Archive for the ‘NSA’ Category

Former NSA contractor may have stolen 75% of TAO’s elite hacking tools – Ars Technica

On Monday, The Washington Post reported one of the most stunning breaches of security ever. A former NSA contractor, the paper said, stole more than 50 terabytes of highly sensitive data. According to one source, that includes more than 75 percent of the hacking tools belonging to the Tailored Access Operations. TAO is an elite hacking unit that develops and deploys some of the world's most sophisticated software exploits.

Investigators have floated several theories. One holds that Martin directly provided the tools to the person or group responsible for the leak. An alternate theory is that the leakers obtained the software by hacking Martin. As reported in October, Martin was charged with felony theft of government property and unauthorized removal and retention of classified material. Monday's Washington Post article says that prosecutors will likely file charges of "violating the Espionage Act by 'willfully' retaining information that relates to the national defense, including classified data such as NSA hacking tools and operational plans against 'a known enemy' of the United States."

An unnamed US official told the paper that Martin allegedly hoarded more than 75 percent of the TAO's library of hacking tools. It's hard to envision a scenario under which a theft of that much classified material by a single individual would be possible.

Listing image by National Security Agency

Link:
Former NSA contractor may have stolen 75% of TAO's elite hacking tools - Ars Technica

NSA’s No. 2, its top civilian, will retire shortly – FedScoop

Richard Ledgett, deputy director of the National Security Agency, has announced he will retire this spring, the agency confirmed to CyberScoop Friday.

Ledgett, 59, has been deputy director the agencys top civilian since January 2014, when he succeeded Chris Inglis. Prior to that, according to his official biography,He led the NSA Media Leaks Task Force responsible for integrating and overseeing the totality of NSAs efforts surrounding the Ed Snowden megaleaks.

Ledgett joined the NSAin 1988 and and rose to be, during 2012-13, director of the agencysThreat Operations Center, the famed NTOC. Before that, he served a a stint 2010-12 in various posts in the Office of the Director of National Intelligence, including being the the first national intelligence manager for cyber.

He is a recipient of the National Intelligence Superior Service Medal and was for a time an instructor andand course developer at the National Cryptologic School.

It has been anticipated that he would retire in 2017 and he decided the time is right this spring after nearly 40 years of service to the nation, the agency said in an emailed statement.

Last year, Ledgett presented a gloomy picture of the connected future, warning about the dangers of the Internet of Things. Hetoldthe U.S. Chamber of Commerces 5th Annual Cybersecurity Summit that theconnection to our networks of hundreds of thousands, maybe millions, ofinternet-connecteddevices that come from multiple vendors and havediffering software and hardware upgrade paths without a coherent security plan means that there are vulnerabilities[created]in those networks.

Continued here:
NSA's No. 2, its top civilian, will retire shortly - FedScoop

Confirmed: The NSA Got Hacked – The Atlantic

After a never-before-seen group announced it was in possession of a trove of malware developed by the elite hacking arm of the National Security Agency early this week, professional security researchers began working to try and determine whether the code the group released was truly developed by the NSA.

Working off of hints they found in the code, which was released by a group calling itself the Shadow Broker, researchers guessed it was authenticbut new documentation straight from the source appears to confirm the codes provenance.

According to NSA documents obtained by Edward Snowden and reviewed by The Intercept, several elements in the released code line up with details in the agencys own manuals and materials.

One manual, for example, instructs agents to use a specific 16-character string, ace02468bdf13579, to track a certain strain of government-developed malware as it makes its way through networks. That string shows up character-for-character in one of the leaked hacking tools, SECONDDATE.

The tool allows the NSA to execute man-in-the-middle attacks, which intercept traffic on a network as its traveling from its origin to its destination. The agency used it to redirect users who think theyre browsing safe websites to NSA-run servers that infect their computers with malwareand then back to their destination before they know what happened. In a slide deck, the NSA used cnn.com as an example of the sort of site it could exploit to deliver its malicious code.

