Showing posts with label Prism. Show all posts
Showing posts with label Prism. Show all posts

Saturday, 24 August 2013

NZ direct access to PRISM

Fuck you John Key - liar! Here we are again – New Zealand in the headlines for all the wrong reasons.

A quick search under NZ media finds NOTHING.


New Zealand has direct access to US surveillance
New Zealand’s police and intelligence services have direct access to US surveillance systems such as PRISM, to monitor email and capture various data traffic, according to police affidavits in connection with the raid on Kim Dotcom’s mansion.


RT,
23 August, 2013


The news that the Organised and Financial Crime Agency New Zealand (OFCANZ) requested assistance from the Government Communications Security Bureau (GCSB) was revealed by blogger Keith Ng on his On Point blog


He discovered that the police provided the GCSB – the government’s signals intelligence unit – with a list of indicators for scanning emails and other information traffic generated by Kim Dotcom and his colleagues and co-founders at Megaupload.

New Zealand and Australia use a ‘selector’ categorization system akin to the NSA’s XKEYSCORE, revealed recently by whistleblower Edward Snowden in his set of PRISM revelations about unsanctioned US spying on people across the globe. 

PRISM is an all-reaching computer surveillance system run by the US government and the NSA.

Some of these selectors have been redacted in the documents, but others remain – such as Kim Dotcom’s email addresses and the names of proxy servers he uses to access various accounts and servers. 

Megaupload founder Kim Dotcom (AFP Photo/Marty Melville)
Megaupload founder Kim Dotcom (AFP Photo/Marty Melville)


Last year, Dotcom’s mansion was raided by the police for alleged rights and piracy-related breaches, all based on indictments filed in the US. 


There is clear indication of the surveillance system monitoring live traffic. The reports reveal communications interspersed with terms such as ‘CONFIDENTIAL’ or ‘NEW ZEALAND EYES ONLY’, or even ‘SECRET…REL TO NZL, AUS, CAN, GBR, USA,” which speaks for itself.

However, while this is certainly a new revelation, it may not be surprising to many. 

The NSA sometime shares information with NZ, as part of the Five Eyes intelligence-sharing alliance, which also includes the UK, Australia and Canada. 

Moreover, New Zealand passed a new bill in August, which radically expands the powers of its spying agency. The legislation was passed 61 votes to 59 in a move that was slammed by the opposition as a death knell for privacy rights in New Zealand.


The new amendment bill gives the GCSB powers to support the New Zealand police, Defense Force and the Security Intelligence Service. 

Polls have shown that three quarters of the Kiwi population are opposed to the law. And Kim Dotcom promptly gave his reaction on Twitter with the words “RIP Privacy”



NZ police affidavits show use 

of PRISM for surveillance

New Zealand’s police and intelligence services have direct access to US surveillance systems such as PRISM, to monitor email and capture various data traffic, according to police affidavits in connection with the raid on Kim Dotcom’s mansion.

Keith Ng

23 August, 2013


Police affidavits related to the raid on Kim Dotcom's Mega mansion appear to show that New Zealand police and spy agencies are able to tap directly into United States surveillance systems such as PRISM to capture email and other traffic.


The discovery was made by blogger Keith Ng who wrote on his On Point blog that the Organised and Financial Crime Agency New Zealand (OFCANZ) requested assistance from the Government Communications Security Bureau (GCSB), the country's signals intelligence unit, which is charge of surveilling the Pacific region under the Five-Eyes agreement.


A list of so-called selectors or search terms were provided to GCSB by the police [PDF, redacted] for the surveillance of emails and other data traffic generated by Dotcom and his Megaupload associates.


'Selectors' is the term used for the National Security Agency (NSA) XKEYSCORE categorisation system that Australia and New Zealand contribute to and which was leaked by Edward Snowden as part of his series of PRISM revelations.


Some "selectors of interest" have been redacted out, but others such as Kim Dotcom's email addresses, the mail proxy server used for some of the accounts and websites, remain in the documents.


Megaupload co-founders Bram van der Kolk and Sven Ecthernach was were also targeted for electronic surveillance, ditto Dotcom's wife Mona.


Dotcom's mansion was raided by NZ police last year for crimes related to online piracy, based on indictments filed in the US.


One note on the reports generated from the surveillance points to the system used capturing real-time traffic.


Several of the documents are classified as "CONFIDENTIAL COMINT/NEW ZEALAND EYES ONLY" with one being marked as "SECRET/COMINT/REL TO NZL, AUS, CAN, GBR, USA".


The spying on Dotcom, his wife and van der Kolk was deemed to be illegal as all three are residents of New Zealand and the GCSB is precluded by current law from intercepting their communications.


In the United States, declassified government documents have been released to the Electronic Frontier Fourndation that show the NSA operates an eavesdropping program that has direct access to internet communications.


The documents are part of a statement by the US Foreign Intelligence Surveillance Court (FISC) which berates the NSA for misleading the tribunal on the extent of domestic spying on innocent people, saying such collection was unconstitutional.


