiple commands that the actors can issue from a command and control (C2) server to a victim’s system via dual proxies. FALLCHILL typically infects a system as a file dropped by other HIDDEN COBRA malware or as a file downloaded unknowingly by users when visiting sites compromised by HIDDEN COBRA actors. HIDDEN COBRA actors use an external tool or dropper to install the FALLCHILL malware-as-a-service to establish persistence. Because of this, additional HIDDEN COBRA malware may be present on systems compromised with FALLCHILL.


 


During analysis of the infrastructure used by FALLCHILL malware, the U.S. Government identified 83 network nodes. Additionally, using publicly available registration information, the U.S. Government identified the countries in which the infected IP addresses are registered.



KJU


These latest technical alerts follow similar updates from DHS and the FBI from earlier this summer which highlighted malware they claimed North Korean hackers were utilizing to lauch DDoS attacks in the U.S.  Per The Hill:








The agencies identified IP addresses associated with a malware known as DeltaCharlie, which North Korea uses to launch distributed denial-of-service (DDoS) attacks.


 


The alert called for institutions to come forward with any information they might have about the nation’s cyber activity, which the U.S. government refers to as “Hidden Cobra.”


 


“If users or administrators detect the custom tools indicative of HIDDEN COBRA, these tools should be immediately flagged, reported to the DHS National Cybersecurity Communications and Integration Center (NCCIC) or the FBI Cyber Watch (CyWatch), and given highest priority for enhanced mitigation,” the alert reads.


 


The DHS and FBI also highlighted some vulnerabilities that North Korea has been known to exploit and recommended organizations upgrade to the latest versions of Adobe Flash Player, Microsoft Silverlight and Hangui Word Processor, or delete them altogether if the programs aren’t needed.



Of course, North Korea has routinely denied involvement in cyber attacks against other countries.









Monday, October 16, 2017

"Not The Russians" - British MPs Blame Iran For "Brute Force" Hack

Yet another purported example of Russia-linked hackers infiltrating the email accounts of powerful government officials    has been conclusively debunked.


The Guardian is reporting that a June incident where the accounts of dozens of UK ministers of parliament were infiltrated by shadowy hackers has been traced back to Iran. The UK intelligence community’s initial conclusion – that the attacks originated in Russia – has been refuted by an as-yet-unpublished report on the incident compiled by British intelligence.


Indeed, the intelligence community’s initial assumption appears to be another example of investigators jumping to a conclusion before a thorough analysis of the evidence has been completed. In a way, it echoes the response by several US states last month to the revelation that hackers had attempted to compromise their voting systems. Some states, including California and Wisconsin, apparently assumed the attacks were linked to Russia, until DHS informed them that it had found no evidence to support this conclusion.



The June 23 cyberattack affected the accounts of dozens of MPs, including Prime Minister Theresa May and several senior other senior ministers. The network that was compromised is used by every MP for interactions with constituents, the Guardian reported.


Initially, UK intelligence determined that hackers had attempted to gain access to accounts protected by weak passwords – despite repeated warnings to choose strong, hard-to-crack passwords.


An anonymous “security source” cited by the Guardian said the hackers used unsophisticated “brute force” attacks where the hackers use specifically designed programs to test out hundreds of thousands of different passwords combinations. “It was a brute-force attack. It appears to have been state-sponsored. The nature of cyber-attacks means it is notoriously difficult to attribute an incident to a specific actor.”


Conservative MP Andrew Bridgen added that the attack “absolutely” could leave some people open to blackmail. “Constituents want to know the information they send to us is completely secure,” he said.


Initially, suspicion had fallen upon foreign governments such as Russia and North Korea, both of which have been accused of orchestrating previous hacking attempts in the UK.


Liam Fox, the international trade secretary, said the incident reinforced the notion that MPs need to take extra precaution when securing their data.


“We know that our public services are attacked, so it is not at all surprising that there should be an attempt to hack into parliamentary emails,” he said. “And it’s a warning to everybody, whether they are in parliament or elsewhere, that they need to do everything possible to maintain their own cybersecurity.”


Given the furor that erupted after DHS ordered US government agencies to immediately remove security software designed by Russia-based firm Kaspersky Labs, the revelation about Iran’s involvement in the UK hacks should give intelligence agencies – not to mention lawmakers who seemingly blame Russia for every incidence of cyber meddling uncovered by US intelligence – pause. After the WSJ reported that Kaspersky’s software was essentially being leveraged by the Russian government to create an international spy network, German intelligence announced that they had found no evidence to support this claim.


And while many have blamed Russia-linked hackers for last year’s hack of DNC emails, including emails sent by Hillary Clinton Campaign Chairman John Podesta, Wikileaks’ Julian Assange is reportedly offering President Donald Trump conclusive evidence that he says would debunk this claim.


However, Chief of Staff John Kelly has rebutted one Congressman’s attempts to bring the deal to President Trump. But as the multiple investigations into whether Trump campaign colluded with the Russian government to sway the election in the president’s favor have apparently hit a wall, Assange’s evidence might be the key to silencing these suspicions, which have cast an unsubstantiated pall of illegitimacy over Trump’s first term in office.
 

