When the going gets weird, the weird turn pro. - Hunter S. Thompson

Showing posts with label homeland security. Show all posts
Showing posts with label homeland security. Show all posts

11 May 2009

Sysadmins in BDUs

The Army forces were under attack. Communications were down, and the chain of command was broken.

Pacing a makeshift bunker whose entrance was camouflaged with netting, the young man in battle fatigues barked at his comrades: “They are flooding the e-mail server. Block it. I’ll take the heat for it.”

These are the war games at West Point, at least last month, when a team of cadets spent four days struggling around the clock to establish a computer network and keep it operating while hackers from the National Security Agency in Maryland tried to infiltrate it with methods that an enemy might use. The N.S.A. made the cadets’ task more difficult by planting viruses on some of the equipment, just as real-world hackers have done on millions of computers around the world.

The competition was a final exam of sorts for a senior elective class. The cadets, who were computer science and information technology majors, competed against teams from the Navy, Air Force, Coast Guard and Merchant Marine as well as the Naval Postgraduate Academy and the Air Force Institute of Technology. Each team was judged on how well it subdued the threats from the N.S.A.
Cyberwar: Cadets trade the trenches for firewalls (New York Times, 11 May 2009)

05 December 2008

War in cyberspace

The discussion of cyberattacks and cyberwarfare is complicated by widespread disagreement over how to define these terms. Many cyberattacks are really examples of vandalism or hooliganism, observes Bruce Schneier, a security guru who works for BT, a British telecoms operator. A cyberattack on a power station or an emergency-services call centre could be an act of war or of terrorism, depending on who carries it out and what their motives are.

For a cyberattack to qualify as “cyberwar”, some observers argue, it must take place alongside actual military operations. Trying to disrupt enemy communications during conflict is, after all, a practice that goes back to the earliest telecommunications technology, the telegraph. In 1862, for example, during the American Civil War, a landing party from Thomas Freeborn, a Union navy steamer, went ashore to cut the telegraph lines between Fredericksburg and Richmond. The Russian navy pioneered the use of radio jamming in the Russo-Japanese war of 1905. On this view, cyberattacks on infrastructure are the next logical step. The attacks on Georgia might qualify as cyberwarfare by this definition, but those on Estonia would not, since there was no accompanying military offensive in the real world. As Mr Schneier puts it: “For it to be cyberwar, it must first be war.”

Not everyone agrees. For years there has been talk of a “digital Pearl Harbour”—an unexpected attack on a nation’s infrastructure via the internet, in which power stations are shut down, air-traffic control is sabotaged and telecoms networks are disabled. There have even been suggestions that future wars could be waged in cyberspace, displacing conventional military operations altogether. Why bomb your enemy’s power-stations or stockmarkets if you can disable them with software? So far there have been no successful attacks of this type, but that does not stop people worrying about them—or speculating about how to launch them.
Do cyberattacks count as war? (The Economist, 4 December 2008)

18 October 2008

...Guns, bombs, three-ounce tubes of anthrax, Crest toothpaste, nail clippers, Snapple, and so on

If I were a terrorist, and I’m not, but if I were a terrorist—a frosty, tough-like-Chuck-Norris terrorist, say a C-title jihadist with Hezbollah or, more likely, a donkey-work operative with the Judean People’s Front—I would not do what I did in the bathroom of the Minneapolis–St. Paul International Airport, which was to place myself in front of a sink in open view of the male American flying public and ostentatiously rip up a sheaf of counterfeit boarding passes that had been created for me by a frenetic and acerbic security expert named Bruce Schnei­er. He had made these boarding passes in his sophisticated underground forgery works, which consists of a Sony Vaio laptop and an HP LaserJet printer, in order to prove that the Transportation Security Administration, which is meant to protect American aviation from al-Qaeda, represents an egregious waste of tax dollars, dollars that could otherwise be used to catch terrorists before they arrive at the Minneapolis–St. Paul International Airport, by which time it is, generally speaking, too late.

I could have ripped up these counterfeit boarding passes in the privacy of a toilet stall, but I chose not to, partly because this was the renowned Senator Larry Craig Memorial Wide-Stance Bathroom, and since the commencement of the Global War on Terror this particular bathroom has been patrolled by security officials trying to protect it from gay sex, and partly because I wanted to see whether my fellow passengers would report me to the TSA for acting suspiciously in a public bathroom. No one did, thus thwarting, yet again, my plans to get arrested, or at least be the recipient of a thorough sweating by the FBI, for dubious behavior in a large American airport. Suspicious that the measures put in place after the attacks of September 11 to prevent further such attacks are almost entirely for show—security theater is the term of art—I have for some time now been testing, in modest ways, their effectiveness. Because the TSA’s security regimen seems to be mainly thing-based—most of its 44,500 airport officers are assigned to truffle through carry-on bags for things like guns, bombs, three-ounce tubes of anthrax, Crest toothpaste, nail clippers, Snapple, and so on—I focused my efforts on bringing bad things through security in many different airports, primarily my home airport, Washington’s Reagan National, the one situated approximately 17 feet from the Pentagon, but also in Los Angeles, New York, Miami, Chicago, and at the Wilkes-Barre/Scranton International Airport (which is where I came closest to arousing at least a modest level of suspicion, receiving a symbolic pat-down—all frisks that avoid the sensitive regions are by definition symbolic—and one question about the presence of a Leatherman Multi-Tool in my pocket; said Leatherman was confiscated and is now, I hope, living with the loving family of a TSA employee).
The Things He Carried (Jeffrey Goldberg, The Atlantic, November 2008)

18 July 2008

Schneier on Chinese hackers

Bruce Schneier doesn't think that the multifarious hacker attacks against Western IT infrastructure emanating from China are state-sponsored... but he also doesn't take much comfort in that:

If anything, the fact that these groups aren't being run by the Chinese government makes the problem worse. Without central political coordination, they're likely to take more risks, do more stupid things and generally ignore the political fallout of their actions.