And from the man himself - 


Ich bin ein Cyberpunk

Keith Ng

22 August, 2013


Welcome to your sudden but inevitable future of ubiquitous surveillance.
To an extent, I appreciate the arguments made by supporters of the GCSB Bill – it’s not really a huge encroachment of mass surveillance powers, it is, mostly, just the formalisation of mass surveillance powers that have been encroaching for a decade. We are not fucked off because of the bill itself, really, but because we’ve finally been forced to pay attention to the barftastic overreach of state surveillance that’s been happening around us.
At least, that’s true for me. Thanks to the GCSB Bill, I finally got around to reading the Kim Dotcom affidavits. It’s the best example we have of how “GCSB assistance” is actually rendered. The Police asked the GCSB for help in a one-page request (page 13 of this):



Once the GCSB’s lawyer had a look at it, the Police provided a list of “selectors” to the GCSB (we now know from the PRISM documents that “selectors” is the term used to describe the search terms used to make PRISM requests):


The selectors were entered into █████, in an email classified as “SECRET//COMINT//REL TO NZL, AUS, CAN, GBR, USA”. In other words, the selectors were entered into a secret communications intelligence system, and this secret system was considered related to Five Eyes:


The email from the GCSB then described “traffic volume from these selectors”: i.e. This secret system was capturing live traffic.


This is consistent with everything that we know about PRISM. Key has refused to comment on this.

What does this mean? It means that GCSB assistance is NSA assistance. It means that government agencies can tap into these powers as part of bread-and-butter law enforcement. Through the Bradley Ambrose case, we’ve seen that the Police are willing to use the full extent of their powers for entirely bullshit cases. Combine the two, and it makes me very, very queasy.
I ended my post in May with “we need to start by getting really, really fucked off”. What is step two? Fortunately, there is a 25-year-old answer to this question: Encrypt everything.
Over the next however long it’s going to take me, I’m going to be doing short posts on how to secretfy your stuff. Today’s post is on encrypting text using public-key encryption.
Public-key Encryption (the uber-short version)
This technique is based on a pair of matching keys – one public, one private. Anything encrypted with one can only be decrypted with the other. Why? MATHS, that’s why. The public key is then made public (my key is here), and anyone can use that key to encrypt a messsage. Only you – with the private key that you keep secret – can decrypt that message.
It’s actually not that hard. The simplest tool for dealing with PGP keys is gpg4usb. Go download it and have a play. Purely for testing purposes, here is the public AND private keys for “John PGPKey” (right click on the link –> “Save link as..” to save the file). Open up gpg4usb and use the menu bar: Keys –> Import Key from.. –> File.



Select the .asc file you just downloaded. You can now use John PGPKey’s private and public keys.
(Just to reiterate, this is for testing purposes only – you should NEVER put your real private key on the internet.)
Here is a message that’s been encrypted using John PGPKey’s public key. Open it up and copy and paste the garbled text into gpg4usb (including the BEGIN PGP MESSAGE and END PGP MESSAGE lines). Click on the “Decrypt” button. It’ll ask you for a passphrase, which is “spicy panopticon in a dunnenad sauce” (this is a more reliable guide to making secure passphrases than your IT department).
(And no, you should not be putting the passphrases for your real private key on the internet, either. NOTE: Apologies if this didn’t work before, I posted the wrong version of the key I was faffing around with.)


Enter the passphrase and BAM – you’ve decrypted a message! (If you haven’t, check that you’ve copied the whole message, and check that you typed in the password properly.)
Now, to encrypt a message, just type things into the text box, select the key you want to encrypt with, and click on the “Encrypt” button. Pretty goddamn easy.
To create your own key, open up Keys –> Manage Keys. From the Key Management window, open up Key –> Generate Key. Fill out the boxes and go. You can export the public key and put it somewhere public – but let’s not actually do that yet, until we have a way of securing your private key.

In the next part, we’ll talk about publishing keys, verifying keys, signing with keys


Access to Keith Ng's blog site On Point HERE

Friday, 12 July 2013

Microsoft worked with NSA


Revealed: how Microsoft handed the NSA access to encrypted messages
  • Secret files show scale of Silicon Valley co-operation on Prism
  • Outlook.com encryption unlocked even before official launch 
  • Skype worked to enable Prism collection of video calls
  • Company says it is legally compelled to comply


Skype worked with intelligence agencies last year to allow Prism to collect video and audio conversations. Photograph: Patrick Sinkel/AP

11 July, 2013


Microsoft has collaborated closely with US intelligence services to allow users' communications to be intercepted, including helping the National Security Agency to circumvent the company's own encryption, according to top-secret documents obtained by the Guardian.

The files provided by Edward Snowden illustrate the scale of co-operation between Silicon Valley and the intelligence agencies over the last three years. They also shed new light on the workings of the top-secret Prism program, which was disclosed by the Guardian and the Washington Post last month.

The documents show that:

Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;

The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;

The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide;

Microsoft also worked with the FBI's Data Intercept Unit to "understand" potential issues with a feature in Outlook.com that allows users to create email aliases;

In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;

Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".

The latest NSA revelations further expose the tensions between Silicon Valley and the Obama administration. All the major tech firms are lobbying the government to allow them to disclose more fully the extent and nature of their co-operation with the NSA to meet their customers' privacy concerns. Privately, tech executives are at pains to distance themselves from claims of collaboration and teamwork given by the NSA documents, and insist the process is driven by legal compulsion.

In a statement, Microsoft said: "When we upgrade or update products we aren't absolved from the need to comply with existing or future lawful demands." The company reiterated its argument that it provides customer data "only in response to government demands and we only ever comply with orders for requests about specific accounts or identifiers".