Thursday, October 12, 2017

Germany Says It Found "No Evidence" Kaspersky Helped Russia Spy On US

US intelligence agencies are claiming that the Russian government leveraged the popularity of Kaspersky Labs’ cybersecurity software to create what is tantamount to a global spy network with the company’s explicit cooperation. However, Germany’s intelligence agencies say they’ve found “no evidence” to suggest these reports are true.


The Wall Street Journal, which last week reported that the US had identified at least one case of Kaspersky’s software improperly copying classified information, is back with another “exclusive” spoon fed to it by anonymous “senior US officials” alleging that Kaspersky allowed Russian government malware to piggy back on its software. The malware scanned for and copied files labeled “top secret,” not just in the US, but globally. Though WSJ neglects to list other countries that are suspected victims of Russian hacking.



Meanwhile, Germany"s BSI federal cyber agency said on Wednesday it had found no evidence to suggest that Russian hackers had used Kaspersky’s software to spy on US authorities. "There are no plans to warn against the use of Kaspersky products since the BSI has no evidence for misconduct by the company or weaknesses in its software," BSI said in an emailed response to questions about the latest media reports. "The BSI has no indications at this time that the process occurred as described in the media," according to Reuters.


Germany"s BSI, which also uses Kaspersky products for technical analyses, said it was in touch with U.S. officials and other security agencies about the issue so it could take action and issue a warning on short notice if required.





The Russian government used a popular antivirus software to secretly scan computers around the world for classified U.S. government documents and top-secret information, modifying the program to turn it into an espionage tool, according to current and former U.S. officials with knowledge of the matter.



The software, made by the Moscow-based company Kaspersky Lab, routinely scans files of computers on which it is installed looking for viruses and other malicious software. But in an adjustment to its normal operations that the officials say could only have been made with the company’s knowledge, the program searched for terms as broad as “top secret,” which may be written on classified government documents, as well as the classified code names of U.S. government programs, these people said.



After becoming suspicious that the Kaspersky software might be concealing malicious spyware, US intelligence agencies began scrutinizing the software, searching for signs that it was unknowingly copying and transmitting sensitive information.





For many months, U.S. intelligence agencies studied the software and even set up controlled experiments to see if they could trigger Kaspersky’s software into believing it had found classified materials on a computer being monitored by U.S. spies, these people said. Those experiments persuaded officials that Kaspersky was being used to detect classified information.



Later, WSJ notes that, in fact, it was Israeli intelligence that first alerted the US to Kaspersky’s skullduggery, effectively creating a separate, parallel narrative to explain how the deception was exposed.


So, which is it? Did the Israelis tell us? Or did the US discover the breach independently in 2015?


In an ironic twist, Kaspersky exposed Israel for lying about the source of its information on Iran deal talks after WSJ reported two years ago that Israel had spied on negotiations. Israel had said it received its intelligence by other means, but it had in reality infiltrated Kaspersky’s software, a fact the company publicly acknowledged in a research paper published two years ago.





In a twist, Kaspersky appears to have known, or at least suspected, that it had been hacked by Israel. In June 2015, the company published a detailed technical analysis about malicious computer code used to break into its systems, which it dubbed Duqu 2.0. Experts believe that the original Duqu malware, on which the one inside Kaspersky’s system appears to have been based, was used to spy on officials participating in international negotiations over Iran’s nuclear program, a fact that Kaspersky acknowledged in its paper.



The Journal reported in 2015 that Israel had spied on closed-door talks among the U.S. and other world powers about curtailing Iran’s nuclear ambitions. Israeli officials denied spying directly on U.S. negotiators and said they received their information through other means, including close surveillance of Iranian leaders receiving the latest U.S. and European offers.



Which begs the question: Is it possible that Israel was the source of the Kaspersky hack? The country has been exposed for spying on the US before – and not just during the Iran negotiations. And it has also been exposed for infiltrating Kaspersky’s systems.


Keep in mind, suspicions about the infiltration first emerged two years ago at a time of heightened tension between the Obama administration and Israel. In an unprecedented move, the Department of Homeland Security ordered all federal agencies using Kaspersky’s software to uninstall it, effectively ending Kaspersky’s relationship with one of its largest clients.  
 

Wednesday, October 11, 2017

North Korea Hackers Steal War Plans, Kim Jong-Un Assassination Details

While tensions with North Korea have receded in recent weeks, and especially following the latest uneventful weekend, when markets were on edge that Kim could try another missile test launch to celebrate the country"s national holiday, this could reverse following news from the BBC that North Korea hackers have reportedly stolen a large cache of military documents from South Korea, including a plan to assassinate North Korea"s leader Kim Jong-un.


According to South Korean lawmaker Rhee Cheol-hee - a member of South Korea"s ruling party who sits on its parliament"s defence committee - the compromised documents, which were stolen from the country"s defense ministry, include wartime contingency plans created by the US and South Korea, and also include reports to the allies" senior commanders. Plans for the South"s special forces are also said to have been accessed, along with information on significant power plants and military facilities in the South.


Rhee also said some 235 gigabytes of military documents had been stolen from the Defence Integrated Data Centre, and that 80% of them have yet to be identified.



