Showing posts with label Shadow Brokers. Show all posts
Showing posts with label Shadow Brokers. Show all posts

Tuesday, November 14, 2017

The deepest of the deep state agencies is deeply vulnerable

The story of the Shadow Brokers hacking the NSA.


Bottom line from Charlie Pierce:
In brief, these people hacked our hackers, and the problem seems to have been that the NSA was so bent on offensive cyber operations that it neglected to defend its own people and property. So, when the NSA hackers themselves got hacked, apparently by people who simply are better at it than the NSA’s people are, the door to the vault where the family jewels are kept was wide open. Money well-spent again. Now, the agency is convulsed in a hunt for moles and trolls in its own ranks, an exercise that, in the hothouse environment of an intelligence agency, almost is guaranteed to spread suspicion and demolish morale, if history is any guide.

And because, last November, we chose to elect a vulgar talking yam to be president*, even this episode carries with it the distinct sound of a carnival calliope summoning the suckers to the midway.

 Charles P Pierce
P.S.  Shadow Brokers appear to be a group pissed off that Trump didn't do all the things he said he would to restore white supremacy to the States.

P.P.S.  Could this be the work of the "second leaker" referenced in Laura Poitras' documentary about Edward Snowden?
Current and former agency officials say the Shadow Brokers disclosures, which began in August 2016, have been catastrophic for the N.S.A., calling into question its ability to protect potent cyberweapons and its very value to national security. The agency regarded as the world’s leader in breaking into adversaries’ computer networks failed to protect its own.

[...]

Created at huge expense to American taxpayers, those cyberweapons have now been picked up by hackers from North Korea to Russia and shot back at the United States and its allies.

[...]

Tens of thousands of employees at Mondelez International, the maker of Oreo cookies, had their data completely wiped. FedEx reported that an attack on a European subsidiary had halted deliveries and cost $300 million. Hospitals in Pennsylvania, Britain and Indonesia had to turn away patients. The attacks disrupted production at a car plant in France, an oil company in Brazil and a chocolate factory in Tasmania, among thousands of enterprises affected worldwide.

American officials had to explain to close allies — and to business leaders in the United States — how cyberweapons developed at Fort Meade in Maryland came to be used against them. Experts believe more attacks using the stolen N.S.A. tools are all but certain.

[...]

Three employees have been arrested since 2015 for taking classified files, but there is fear that one or more leakers may still be in place. And there is broad agreement that the damage from the Shadow Brokers already far exceeds the harm to American intelligence done by Edward J. Snowden, the former N.S.A. contractor who fled with four laptops of classified material in 2013.

[...]

Much of the agency’s arsenal is still being replaced, curtailing operations. Morale has plunged, and experienced specialists are leaving the agency for better-paying jobs — including with firms defending computer networks from intrusions that use the N.S.A.’s leaked tools.

“It’s a disaster on multiple levels,” Mr. Williams said. “It’s embarrassing that the people responsible for this have not been brought to justice.”

  NYT
They've been pretty quiet about it. Or maybe most journalists are just focused on the Trump administration debacle.
Some veteran intelligence officials believe a lopsided focus on offensive weapons and hacking tools has, for years, left American cyberdefense dangerously porous.

“We have had a train wreck coming,” said Mike McConnell, the former N.S.A. director and national intelligence director. “We should have ratcheted up the defense parts significantly.”


...but hey, do what you want...you will anyway.

Sunday, April 9, 2017

Hacked Off

Hacking group Shadow Brokers has released the password to a trove of NSA exploits in what they say is a form of protest against President Donald Trump for going back on his campaign promises, and warning the president, “Don’t forget your base.”

[...]

Shadow Brokers listed some of the reasons they were unhappy with Trump in a Medium blog post: “Goldman Sachs (TheGlobalists) and Military Industrial Intelligence Complex (MIIC), cabinet, #2 — Backtracked on Obamacare, #3 — Attacked the Freedom Caucus (TheMovement), #4 — Removed Bannon from the NSC, #5 — Increased U.S. involvement in a foreign war (Syria Strike).”

The group also criticized Trump for launching the cruise missile strike against Syria, saying: “Whose war are you fighting? Israeli Nationalists’ (Zionist) and Goldman Sachs’ war? Chinese Globalists’ and Goldman Sachs war? Is not looking like you fighting the domestic wars, the movement elected you to be fighting.”

[...]

The password provided by Shadow Brokers unlocks the hacking tools, which include servers belonging to companies and universities which are allegedly used to deploy malware, according to researchers who have examined some of the documents.

[...]

NSA whistleblower Edward Snowden has confirmed that the leak included authentic NSA software. The leak doesn’t contain the entire spy tools library, Snowden tweeted.

However, he added that “NSA should be able to instantly identify where this set came from and how they lost it. If they can’t, it’s a scandal.”

[...]

While the Shadow Brokers were accused of being Russians, several NSA insiders earlier told the media that signs pointed to it being someone within the NSA.

  RT
...but hey, do what you want...you will anyway.

Monday, August 22, 2016

Blame It on Russia

But James Bamford, author of many spy/intelligence articles and books, doesn't believe it.
Today, [Watergate's campaign spying by] amateur burglars [has] been replaced by cyberspies, who penetrated the DNC armed with computers and sophisticated hacking tools.

[...]

Now, in the latest twist, hacking tools themselves, likely stolen from the National Security Agency, are on the digital auction block. Once again, the usual suspects start with Russia – though there seems little evidence backing up the accusation.

[...]

[I]f Russia had stolen the hacking tools, it would be senseless to publicize the theft, let alone put them up for sale. It would be like a safecracker stealing the combination to a bank vault and putting it on Facebook. Once revealed, companies and governments would patch their firewalls, just as the bank would change its combination.

[...]

f Russia had stolen the hacking tools, it would be senseless to publicize the theft, let alone put them up for sale. It would be like a safecracker stealing the combination to a bank vault and putting it on Facebook. Once revealed, companies and governments would patch their firewalls, just as the bank would change its combination.

[...]

According to the former NSA officials who viewed the Shadow Broker files, they contained a number of exploits [...] s that the NSA often pays thousands of dollars for to private hacking groups.

[...]

I was [...] given unrestricted access to [the Snowden] cache of documents. These included both the entire British, or GCHQ, files and the entire NSA files.

But going through this archive using a sophisticated digital search tool, I could not find a single reference to the ANT catalog [a highly secret NSA document that was leaked in Decmeber 2013]. This confirmed for me that it had likely been released by a second leaker. And if that person could have downloaded and removed the catalog of hacking tools, it’s also likely he or she could have also downloaded and removed the digital tools now being leaked.

[...]

Consisting of about 300 megabytes of code, the tools could easily and quickly be transferred to a flash drive. But unlike the catalog, the tools themselves – thousands of ones and zeros – would have been useless if leaked to a publication. This could be one reason why they have not emerged until now.   Reuters
"The second leaker." I've always wondered whatever happened to that person who was referenced at the very end of the Poitras documentary about Edward Snowden (Citizen Four). Since we have never been told, I assumed that it was likely the NSA found that person and neutralized him in one way or another. Maybe not.

We'll be looking forward to the promised further emails from Wikileaks.
But we now have entered a period many have warned about, when NSA’s cyber weapons could be stolen like loose nukes and used against us. It opens the door to criminal hackers, cyber anarchists and hostile foreign governments that can use the tools to gain access to thousands of computers in order to steal data, plant malware and cause chaos.

It’s one more reason why NSA may prove to be one of Washington’s greatest liabilities rather than assets.
The fun has only just started.

...but hey, do what you want...you will anyway.