In June, the Guardian revealed that the NSA claimed to have "direct access" through the Prism program to the systems of many major internet companies, including Microsoft, Skype, Apple, Google, Facebook and Yahoo.

Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time. Targeting US citizens does require an individual warrant, but the NSA is able to collect Americans' communications without a warrant if the target is a foreign national located overseas.

Since Prism's existence became public, Microsoft and the other companies listed on the NSA documents as providers have denied all knowledge of the program and insisted that the intelligence agencies do not have back doors into their systems.

Microsoft's latest marketing campaign, launched in April, emphasizes its commitment to privacy with the slogan: "Your privacy is our priority."

Similarly, Skype's privacy policy states: "Skype is committed to respecting your privacy and the confidentiality of your personal data, traffic data and communications content."

But internal NSA newsletters, marked top secret, suggest the co-operation between the intelligence community and the companies is deep and ongoing.

The latest documents come from the NSA's Special Source Operations (SSO) division, described by Snowden as the "crown jewel" of the agency. It is responsible for all programs aimed at US communications systems through corporate partnerships such as Prism.

The files show that the NSA became concerned about the interception of encrypted chats on Microsoft's Outlook.com portal from the moment the company began testing the service in July last year.

Within five months, the documents explain, Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats

A newsletter entry dated 26 December 2012 states: "MS [Microsoft], working with the FBI, developed a surveillance capability to deal" with the issue. "These solutions were successfully tested and went live 12 Dec 2012."

Two months later, in February this year, Microsoft officially launched the Outlook.com portal.

Another newsletter entry stated that NSA already had pre-encryption access to Outlook email. "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption."

Microsoft's co-operation was not limited to Outlook.com. An entry dated 8 April 2013 describes how the company worked "for many months" with the FBI – which acts as the liaison between the intelligence agencies and Silicon Valley on Prism – to allow Prism access without separate authorization to its cloud storage service SkyDrive.

The document describes how this access "means that analysts will no longer have to make a special request to SSO for this – a process step that many analysts may not have known about".

The NSA explained that "this new capability will result in a much more complete and timely collection response". It continued: "This success is the result of the FBI working for many months with Microsoft to get this tasking and collection solution established."

A separate entry identified another area for collaboration. "The FBI Data Intercept Technology Unit (DITU) team is working with Microsoft to understand an additional feature in Outlook.com which allows users to create email aliases, which may affect our tasking processes."

The NSA has devoted substantial efforts in the last two years to work with Microsoft to ensure increased access to Skype, which has an estimated 663 million global users.

One document boasts that Prism monitoring of Skype video production has roughly tripled since a new capability was added on 14 July 2012. "The audio portions of these sessions have been processed correctly all along, but without the accompanying video. Now, analysts will have the complete 'picture'," it says.

Eight months before being bought by Microsoft, Skype joined the Prism program in February 2011.

According to the NSA documents, work had begun on smoothly integrating Skype into Prism in November 2010, but it was not until 4 February 2011 that the company was served with a directive to comply signed by the attorney general.

The NSA was able to start tasking Skype communications the following day, and collection began on 6 February. "Feedback indicated that a collected Skype call was very clear and the metadata looked complete," the document stated, praising the co-operation between NSA teams and the FBI. "Collaborative teamwork was the key to the successful addition of another provider to the Prism system."

ACLU technology expert Chris Soghoian said the revelations would surprise many Skype users. "In the past, Skype made affirmative promises to users about their inability to perform wiretaps," he said. "It's hard to square Microsoft's secret collaboration with the NSA with its high-profile efforts to compete on privacy with Google."

The information the NSA collects from Prism is routinely shared with both the FBI and CIA. A 3 August 2012 newsletter describes how the NSA has recently expanded sharing with the other two agencies.

The NSA, the entry reveals, has even automated the sharing of aspects of Prism, using software that "enables our partners to see which selectors [search terms] the National Security Agency has tasked to Prism".

The document continues: "The FBI and CIA then can request a copy of Prism collection of any selector…" As a result, the author notes: "these two activities underscore the point that Prism is a team sport!"

In its statement to the Guardian, Microsoft said:

We have clear principles which guide the response across our entire company to government demands for customer information for both law enforcement and national security issues. First, we take our commitments to our customers and to compliance with applicable law very seriously, so we provide customer data only in response to legal processes.

Second, our compliance team examines all demands very closely, and we reject them if we believe they aren't valid. Third, we only ever comply with orders about specific accounts or identifiers, and we would not respond to the kind of blanket orders discussed in the press over the past few weeks, as the volumes documented in our most recent disclosure clearly illustrate.

Finally when we upgrade or update products legal obligations may in some circumstances require that we maintain the ability to provide information in response to a law enforcement or national security request. There are aspects of this debate that we wish we were able to discuss more freely. That's why we've argued for additional transparency that would help everyone understand and debate these important issues.

In a joint statement, Shawn Turner, spokesman for the director of National Intelligence, and Judith Emmel, spokeswoman for the NSA, said:

The articles describe court-ordered surveillance – and a US company's efforts to comply with these legally mandated requirements. The US operates its programs under a strict oversight regime, with careful monitoring by the courts, Congress and the Director of National Intelligence. Not all countries have equivalent oversight requirements to protect civil liberties and privacy.