Just like in the case of Equifax, the breach itself took place long ago, with South Korea waiting over a year to disclose the full details of the the hack which took place in September last year. In May, South Korea said a large amount of data had been stolen and that North Korea may have instigated the cyber attack - but gave no details of what was taken. The South Korean defence ministry has so far refused to comment about the allegation, while North Korea denied the claim.


According to South Korea"s Yonhap news agency reports that Seoul has been subject to a barrage of cyber attacks by its communist neighbour in recent years, with many targeting government websites and facilities. According to long-running media reports, which have yet to be confirmed with hard evidence however, the isolated, backward state is believed to have specially-trained hackers based overseas, including in China.


One thing that"s certain, is that tews that Pyongyang is "likely to have accessed the Seoul-Washington plans for all-out war" in the Koreas will do nothing to soothe tensions between the US and North Korea. The two nations have been at verbal loggerheads over the North"s nuclear activities, with the US pressing for a halt to missile tests and Pyongyang vowing to continue them.


Meanwhile, away from cyber war, Pyongyang has been far more aggressive in the realm of unconventional warfare, and the North recently claimed to have successfully tested a miniaturised hydrogen bomb, which could be loaded onto a long-range missile. In a speech at the UN in September, US President Donald Trump threatened to destroy North Korea if it menaced the US or its allies, and said its leader "is on a suicide mission".


Kim responded with a rare televized statement, vowing to "tame the mentally deranged US dotard with fire". Trump"s latest comment took the form of a cryptic tweet at the weekend, where he warned that "only one thing will work" in dealing with North Korea, after years of talks had proved fruitless. He did not elaborate further.

Wednesday, September 27, 2017

In Stunning Reversal, DHS Says Russians Were Not Behind Attempted Wisconsin Vote Hacking

Just in time for the weekend, the Associated Press reported on Friday that the Department of Homeland Security had notified 21 states earlier that day that their election systems had been targeted by malicious cyber actors. The states and DHS quickly jumped to the conclusion that Russia had ordered the cyberattacks, even though it was reported that the identity or identities of the perpetrators were inconclusive Yet, the news spread like wildfire after readers had been primed as reports of possible infiltartion of state election systems had circulated for nearly a year. Even so, for many states, the call Friday from the Department of Homeland Security was the first official confirmation that their election systems had, in fact, been targeted by hackers.


Federal officials said that in most of the 21 states, the targeting was preparatory activity such as scanning computer systems.



But in a stunning reversal - one which we doubt will put endless rumors of Russian cyberinterference to bed - the AP now reports that DHS has told Wisconsin that the Russian government was not involved in the cyber-targeting.


In an email to the state’s deputy elections administrator that was provided to reporters at the Wisconsin Elections Commission meeting on Tuesday, Homeland Security said that initial notice of Russian involvement was made in error. Also, as we noted at the time, the government did not originally assign blame to the Russians when news of the alleged "scanning" initially broke on Friday although most medias jumped at the opportunity to blame Putin.


Infuriated by the error, some state officials said that DHS should provide an expalanation for the errror, or at least issue an apology to state elections officials, who were understandbly unnerved by the news of Russian involvement.





“Based on our external analysis, the WI IP address affected belongs to the WI Department of Workforce Development, not the Elections Commission,” said the email from Juan Figueroa, with Homeland Security’s Office of Infrastructure Protection.


It wasn’t immediately known if Homeland Security made similar mistakes with any of the other 20 states. Figueroa did not immediately reply to an email seeking an explanation of how the mistake was made.


Homeland Security initially told the Elections Commission that the Russians scanned the state’s internet-connected election infrastructure, likely seeking specific vulnerabilities to access voter registration databases.


“Either they were right on Friday and this is a cover up, or they were wrong on Friday and we deserve an apology,” Mark Thomsen, the commission’s chairman, said in light of the new email.



Wisconsin’s chief elections administrator Michael Haas told AP that Homeland Security had assured the state that it had not been targeted - by Russians, or anybody else, for that matter.





“Wisconsin was not provided any information that indicated before the November election that Russian government actors were targeting election systems,” Haas said. He said one theory is that Homeland Security saw suspicious activity from IP addresses targeting state election systems in other states and assumed that was the intent in Wisconsin as well.



Others were apparently in shock: “It’s been a difficult process trying to piece all of this together,” said Wisconsin Elections Commission spokesman Reid Magney. “We’re trying to understand what happened.”


Furthermore, Wisconsin’s chief information officer, David Cagigal, told the elections commission that Wisconsin had never been told by Homeland Security, prior to the Friday notice, that Russians had targeted Wisconsin’s election system or anything else. Deputy information officer, Herb Thompson, said Homeland Security told the state in October to check on a certain IP address that the state had blocked from accessing its systems in August 2016.





“We have never seen any of those activities result in anything other than someone trying to turn the doorknob to see if a door is open,” Thompson said. “Those IP addresses we talked about, we had blocked, they were related to non-election systems.” Cagigal said, “Our systems were protected and we had no incidences.”