The documents released by The Intercept reveal that SECONDDATE has been used to spy on systems in Pakistan and in Lebanon, where it gained access to data belonging to Hezbollah.

Its still not clear how the tools leaked from the NSA. Snowden speculated on Twitter that the tools could have been found on a server it used to infect a target, but former NSA staffers interviewed by Motherboard said the leak could be the work of a rogue insider, claiming that some of the files in the leak would never had made it to an outside server.

Original post:
Confirmed: The NSA Got Hacked - The Atlantic

WATCH: The real beautiful mind belongs to Bill Binney, NSA whistleblower and metadata czar – Salon

When Bill Binney, former NSA analyst and head of the anti-terror ThinThread metadata program sits in front of you and says he is not afraid of the government, you have to admire him. A wheel-chair-bound U.S. serviceman who rose in the ranks of intelligence to work in top-secret NSA programs, Binney created ThinThread prior to September 11, 2001, and says it mathematically broke down all phone communications anywhere in the world without any infringement on Constitutional rights. Identities were protected, except in suspected terrorism cases, and the program was self-running. More important, it worked.

In A Good American, the new documentary from executive producer Oliver Stone and director Friedrich Moser, audiences are taken on a tense and frightening ride through Binney and his colleagues experience developing and deploying ThinThread in tests, only to see its funding pulled just weeks before 9/11 in favor of an expensive and ineffective but job-creating program called TrailBlazer, which the NSA preferred. Binney contends that ThinThread would have identified the terrorists who planned and executed the 9/11 terror attacks, thereby preventing them from occurring. Understandably, he remains disappointed and angry about this, all these years later.

The docu-thriller is a candid portrait of how exploding information in the digital age found government agencies both behind the technology of terrorism and struggling to keep current. When Binney and his small team developed ThinThread, it was an effort to help the NSA be attentive to the code-breaking needs of the modern era. ThinThread represented a home run for intelligence: Itwas highly effective at sorting data and protecting privacy, two huge challenges of working with large amounts of small bits of information. But when ThinThreads plug was pulled, Binney and his team challenged their NSA bosses, and in the process found themselves at odds with the U.S. government and in a complex web of lies and corruption. Thus, when Binney said he remains unafraid of possible repercussions or retaliation tied to the films thesis, its not hard to believe. What else can they do to me? he asks. Theyve already tried everything to stop me.

Read more here:
WATCH: The real beautiful mind belongs to Bill Binney, NSA whistleblower and metadata czar - Salon

NSA’s No. 2, its top civilian, will retire shortly – Cyberscoop – CyberScoop

Richard Ledgett, deputy director of the National Security Agency, has announced he will retire this spring, the agency confirmed to CyberScoop Friday.

Ledgett, 59, has been deputy director the agencys top civilian since January 2014, when he succeeded Chris Inglis. Prior to that, according to his official biography,He led the NSA Media Leaks Task Force responsible for integrating and overseeing the totality of NSAs efforts surrounding the Ed Snowden megaleaks.

Ledgett joined the NSAin 1988 and and rose to be, during 2012-13, director of the agencysThreat Operations Center, the famed NTOC. Before that, he served a a stint 2010-12 in various posts in the Office of the Director of National Intelligence, including being the the first national intelligence manager for cyber.

He is a recipient of the National Intelligence Superior Service Medal and was for a time an instructor andand course developer at the National Cryptologic School.

It has been anticipated that he would retire in 2017 and he decided the time is right this spring after nearly 40 years of service to the nation, the agency said in an emailed statement.

Last year, Ledgett presented a gloomy picture of the connected future, warning about the dangers of the Internet of Things. Hetoldthe U.S. Chamber of Commerces 5th Annual Cybersecurity Summit that theconnection to our networks of hundreds of thousands, maybe millions, ofinternet-connecteddevices that come from multiple vendors and havediffering software and hardware upgrade paths without a coherent security plan means that there are vulnerabilities[created]in those networks.

Read the original:
NSA's No. 2, its top civilian, will retire shortly - Cyberscoop - CyberScoop