They added: "In practice, US companies put energy, focus and commitment into consistently protecting the privacy of their customers around the world, while meeting their obligations under the laws of the US and other countries in which they operate."



This article was amended on 11 July 2013 to reflect information from Microsoft that it did not make any changes to Skype to allow Prism collection on or around July 2012.

Friday, 5 July 2013

The French Big Brother


'French PRISM' revealed: All communications tracked, metadata collected
The French external intelligence agency spies on French citizen’s phone calls, emails and social media activity and web use, the Le Monde newspaper has reported.

RT,
4 July, 2013

AFP Photo/Eric Cabanis
AFP Photo/Eric Cabanis





France’s external intelligence agency the DGSE, intercepts signals from computers and telephones in France and between France and other countries in order to get a pictures of who is talking to whom, although, apparently, they do not randomly spy on the content of phone calls, the daily revealed on Thursday.   
Emails, text messages, telephone records, access to Facebook and Twitter are stored for years. “All of our communications are spied on,” read the article quoting unnamed sources in the intelligence services as well as remarks made publicly by intelligence officials. 

The DGSE allegedly stores the metadata from private communications in a basement under its Paris headquarters. All of France’s seven other intelligence services have access to the data and can tap into it freely as a means to spot people's suspicious communications. Individuals can then be targeted by more intrusive techniques such as phone-tapping, it was reported. 

printsreen from http://www.lemonde.fr
printsreen from http://www.lemonde.fr

Le Monde pointed out the activities were illegal, but the French national security commission whose job it is to authorize targeted spying, and the parliamentary intelligence committee, challenged the papers report. It said that it works within the law and that the only body in France that collected communication information was a government agency controlled by the Prime Minister’s office to monitor for security breaches.




The report comes after revelations that America’s NSA regularly spies on its own people as well as on European citizens and embassies.

The allegations were leaked by Edward Snowden and published in the German magazine Der Spiegel, and have sparked a furious response from European governments just as a major US-EU trade talks are about to get underway.

The Guardian newspaper reported last month that Britain has a similar spying program and shares vast quantities of information with the NSA through its Prism program.

Sunday, 23 June 2013

We Are All Witnesses Now

PRISM and the Rise of a New Fascism
John Pilger



21 June, 2013


In his book Propaganda, published in 1928, Edward Bernays wrote: “The conscious and intelligent manipulation of the organised habits and opinions of the masses is an important element in democratic society.

Those who manipulate this unseen mechanism of society constitute an invisible government which is the true ruling power of our country.”

The American nephew of Sigmund Freud, Bernays invented the term “public relations” as a euphemism for state propaganda. He warned that an enduring threat to the invisible government was the truth-teller and an enlightened public.

In 1971, the whistleblower Daniel Ellsberg leaked US government files known as the Pentagon Papers, which showed that the invasion of Vietnam was based on systematic lying. Four years later, Frank Church conducted sensational hearings in the Senate: one of the last flickers of American democracy. These laid bare the extent of the invisible government: the domestic spying and subversion and warmongering by intelligence and “security” agencies and the backing they received from big business and the media, both conservative and liberal.

Speaking about the National Security Agency (NSA), Senator Church said: “I know the capacity that there is to make tyranny total in America, and we must see to it that this agency and all agencies that possess this technology operate within the law . . . so that we never cross over that abyss. That is the abyss from which there is no return.”

On 11 June, following the revelations in the Guardian by the NSA contractor Edward Snowden, Ellsberg wrote that the US had now fallen into “that abyss”.

Snowden’s revelation that Washington has used Google, Facebook, Apple and other giants of consumer technology to spy on almost everyone is further evidence of a modern form of fascism. Having nurtured oldfashioned fascists around the world – from Latin America to Africa and Indonesia – the genie has risen at home. Understanding this is as important as understanding the criminal abuse of technology.

Fred Branfman, who exposed the “secret” destruction of tiny Laos by the US air force in the 1960s and 1970s, provides an answer to those who still wonder how a liberal African-American president, a professor of constitutional law, can command such lawlessness. “Under Mr Obama, America is still far from being a classic police-state . . .” he wrote. “But no president has done more to create the infrastructure for a possible future police state.” Why? Because Obama understands that his role is not to indulge those who voted for him but to expand “the most powerful institution in the history of the world, one that has killed, wounded or made homeless well over 20 million human beings, mostly civilians, since 1962”.

In the new American cyberpower, only the revolving doors have changed. The director of Google Ideas, Jared Cohen, was an adviser to Condoleezza Rice, the former secretary of state in the Bush administration who lied that Saddam Hussein could attack the US with nuclear weapons. Cohen and Google’s executive chairman, Eric Schmidt – they met in the ruins of Iraq – have co-authored a book, The New Digital Age, endorsed as visionary by the former CIA director Michael Hayden and the war criminals Henry Kissinger and Tony Blair. The authors make no mention of the Prism spying programme, revealed by Snowden, that provides the NSA with access to all of us who use Google.

Control and dominance are the two words that make sense of this. These are exercised by political, economic and military design, of which mass surveillance is an essential part, but also by insinuating propaganda into the public consciousness. This was Edward Bernays’s point. His two most successful PR campaigns convinced Americans that they should go to war in 1917 and persuaded women to smoke in public; cigarettes were “torches of freedom” that would hasten women’s liberation.