Still, the state"s election commission has promised to improve security before the midterms next year. Reports that Russians may have targeted, or infiltrated, state voting systems have been circulating since late last year, when the Washington Post published a story about alleged Russian infiltration in Vermont, only to retract the story shortly after. 


While we doubt that this will be the last "Russia hacked the elections" fake news, it is reassuring that all this frenzied chaos will at least bring some security to America"s voting systems. Security enhancements being considered include encrypting the entire voter registration database to protect the information and make it unusable to anyone who may be able to steal it and requiring two-factor authentication for the roughly 3,000 local and state officials who have access to the WisVote system.


Perhaps an appropriate question is why this wasn"t done before?

Tuesday, September 26, 2017

Massive Hack At Deloitte: Entire Internal Email System Compromised, Client Emails Exposed

Another day, another major hacking.


The Guardian reports that in the latest corporate cyber breach, one of the world’s “big four” accounting and consultancy firms, Deloitte, was been targeted by a sophisticated hack that "compromised the confidential emails and plans of some of its blue-chip clients." And just like Equifax, New York-headquartered Deloitte was similarly the victim of a cybersecurity attack that went unnoticed for months. The Guardian understands Deloitte discovered the hack in March this year, but it is believed the attackers may have had access to its systems since October or November 2016.


Responding to questions from the Guardian, Deloitte confirmed it had been the victim of a hack but insisted only a small number of its clients had been “impacted”. It would not be drawn on how many of its clients had data made potentially vulnerable by the breach. Alas, the company has yet to provide a full disclosure of just who and which clients were violated: an estimated 5 million emails were in the hacked email cloud and could have been been accessed by the hackers. Deloitte said the number of emails that were at risk was a fraction of this number but declined to elaborate.


While unlike Equifax Deloite is not a public public company and is not accountable to countless shareholders, with $37 billion in revenue last year and over 263,000 worldwide employees, Deloitte is a corporate behemoth which provides auditing, tax consultancy and - like Equifax - high-end cybersecurity advice to some of the world’s biggest banks, multinational companies, media enterprises, pharmaceutical firms and government agencies.  Here the Guardian reports that Deloitte clients "across all of these sectors had material in the company email system that was breached. The companies include household names as well as US government departments."





So far, six of Deloitte’s clients have been told their information was “impacted” by the hack. Deloitte’s internal review into the incident is ongoing.



The hacker compromised the firm’s global email server through an “administrator’s account” that, in theory, gave them privileged, unrestricted “access to all areas”.



Embarrassingly, the administrator level hack required only a single password and did not have “two-step“ verification, much like Deloitte and other companies strongly urge everyone to do.


As the Krebs on Security blog separately notes, "according to a source close to the investigation, the breach dates back to at least the fall of 2016, and involves the compromise of all administrator accounts at the company as well as Deloitte’s entire internal email system"





The source told KrebsOnSecurity they were coming forward with information about the breach because, “I think it’s unfortunate how we have handled this and swept it under the rug. It wasn’t a small amount of emails like reported. They accessed the entire email database and all admin accounts. But we never notified our advisory clients or our cyber intel clients.



This same source said forensic investigators identified several gigabytes of data being exfiltrated to a server in the United Kingdom. The source further said the hackers had free reign in the network for “a long time” and that the company still does not know exactly how much total data was taken.



Penetrating the unknown number of emails involved breaching the Microsoft cloud used the by the company. Emails to and from Deloitte’s 244,000 staff were stored in the Azure cloud service, which was provided by Microsoft. This is Microsoft’s equivalent to Amazon Web Service and Google’s Cloud Platform.


In addition to emails, the Guardian adds the hackers had "potential access to usernames, passwords, IP addresses, architectural diagrams for businesses and health information. Some emails had attachments with sensitive security and design details."


Until today"s report, the hack had been disclosed to the public: the breach, which was US-focused, was regarded as so sensitive that only a handful of Deloitte’s most senior partners and lawyers were informed.





The team investigating the hack is understood to have been working out of the firm’s offices in Rosslyn, Virginia, where analysts have been reviewing potentially compromised documents for six months.



It has yet to establish whether a lone wolf, business rivals or state-sponsored hackers were responsible.



Translation: while Putin wasn"t accused of hacking Equifax, he may yet get the blame this time.


Making this breach even more complicated, it is still unknown what information the hackers acquired: Guardian sources said if the hackers had been unable to cover their tracks, it should be possible to see where they went and what they compromised by regenerating their queries. This kind of reverse-engineering is not foolproof, however.





“In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,” a spokesman said. “As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators.



“The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers. We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required."



“Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”



Deloitte declined to say which government authorities and regulators it had informed, or when, or whether it had contacted law enforcement agencies.


Of course, as noted above, the breach is a deep embarrassment for Deloitte, which offers clients advice on how to manage the risks posed by sophisticated cybersecurity attacks. If only the company had followed its own advice.  Even more awkward, in 2012 Deloitte was ranked the best cybersecurity consultant in the world and has a “CyberIntelligence Centre” to provide clients with “round-the-clock business focussed operational security." It is unclear if that unit was also hacked.