In this regard, they're more like a non-state actor.

So while I'm perfectly happy that the U.S. government is using the threat of Chinese hacking as an impetus to get their own cybersecurity in order, and I hope they succeed, I also hope that the U.S. government recognizes that these groups are not acting under the direction of the Chinese military and doesn't treat their actions as officially approved by the Chinese government.

Schneier on Security: Chinese Cyber Attacks (14 July 2008)

04 November 2007

Bruce Schneier: The War on the Unexpected

We've opened up a new front on the war on terror. It's an attack on the unique, the unorthodox, the unexpected; it's a war on different. If you act different, you might find yourself investigated, questioned, and even arrested -- even if you did nothing wrong, and had no intention of doing anything wrong. The problem is a combination of citizen informants and a CYA attitude among police that results in a knee-jerk escalation of reported threats.

This isn't the way counterterrorism is supposed to work, but it's happening everywhere. It's a result of our relentless campaign to convince ordinary citizens that they're the front line of terrorism defense. "If you see something, say something" is how the ads read in the New York City subways. "If you suspect something, report it" urges another ad campaign in Manchester, UK. The Michigan State Police have a seven-minute video. Administration officials from then-attorney general John Ashcroft to DHS Secretary Michael Chertoff to President Bush have asked us all to report any suspicious activity.

The problem is that ordinary citizens don't know what a real terrorist threat looks like. They can't tell the difference between a bomb and a tape dispenser, electronic name badge, CD player, bat detector, or a trash sculpture; or the difference between terrorist plotters and imams, musicians, or architects. All they know is that something makes them uneasy, usually based on fear, media hype, or just something being different.

Even worse: after someone reports a "terrorist threat," the whole system is biased towards escalation and CYA instead of a more realistic threat assessment.

Schneier on Security: The War on the Unexpected (1 November 2007)



Updated and bumped because Doc has responded (extensively) at They Rode On. Short version: "Schneier can kiss my sweet ass."

More detailed version here: Flag on the play: Schneier gets it all wrong (They Rode On)

05 August 2007

Billions for "homeland security"... but how much for homeland infrastructure?

The tragic rush-hour collapse in Minneapolis of the I-35W Bridge over the Mississippi River is again forcing a reexamination of the nation's approach to maintaining and inspecting critical infrastructure.

According to engineers, the nation is spending only about two-thirds as much as it should be to keep dams, levees, highways, and bridges safe. The situation is more urgent now because many such structures were designed 40 or 50 years ago, before Americans were driving weighty SUVs and truckers were lugging tandem loads.

It all adds up to a poor grade: The American Society of Civil Engineers gave the nation a D in 2005, the latest report available, after assessing 12 categories of infrastructure ranging from rails and roads to wastewater treatment and dams.

"Bridge collapse spotlights America's deferred maintenance," Christian Science Monitor, August 3, 2007

A bridge collapse in Minneapolis. A steam pipe explosion in midtown Manhattan. A catastrophic levee failure in New Orleans...

Homeland Security dollars are being spent in a way that would make any self-respecting drunken sailor blush.

In the meantime, we aren't spending the necessary funds to maintain our roads, bridges, and our power, water and waste treatment infrastructure.

Our old, overloaded, decaying power grid struggles to keep up with demand and is incredibly vulnerable to failure (I *can't believe* that the 2003 Northeast Blackout, which took an enormous swath of the US and part of Canada out of service for up to four days, depending on where you lived, was not a wakeup call.)

Ye gods, what I wouldn't give for a real conservative candidate to step up and make this an issue.

Conservation and responsible stewardship of infrastructure is a bedrock issue, and one that allegedly fiscally responsible adults ought to be mighty damned interested in.

04 August 2007

DIY sub builder meets the NYPD

What began as an unorthodox art project has become a law-enforcement headache today and the talk of the New York blogosphere.

Duke Riley, a heavily tattooed Brooklyn artist whose waterborne performance projects around the city have frequently landed him in trouble with authorities, spent the last five months building a makeshift submarine — a partial replica of what may be America’s earliest submarine, an oak sphere called the Turtle, which saw action (not particularly successful action) in New York Harbor during the Revolutionary War.

The wood and fiberglass submarine, which was launched into the New York Harbor, made its way toward a far larger vessel — the Queen Mary 2, one of the largest ocean liners in the world, which was docked at the cruise ship terminal in the Buttermilk Channel off Red Hook, Brooklyn.

What happened next was a delicate mixture of performance art and domestic security.
NY Times CityRoom Blog: One Mans Art (a Submarine?) Runs Into Trouble