It is in popular culture that the fraudulent “ideal” of America as morally superior, a “leader of the free world”, has been most effective. Yet even during Hollywood’s most jingoistic periods there were exceptional films, such as those of the exiled Stanley Kubrick, and adventurous European films would find US distributors. These days there is no Kubrick, no Strangelove, and the US market is almost closed to foreign films.

When I showed my own film The War on Democracy to a major, liberal-minded US distributor, I was handed a laundry list of changes, to “ensure the movie is acceptable”. His memorable sop to me was: “OK, maybe we could drop in Sean Penn as narrator. Would that satisfy you?” Kathryn Bigelow’s torture-apologising Zero Dark Thirty and, this year, Alex Gibney’s We Steal Secrets, a cinematic hatchet job on Julian Assange, were made with generous backing by Universal Studios, whose parent company until recently was General Electric. GE manufactures weapons, components for fighter aircraft and advanced surveillance technology. The company also has lucrative interests in “liberated” Iraq.

The power of truth-tellers such as Bradley Manning, Julian Assange and Edward Snowden is that they dispel a whole mythology carefully constructed by the corporate cinema and the corporate media. WikiLeaks is especially dangerous because it provides truthtellers with a means to get the truth out. This was achieved by Collateral Damage, the cockpit video of a US Apache helicopter allegedly leaked by Manning. The impact of this one video marked Manning and Assange for state vengeance. Here were US airmen murdering journalists and maiming children in a Baghdad street, clearly enjoying it, and describing their atrocity as “nice”. Yet, in one vital sense, they did not get away with it; for we are all witnesses now, and the rest is up to us.


John Pilger’s film on Australia, Utopia, will be released in the autumn.

Emperor Alexander


Meet The Man In Charge Of America's Secret Cyber Army (In Which "Bonesaw" Makes A Mockery Of PRISM)




22 June, 2013



With his revelations exposing the extent of potential, and actual, pervasive NSA surveillance over the American population, Edward Snowden has done a great service for the public by finally forcing it to answer the question: is having Big Brother peek at every private communication and electronic information, a fair exchange for the alleged benefit of the state's security. Alas, without further action form a population that appears largely numb and apathetic to disclosures that until recently would have sparked mass protests and toppled presidents, the best we can hope for within a political regime that has hijacked the democratic process, is some intense introspection as to what the concept of "America" truly means.

However, and more importantly, what Snowden's revelations have confirmed, is that behind the scenes, America is now actively engaged in a new kind of war: an unprecedented cyber war, where collecting, deciphering, intercepting, and abusing information is the only thing that matters and leads to unprecedented power, and where enemies both foreign and domestic may be targeted without due process based on a lowly analyst's "whim."


It has also put spotlight on the man, who until recently deep in the shadows, has been responsible for building America's secret,absolutely massive cyber army, and which according to a just released Wired profile is "capable of launching devastating cyberattacks. Now it's ready to unleash hell."


Meet General Keith Alexander, "a man few even in Washington would likely recognize", which is troubling because Alexander is now quite possibly the most powerful person in the world, that nobody talks about. Which is just the way he likes it.




This is the partial and incomplete story of the man who may now be empowered with more unchecked power than any person in the history of the US, or for that matter, the world. It comes once again, courtesy of the man who over a year before the Guardian's Snowden bombshell broke the story about the NSA's secret Utah data storage facility, James Bamford, and whose intimate knowledge of the NSA's secrets comes by way of being a consultant for the defense team of one Thomas Drake, one of the original NSA whistleblowers (as we learn from the full Wired article).


But first, by way of background, here is a glimpse of Alexander's ultra-secretive kingdom. From Wired:







Inside Fort Meade, Maryland, a top-secret city bustles. Tens of thousands of people move through more than 50 buildings—the city has its own post office, fire department, and police force. But as if designed by Kafka, it sits among a forest of trees, surrounded by electrified fences and heavily armed guards, protected by antitank barriers, monitored by sensitive motion detectors, and watched by rotating cameras. To block any telltale electromagnetic signals from escaping, the inner walls of the buildings are wrapped in protective copper shielding and the one-way windows are embedded with a fine copper mesh. 
 
This is the undisputed domain of General Keith Alexander, a man few even in Washington would likely recognize. Never before has anyone in America’s intelligence sphere come close to his degree of power, the number of people under his command, the expanse of his rule, the length of his reign, or the depth of his secrecy. A four-star Army general, his authority extends across three domains: He is director of the world’s largest intelligence service, the National Security Agency; chief of the Central Security Service; and commander of the US Cyber Command. As such, he has his own secret military, presiding over the Navy’s 10th Fleet, the 24th Air Force, and the Second Army.


Schematically, Alexander's empire consists of the following: virtually every 
piece in America's information intelligence arsenal.



As the Snowden scandal has unfurled, some glimpses into the "introspective" capabilities of the NSA, and its sister organizations, have demonstrated just how powerful the full "intelligence" arsenal of the US can be.


However, it is when it is facing outward - as it normally does - that things get really scary. Because contrary to prevailing conventional wisdom, Alexander's intelligence and information-derived power is far from simply defensive. In fact, it is when its offensive potential is exposed that the full destructive power in Alexander's grasp is revealed:







In its tightly controlled public relations, the NSA has focused attention on the threat of cyberattack against the US—the vulnerability of critical infrastructure like power plants and water systems, the susceptibility of the military’s command and control structure, the dependence of the economy on the Internet’s smooth functioning. Defense against these threats was the paramount mission trumpeted by NSA brass at congressional hearings and hashed over at security conferences.
 