While we await an official statement from Deloitte, what comes next is lots of lawsuits and even more settlements. According to the Guardian, on 27 April Deloitte hired US law firm Hogan Lovells on “special assignment” to review what it called “a possible cybersecurity incident”. The Washington-based firm has been retained to provide “legal advice and assistance to Deloitte LLP, the Deloitte Central Entities and other Deloitte Entities” about the potential fallout from the hack.

Saturday, September 9, 2017

Hackers Can Now Cause Blackouts On America's Electrical Grid, Report

It was inevitable that someday, hackers would have the ability to exert control over the U.S. electrical grid.  According to the computer security firm Symantec, someday is today.



Hacking attacks over the last several months that targeted U.S. energy companies have been able to gain "operational control" over systems, thus threatening blackouts across the U.S., says Symantec.


 The hacker group known as DragonFly 2.0 was able to gain control in at least 20 places, according to the firm.


Wired:





Symantec on Wednesday revealed a new campaign of attacks by a group it is calling Dragonfly 2.0, which it says targeted dozens of energy companies in the spring and summer of this year. In more than 20 cases, Symantec says the hackers successfully gained access to the target companies" networks. And at a handful of US power firms and at least one company in Turkey – none of which Symantec will name – their forensic analysis found that the hackers obtained what they call operational access: control of the interfaces power company engineers use to send actual commands to equipment like circuit breakers, giving them the ability to stop the flow of electricity into US homes and businesses.



"There"s a difference between being a step away from conducting sabotage and actually being in a position to conduct sabotage ... being able to flip the switch on power generation," says Eric Chien, a Symantec security analyst. "We"re now talking about on-the-ground technical evidence this could happen in the US, and there"s nothing left standing in the way except the motivation of some actor out in the world."



Never before have hackers been shown to have that level of control of American power company systems, Chien notes. The only comparable situations, he says, have been the repeated hacker attacks on the Ukrainian grid that twice caused power outages in the country in late 2015 and 2016, the first known hacker-induced blackouts.



Security firms like FireEye and Dragos have pinned those Ukrainian attacks on a hacker group known as Sandworm, believed to be based in Russia. But Symantec stopped short of blaming the more recent attacks on any country or even trying to explain the hackers" motives. Chien says the company has found no connections between Sandworm and the intrusions it has tracked. Nor has it directly connected the Dragonfly 2.0 campaign to the string of hacker intrusions at US power companies – including a Kansas nuclear facility – known as Palmetto Fusion, which unnamed officials revealed in July and later tied to Russia.



Chien does note, however, that the timing and public descriptions of the Palmetto Fusion hacking campaigns match up with its Dragonfly findings. "It"s highly unlikely this is just coincidental," Chien says. But he adds that while the Palmetto Fusion intrusions included a breach of a nuclear power plant, the most serious DragonFly intrusions Symantec tracked penetrated only non-nuclear energy companies, which have less strict separations of their internet-connected IT networks and operational controls.



The first question I would want answered is, if they have that sort of control, why not exercise it?  Why no blackouts or service interruptions in the U.S.?


Hacking Sony or another private business is one thing.  Fooling with our electrical infrastructure is many orders of magnitude more serious.  If a sovereign nation were behind such an event, it would be tantamount to a declaration of war.  Unless the attacking nation was supremely confident that the hack couldn"t be traced back to it, the nation would be unlikely to attempt it.


Causing a blackout in a major urban area would almost certainly result in many deaths.  We know this from previous blackouts in New York City, where the 2003 power outage is estimated to have resulted in 100 deaths.  This would be intolerable, and if the attack could be traced back to Russia or China, it would result in retaliation by the U.S.  We"re no slouches ourselves when it comes to cyber-warfare, and we could almost certainly make any country pay dearly.


But in a time of war, that kind of control over our electrical grid could wreak havoc and sow confusion and fear among the populace.  In the meantime, it would behoove the government to work with industry to harden our systems to prevent that kind of catastrophe.

Monday, July 24, 2017

David Stockman Has Had Enough: "Brennan, Rice, Power - Lock Them All Up!"

Authored by David Stockman via LewRockwell.com,


We frequently hear people say they have nothing to hide - so surrendering privacy and constitutional rights to the Surveillance State may not be such a big deal if it helps catch a terrorist or two. But with each passing day in the RussiaGate drama we are learning that this superficial exoneration is dangerously beside the point.


We are referring here to the unrelenting witch hunt that has been unleashed by Imperial Washington against the legitimately elected President of the United States, Donald J. Trump. This campaign of lies, leaks and Russophobia is the handiwork of Obama’s top national security advisors, who blatantly misused Washington’s surveillance apparatus to discredit Trump and to effectively nullify America’s democratic process.


That is, constitutional protections and liberties were systematically breached, but not simply to intimidate, hush or lock up citizens one by one as per the standard totalitarian modus operandi. Instead, what has happened is that the entire public debate has been hijacked by the shadowy forces of the Deep State and their partisan and media collaborators.


The enabling culprits are Obama’s last CIA director, John Brennan, his national security advisor Susan Rice and UN Ambassador Samantha Power. There is now mounting evidence that it was they who illegally “unmasked” NSA intercepts from Trump Tower; they who confected the Russian meddling narrative from behind the protective moat of classified intelligence; and they who orchestrated a systematic campaign of leaks and phony intelligence reports during the presidential transition—-all designed to delegitimize Trump before he even took the oath of office.