But there is a flip side to this equation that is rarely mentioned: The military has for years been developing offensive capabilities, giving it the power not just to defend the US but to assail its foes. Using so-called cyber-kinetic attacks, Alexander and his forces now have the capability to physically destroy an adversary’s equipment and infrastructure, and potentially even to kill. Alexander—who declined to be interviewed for this article—has concluded that such cyberweapons are as crucial to 21st-century warfare as nuclear arms were in the 20th.
 
And he and his cyberwarriors have already launched their first attack. The cyberweapon that came to be known as Stuxnet was created and built by the NSA in partnership with the CIA and Israeli intelligence in the mid-2000s. The first known piece of malware designed to destroy physical equipment, Stuxnet was aimed at Iran’s nuclear facility in Natanz. By surreptitiously taking control of an industrial control link known as a Scada (Supervisory Control and Data Acquisition) system, the sophisticated worm was able to damage about a thousand centrifuges used to enrich nuclear material.
 
The success of this sabotage came to light only in June 2010, when the malware spread to outside computers. It was spotted by independent security researchers, who identified telltale signs that the worm was the work of thousands of hours of professional development. Despite headlines around the globe, officials in Washington have never openly acknowledged that the US was behind the attack. It wasn’t until 2012 that anonymous sources within the Obama administration took credit for it in interviews with The New York Times.
 
But Stuxnet is only the beginning. Alexander’s agency has recruited thousands of computer experts, hackers, and engineering PhDs to expand US offensive capabilities in the digital realm. The Pentagon has requested $4.7 billion for “cyberspace operations,” even as the budget of the CIA and other intelligence agencies could fall by $4.4 billion. It is pouring millions into cyberdefense contractors. And more attacks may be planned.


Alexander's background is equally as impressive: a classmate of Petraeus and Dempsey, a favorite of Rumsfeld, the General had supreme power written all over his career progression. If reaching the top at all costs meant crushing the fourth amendment and lying to Congress in the process, so be it:







Born in 1951, the third of five children, Alexander was raised in the small upstate New York hamlet of Onondaga Hill, a suburb of Syracuse. He tossed papers for the Syracuse Post-Standard and ran track at Westhill High School while his father, a former Marine private, was involved in local Republican politics. It was 1970, Richard Nixon was president, and most of the country had by then begun to see the war in Vietnam as a disaster. But Alexander had been accepted at West Point, joining a class that included two other future four-star generals, David Petraeus and Martin Dempsey. Alexander would never get the chance to serve in Vietnam. Just as he stepped off the bus at West Point, the ground war finally began winding down.
 
In April 1974, just before graduation, he married his high school classmate Deborah Lynn Douglas, who grew up two doors away in Onondaga Hill. The fighting in Vietnam was over, but the Cold War was still bubbling, and Alexander focused his career on the solitary, rarefied world of signals intelligence, bouncing from secret NSA base to secret NSA base, mostly in the US and Germany. He proved a competent administrator, carrying out assignments and adapting to the rapidly changing high tech environment. Along the way he picked up masters degrees in electronic warfare, physics, national security strategy, and business administration. As a result, he quickly rose up the military intelligence ranks, where expertise in advanced technology was at a premium.
 
In 2001, Alexander was a one-star general in charge of the Army Intelligence and Security Command, the military’s worldwide network of 10,700 spies and eavesdroppers. In March of that year he told his hometown Syracuse newspaper that his job was to discover threats to the country. “We have to stay out in front of our adversary,” Alexander said. “It’s a chess game, and you don’t want to lose this one.” But just six months later, Alexander and the rest of the American intelligence community suffered a devastating defeat when they were surprised by the attacks on 9/11. Following the assault, he ordered his Army intercept operators to begin illegally monitoring the phone calls and email of American citizens who had nothing to do with terrorism, including intimate calls between journalists and their spouses. Congress later gave retroactive immunity to the telecoms that assisted the government.
 
In 2003, Alexander, a favorite of defense secretary Donald Rumsfeld, was named the Army’s deputy chief of staff for intelligence, the service’s most senior intelligence position. Among the units under his command were the military intelligence teams involved in the human rights abuses at Baghdad’s Abu Ghraib prison. Two years later, Rumsfeld appointed Alexander—now a three-star general—director of the NSA, where he oversaw the illegal, warrantless wiretapping program while deceiving members of the House Intelligence CommitteeIn a publicly released letter to Alexander shortly after The New York Times exposed the program, US representative Rush Holt, a member of the committee, angrily took him to task for not being forthcoming about the wiretapping: “Your responses make a mockery of congressional oversight.”


In short: Emperor Alexander.







Inside the government, the general is regarded with a mixture of respect and fear, not unlike J. Edgar Hoover, another security figure whose tenure spanned multiple presidencies. “We jokingly referred to him as Emperor Alexander—with good cause, because whatever Keith wants, Keith gets,” says one former senior CIA official who agreed to speak on condition of anonymity. “We would sit back literally in awe of what he was able to get from Congress, from the White House, and at the expense of everybody else.”


What happened next in Alexander's career some time in the mid 2000's, was Stuxnet: the story of the crushing virus that nearly destroyed the Iranian nuclear program has been widely documented on these pages and elsewhere, so we won't recount the Wired article's details. However, what was very odd about the Stuxnet attack is that such a brilliantly conceived and delivered virus could ultimately be uncovered and traced back to the NSA and Israel. It was almost too good. Still, what happened after the revelation that Stuxnet could be traced to Fort Meade, is that the middle-east, supposedly, promptly retaliated:







Sure enough, in August 2012 a devastating virus was unleashed on Saudi Aramco, the giant Saudi state-owned energy company. The malware infected 30,000 computers, erasing three-quarters of the company’s stored data, destroying everything from documents to email to spreadsheets and leaving in their place an image of a burning American flag, according to The New York Times. Just days later, another large cyberattack hit RasGas, the giant Qatari natural gas company. Then a series of denial-of-service attacks took America’s largest financial institutions offline. Experts blamed all of this activity on Iran, which had created its own cyber command in the wake of the US-led attacks. James Clapper, US director of national intelligence, for the first time declared cyberthreats the greatest danger facing the nation, bumping terrorism down to second place. In May, the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team issued a vague warning that US energy and infrastructure companies should be on the alert for cyberattacks. It was widely reported that this warning came in response to Iranian cyberprobes of industrial control systems. An Iranian diplomat denied any involvement.
 
The cat-and-mouse game could escalate. “It’s a trajectory,” says James Lewis, a cyber­security expert at the Center for Strategic and International Studies. “The general consensus is that a cyber response alone is pretty worthless. And nobody wants a real war.” Under international law, Iran may have the right to self-defense when hit with destructive cyberattacks. William Lynn, deputy secretary of defense, laid claim to the prerogative of self-defense when he outlined the Pentagon’s cyber operations strategy. “The United States reserves the right,” he said, “under the laws of armed conflict, to respond to serious cyberattacks with a proportional and justified military response at the time and place of our choosing.” Leon Panetta, the former CIA chief who had helped launch the Stuxnet offensive, would later point to Iran’s retaliation as a troubling harbinger. “The collective result of these kinds of attacks could be a cyber Pearl Harbor,” he warned in October 2012, toward the end of his tenure as defense secretary, “an attack that would cause physical destruction and the loss of life.”


Almost too good... Because what the so-called hacker "retaliations" originating from Iran, China, Russia, etc, led to such laughable outcomes as DDOS attacks against - to unprecedented media fanfare - the portals of such firms as JPMorgan and Wells Fargo, and as Wired adds, "if Stuxnet was the proof of concept, it also proved that one successful cyberattack begets another. For Alexander, this offered the perfect justification for expanding his empire."


The expansion that took place next for Alexander and his men, all of it under the Obama regime, was simply unprecedented (and that it steamrolled right through the "sequester" was perfectly expected):







[D]ominance has long been their watchword. Alexander’s Navy calls itself the Information Dominance Corps. In 2007, the then secretary of the Air Force pledged to “dominate cyberspace” just as “today, we dominate air and space.” And Alexander’s Army warned, “It is in cyberspace that we must use our strategic vision to dominate the information environment.” The Army is reportedly treating digital weapons as another form of offensive capability, providing frontline troops with the option of requesting “cyber fire support” from Cyber Command in the same way they request air and artillery support.
 
All these capabilities require a giant expansion of secret facilities. Thousands of hard-hatted construction workers will soon begin erecting cranes, driving backhoes, and emptying cement trucks as they expand the boundaries of NSA’s secret city eastward, increasing its already enormous size by a third. “You could tell that some of the seniors at NSA were truly concerned that cyber was going to engulf them,” says a former senior Cyber Command official, “and I think rightfully so.”
 
In May, work began on a $3.2 billion facility housed at Fort Meade in Maryland. Known as Site M, the 227-acre complex includes its own 150-megawatt power substation, 14 administrative buildings, 10 parking garages, and chiller and boiler plants. The server building will have 90,000 square feet of raised floor—handy for supercomputers—yet hold only 50 people. Meanwhile, the 531,000-square-foot operations center will house more than 1,300 people. In all, the buildings will have a footprint of 1.8 million square feet. Even more ambitious plans, known as Phase II and III, are on the drawing board. Stretching over the next 16 years, they would quadruple the footprint to 5.8 million square feet, enough for nearly 60 buildings and 40 parking garages, costing $5.2 billion and accommodating 11,000 more cyberwarriors.
 
In short, despite the sequestration, layoffs, and furloughs in the federal government, it’s a boom time for Alexander. In April, as part of its 2014 budget request, the Pentagon asked Congress for $4.7 billion for increased “cyberspace operations,” nearly $1 billion more than the 2013 allocation. At the same time, budgets for the CIA and other intelligence agencies were cut by almost the same amount, $4.4 billion. A portion of the money going to Alexander will be used to create 13 cyberattack teams.


In the New Normal, the CIA is no longer relevant: all that matters are Alexanders' armies of hackers and computer geeks.


But not only has the public espionage sector been unleashed: the private sector is poised to reap a killing (pardon the pun) too...







What’s good for Alexander is good for the fortunes of the cyber-industrial complex, a burgeoning sector made up of many of the same defense contractors who grew rich supplying the wars in Iraq and Afghanistan. With those conflicts now mostly in the rearview mirror, they are looking to Alexander as a kind of savior. After all, the US spends about $30 billion annually on cybersecurity goods and services.
 