So all three of them should be locked­up—-that’s for sure. But the more urgent solution would be to unlock and make public all the innuendo, surmises, assessments, half-truths and boilerplate intelligence chatter on which the entire false narrative about Russian meddling and collusion is based.


Stated differently, without the nation’s massive intelligence apparatus and absurd system of secrecy and classified information to hide behind, the RussiaGate witch hunt would have never gotten off the ground.


In truth, as we will essay below, there is no there, there. So what this new chapter in McCarthyite hysteria actually demonstrates is that the Imperial City’s far-flung, 17-agency, $75 billion Intelligence Behemoth is a plenary threat not just to individual liberty, but to the very constitutional democracy on which the latter depends.


To appreciate the severity of the threat, it is necessary to recognize that the post-9/11 Deep State has lowered a double whammy on our system. That is, it unconstitutionally collects the entirety of all internet based communications of America’s 325 million citizen, while at the same time it has effectively disenfranchised 98% of the 535 members of the House and Senate who have been elected to represent them.


Accordingly, behind the Surveillance State’s vast wall of secrecy and so-called “classified” information, there operates a Dark Government that is unaccountable to the public and largely unconstrained by normal constitutional limits, which the Patriot Act and secret FISA courts have more or less suspended.


In the realm of this Dark Government, the heart of American democracy—-the US Congress—has been completely usurped. Almost everything behind the secrecy wall is off limits to the rank and file. Only a handful of intelligence committee members and the House and Senate leadership gets sworn into the classified intelligence.


Yet just consider the hideous asymmetry of this arrangement. The so-called “Gang of Eight,” comprising the heads of the intelligence oversight committees and their respective party leadership, gets orally briefed in a secure “vault”, where they can’t take notes or carry-out any documents.


Moreover, this select handful of legislators consists of the incessantly mobilized and frazzled potentates of Capitol Hill who are always knee-deep in a thousand other distractions—-including a heavy quotient of politicking, fund-raising, and campaign trail excursions.


On the inside of the Surveillance State wall, by contrast, there are 600,000 employees or contractors with “top secret” security clearances alone; and more than 4 million total operatives who spend night and days feasting on the $75 billion Intelligence Community (IC) budget and carrying out projects and missions designed to justify their existence and keep the budgetary gravy train flowing.


For example, in the National Security Agency (NSA) there is a subsidiary entity called TAO (Targeted Access Operations) with a budget of several billions and more than 1,000 employees. The latter predominately consist of high-powered civilian and military hackers, computer geeks, intelligence analysts, targeting specialists, computer hardware and software designers and electrical engineers—-whose job it is to do exactly what Russia is being accused of.


Namely, to hack and electronically infiltrate the communications and operations of nearly every government on the planet, and most especially those of IC designated enemies and adversaries such as Russia and Iran.Indeed, TAOs motto says it all:





“Your data is our data, your equipment is our equipment ­ anytime, any place, by any legal means.”



In any given 24-hour day, the TAO hacks and deposits more disinformation and malware into its targeted foreign networks than all the low level Russian probes that were intercepted by NSA during the entire Presidential campaign.


In other words, Washington is the mother of all hackers and cyber-warfare operations, and what Russia and other nations do is only a small potatoes version of the same. Yet the overwhelming share of these digital cloak and dagger operation by all sides is a huge waste of national resources; and most especially it is of no value at all to the safety of the American people.


That because Russia, China and Iran—-the principal targets of the IC’s massive surveillance and cyber warfare activities—are no threats whatsoever to America’s security.


Iran has zero military capacity to attack the American homeland, and the claim that it is the leading sponsor of terrorism is pure bunkum. That hoary claim has been concocted by the Washington neocons and the Netanyahu political machine—both of which need demonized enemies in order to nurture the public fears on which their power is based.


Likewise, Russia has one 40-year old smoke-belching aircraft carry and a fleet of rowboats—–neither of which are capable of launching an assault on the New Jersey shores. True, it does have about 1,00o nuclear warheads; but where is the evidence that cool-hand Vlad is contemplating national suicide by using them against the US or Europe?


The purported Chinese threat is even more ludicrous. Notwithstanding the fertile imaginations of the Deep State fear-mongers who believe the South China Sea is actually an American Lake, the Red Suzerains of Beijing know fully well that without the continuous custom of Wal-Mart and Amazon warehouses, the Red Ponzi would collapse in a heartbeat. And that they would be hung by angry mobs from the CCTV (China Central Television) Tower shortly thereafter.


In fact, we don’t need the $75 billion Surveillance State to deal with the Taliban, the jihadist warlords of Somalia or any of the warring Sunni vs. Shiite (Houthis) parties of Yemen, either. They do not threaten America’s security in the slightest.


Nor did the government of Khadafy in Libya after he turned in his nukes. Likewise, the Assad regime has never, ever threatened to harm America—-despite the non-stop vilification from Washington.


At most, Washington needs modest local and theatre level capacity to monitor the fading remnants of the Islamic State—-a temporary scourge in the mostly the impoverished Sunni villages of the Upper Euphrates, which would not even exist in the first place had it not been fostered and armed with the weapons the US Army left behind in the fiasco of Iraq.


So consider the contrafactual. In the absence of a vast Warfare State apparatus and associated Surveillance State wall of secrecy what would RussiaGate amount to?


The answer is straight-forward: It was nothing more than a politically motivated plot orchestrated by former CIA director Brennan to undermine the Presidential campaign of a rambunctious outsider. That is, the Donald was unschooled in the groupthink of the Imperial City and had enough common sense to realize that Putin is not our enemy, that NATO is obsolete, that regime change has been a fiasco and that foreign policy should be based on homeland security first, not the perpetuation of an American Empire abroad.


Those inchoate impulses were the Donald’s original sin, and it was unverified and self-serving “intelligence” from the Latvian security service—-of all things—- that provided the pretext for Brennan to launch the Deep State’s own version of jihad against Trump.


What this dubious intelligence did was to finger Vlad Putin himself and that was crucial. It permitted Brennan to puff-up the evidence of run-of-the-mill cyber intrusions by the Russian security services—-or even unconnected Russian hackers and profiteers— into a sweeping but phony narrative about an attack on American democracy with Putin at the very center.


As Scott Ritter—- the weapons expert who blew the whistle on the IC’s trumped up claims about Saddam’s WMDs—-succinctly explained in a recent article, Brennan proceeded to turn a dubious molehill into a vertiable mountain:





According to reporting from the Washington Post, sometime during this period, CIA Director John Brennan gained access to a sensitive intelligence report from a foreign intelligence service. This service claimed to have technically penetrated the inner circle of Russian leadership to the extent that it could give voice to the words of Russian President Vladimir Putin as he articulated Russia’s objectives regarding the 2016 U.S. Presidential election — to defeat Hillary Clinton and help elect Donald Trump, her Republican opponent. This intelligence was briefed to President Barack Obama and a handful of his closest advisors in early August, with strict instructions that it not be further disseminated.



The explosive nature of this intelligence report, both in terms of its sourcing and content, served to drive the investigation of Russian meddling in the American electoral process by the U.S. intelligence community. The problem, however, was that it wasn’t the U.S. intelligence community, per se, undertaking this investigation, but rather (according to the Washington Post) a task force composed of “several dozen analysts from the CIA, NSA and FBI,” hand­picked by the CIA director and set up at the CIA Headquarters who “functioned as a sealed compartment, its work hidden from the rest of the intelligence community.”



The result was a closed­circle of analysts who operated in complete isolation from the rest of the U.S. intelligence community. The premise of their work — that Vladimir Putin personally directed Russian meddling in the U.S. Presidential election to tip the balance in favor of Donald Trump — was never questioned in any meaningful fashion, despite its sourcing to a single intelligence report from a foreign service.



President Obama ordered the U.S. intelligence community to undertake a comprehensive review of Russian electoral meddling. As a result, intelligence analysts began to reexamine old intelligence reports based upon the premise of Putin’s direct involvement, allowing a deeply disturbing picture to be created of a comprehensive Russian campaign to undermine the American electoral process.



Here’s the thing. Vlad didn’t do it. The only interference in the electoral process that he has been associated with is with respect to what Imperial Washington did next door while he was basking in glory at the Sochi Olympics in February 2014.


To wit, the violent coup on the streets of Kiev was organized by agents and organs of the US government; overthrew a constitutionally elected President who had decided to make an economic and security deal with Russia rather than Europe and NATO in keeping with Ukraine’s economic propinquity to the former and its 700- years of history as an integral part of Greater Russia; and which imposed a new government, hand-picked by the Obama State Department, which was dominated by Ukrainian nationalists and neo-Nazis who were demonstrably hostile to the Russian speaking populations of Crimea and the Donbas region of eastern Ukraine.


Stated differently, Imperial Washington is the world champion meddler in other peoples’ politics and elections.


Since the CIA sponsored coup against the Mosaddegh government in Iran in 1953, it has sponsored more than eighty incidents ranging from election bag money to military coups.


By contrast, the putative Russian attack on American democracy consists of three specific accusations—all of which are readily refutable.





In the first place, Podesta’s password was “password” and could have been hacked by any fat guy, or not, on any computer plugged into the worldwide web anywhere.



Moreover, Julian Assange of Wikileaks, who makes a living disclosing the truth, not propagating lies as does the IC, says it did not come from Russian state agents; and that it was in fact leaked, not hacked, by disgruntled Democrat insiders.



In any event, if it had actually been hacked by either Russian agents or the proverbial fat guy, there would be a digital imprint stored in NSA’s vast server farms. The fact that it hasn’t leaked amidst all the rest of the anti-Russian innuendo and intelligence hearsay proves beyond much doubt that no such record exists and no such Russian intrusion ever happened.



As for the DNC emails, the smoking gun there still smolders in plain sight. The FBI apparently never even took custody of the DNC computer—–farming out the job to an outfit named Crowdstrike. Alas, the latter is a DNC contractor and wannabe silicon valley IPO run by some fanatical Russian ex-pats looking for fame and fortune. It’s no wonder they didn’t want the FBI second guessing their conclusions.



Finally, there is the Latvian “intelligence” morsel about Putin’s personal direction of the election meddling campaign. If the Donald had any common sense he would declassify said report forthwith.



But never mind. It surely doesn’t exist anyway—-or it too would have leaked long ago.



And that’s all she wrote. The rest is pure spin leaked by Trump’s enemies in the Deep State and canonized by its collaborators in the main stream media.


Unfortunately, the Donald doesn’t seem to recognize that he is actually President. If he did, he would have the Justice Department launch a prosecution against the faithless officials—-Brennan, Rice and Power—-who concocted the whole RussiaGate defamation in the first place.

Saturday, July 15, 2017

Mysterious Hacker Leaks Emails Of Top US State Department Expert On Russia

Coming at a "sensitive" moment for US-Russian hacking diplomatic relations, on Friday Foreign Policy reported that emails belonging to a senior US State Department intelligence official involved in Russian affairs have been leaked by a hacker known as "Johnnie Walker." The official, whose work is focused on Russian domestic affairs and who was described to FT as “probably the top intelligence guy in the entire U.S. government on Russia [who] knows more than anybody about what’s going on there,” is said to have been particularly interested in Russian media and government reshuffling.


The emails which were sourced from a hacked nongovernmental account over a two-year period, were sent to “an unknown number of recipients" and while the leaks were first released on July 10, they did not gain widespread attention until Friday when both FP and Newsweek commented on the hack.


In a letter announcing the alleged hacking, Johnnie Walker said that the leak would provide evidence for establishing what was called “agenda formation in many countries worldwide, especially where the situation is insecure.” The sender also claimed that the US State Department official was in contact with various intelligence agencies, including the CIA, as well as “mainstream media, NGOs, and international funds.”


Although the alleged hacking victim holds “a senior position in the State Department’s Bureau of Intelligence and Research” and while name was disclosed in the leaked emails, Foreign Policy outlet did not disclose the name, citing a request from the state department, which has so far neither confirmed nor denied the hack. The leaked correspondence was released online on Pastebin although its authenticity remains unclear for now. The description to the three archives available for download also adds the name of the alleged agent.


As part of his introduction to the leaked emails, the mysterious hacker says that “perhaps you know that the U.S. State Department has a direct bearing on the agenda formation not only at home but throughout the world. Now you can make sure it’s true." Below is the preface that "Johnnie Walker" posted on the pastebin:





Perhaps you know that the U.S. State Department has a direct bearing on the agenda formation not only at home but throughout the world.



Now you can make sure it"s true. Let me show you the correspondence between the Deputy Chief of Staff for Intelligence, Surveillance and Reconnaissance Agency Robert P. Otto and his colleagues, CIA officers and other intelligence agencies, as well as representatives of mainstream media, NGOs, international funds and think tanks.



With the respect for privacy I"ve deleted his correspondence with his wife and relatives. The rest of emails will give evidence of who is responsible for different information campaigns, the so-called mythmaking and essentially engaged in the promotion of "American values" throughout the world.



As a reminder, two days before the find round of the French election, a dump of internal documents of then-French presidential hopeful Emmanuel Macron was also released on Pastebin, although it is unclear if the two releases are related. Apart from the name of the hacker’s target, the content of the letters has not been published in the Western media, although Russia"s Kommersant claims it has access to the files.


The Russian newspaper says that the intel official sent his colleagues links to articles from different Russian news outlets, including Novaya Gazeta, The New Times, Vedomosti, and RBK, among others. Among the topic of particular interest for the State Department official were social media accounts of Russian officials, staff re-shuffling in governmental bodies, and the influence of some state officials. According to the report, it is also unclear if it was a single leak or only one in a series of hacking attacks.


As Redditor NathanOhio summarized overnight, the facts so far appear to be as follows:


  1. A hacker going by the name "Johnnie Walker" has hacked a senior state department official"s personal Gmail account.

  2. The official has not been publicly named, but is claimed to be the foremost expert on Russia.

  3. Two years worth of emails were stolen and include exchanges between the victim and "CIA officers and other intelligence agencies, mainstream media, NGOs and international funds” that would “give you evidence of who is responsible for agenda formation in many countries worldwide, especially where the situation is insecure.”

  4. A link to the email cache has been published by "an obscure website in Crimea" that the MSM claims is "financed by the Russian secret service, and its topics assigned by top political leadership in Moscow."

In retrospect, it appears that the email contents are relatively innocuous: as the Redditor notes:





Reading through some of the messages, it seems they are mostly discussions between various neocon academics and forwarding of articles. Most of these people rather than experts seem to be groupthinkers endlessly building up the walls of their own echo chamber.



Found a couple of things that are interesting. A Russian scholar "Valery Solovei" is sending Robert Otto a monthly report on Russia. Also, Otto and his buddies HATE John Kerry and continually refer to him as an idiot!



With the Trump administration neck-deep in Russia-hacking drama, we expect that this story, which somehow failed to make last week"s news cycle will be among the main topics in the days ahead, with questions (and predetermined answers) over the identity (and nationality) of Johnnie Walker among the most discussed items.