In the past few years, the contractors have embarked on their own cyber building binge parallel to the construction boom at Fort Meade: General Dynamics opened a 28,000-square-foot facility near the NSA; SAIC cut the ribbon on its new seven-story Cyber Innovation Center; the giant CSC unveiled its Virtual Cyber Security Center. And at consulting firm Booz Allen Hamilton, where former NSA director Mike McConnell was hired to lead the cyber effort, the company announced a “cyber-solutions network” that linked together nine cyber-focused facilities. Not to be outdone, Boeing built a new Cyber Engagement Center. Leaving nothing to chance, it also hired retired Army major general Barbara Fast, an old friend of Alexander’s, to run the operation. (She has since moved on.)
 
Defense contractors have been eager to prove that they understand Alexander’s worldview. “Our Raytheon cyberwarriors play offense and defense,” says one help-wanted site. Consulting and engineering firms such as Invertix and Parsons are among dozens posting online want ads for “computer network exploitation specialists.” And many other companies, some unidentified, are seeking computer and network attackers. “Firm is seeking computer network attack specialists for long-term government contract in King George County, VA,” one recent ad read. Another, from Sunera, a Tampa, Florida, company, said it was hunting for “attack and penetration consultants.”


It gets better: all those anti-virus programs you have on computer to "make it safe" from backdoors and trojans? Guess what - theyare the backdoors and trojans!







One of the most secretive of these contractors is Endgame Systems, a startup backed by VCs including Kleiner Perkins Caufield & Byers, Bessemer Venture Partners, and Paladin Capital Group. Established in Atlanta in 2008, Endgame is transparently antitransparent. “We’ve been very careful not to have a public face on our company,” former vice president John M. Farrell wrote to a business associate in an email that appeared in a WikiLeaks dump. “We don’t ever want to see our name in a press release,” added founder Christopher Rouland. True to form, the company declined Wired’s interview requests.
 
Perhaps for good reason: According to news reports, Endgame is developing ways to break into Internet-connected devices through chinks in their antivirus armor. Like safecrackers listening to the click of tumblers through a stethoscope, the “vulnerability researchers” use an extensive array of digital tools to search for hidden weaknesses in commonly used programs and systems, such as Windows and Internet Explorer. And since no one else has ever discovered these unseen cracks, the manufacturers have never developed patches for them.
 
Thus, in the parlance of the trade, these vulnerabilities are known as “zero-day exploits,” because it has been zero days since they have been uncovered and fixed. They are the Achilles’ heel of the security business, says a former senior intelligence official involved with cyberwarfare. Those seeking to break into networks and computers are willing to pay millions of dollars to obtain them.


Such as the US government. But if you thought PRISM was bad you ain't seen nuthin' yet. Because tying it all together is Endgame's appropriately named "Bonesaw" - what it is is practically The Matrix transplanted into the real cyber world.







According to Defense News’ C4ISR Journal and Bloomberg Businessweek, Endgame also offers its intelligence clients—agencies like Cyber Command, the NSA, the CIA, and British intelligence—a unique map showing them exactly where their targets are located. Dubbed Bonesaw, the map displays the geolocation and digital address of basically every device connected to the Internet around the world, providing what’s called network situational awareness.The client locates a region on the password-protected web-based map, then picks a country and city— say, Beijing, China. Next the client types in the name of the target organization, such as the Ministry of Public Security’s No. 3 Research Institute, which is responsible for computer security—or simply enters its address, 6 Zhengyi Road. The map will then display what software is running on the computers inside the facility, what types of malware some may contain, and a menu of custom-designed exploits that can be used to secretly gain entry. It can also pinpoint those devices infected with malware, such as the Conficker worm, as well as networks turned into botnets and zombies— the equivalent of a back door left open.
 
Bonesaw also contains targeting data on US allies, and it is soon to be upgraded with a new version codenamed Velocity, according to C4ISR Journal. It will allow Endgame’s clients to observe in real time as hardware and software connected to the Internet around the world is added, removed, or changed.


More on Bonesaw:







Marketing documents say “the Bonesaw platform provides a complete environment for intelligence analysts and mission planners to take a holistic approach to target discovery, reducing the time to create actionable intelligence and operational plans from days to minutes.”
 
Bonesaw is the ability to map, basically every device connected to the Internet and what hardware and software it is,” says a company official who requested anonymity. The official points out that the firm doesn’t launch offensive cyber ops, it just helps.


Back to Wired:







[S]uch access doesn’t come cheap. One leaked report indicated that annual subscriptions could run as high as $2.5 million for 25 zero-day exploits.


That's ok though, the US government is happy to collect taxpayer money so it can pay these venture capital-backed private firms for the best in espionage technology, allowing it to reach, hack and manipulate every computer system foreign. And domestic.


How ironic: US citizens are funding Big Brother's own unprecedented spying program against themselves!


Not only that, but by allowing the NSA to develop and utilize technology that is leaps ahead of everyone else  - utilize it against the US citizens themselves - America is now effectively war against itself... Not to mention every other foreign country that is a intelligence interest: 







The buying and using of such a subscription by nation-states could be seen as an act of war. “If you are engaged in reconnaissance on an adversary’s systems, you are laying the electronic battlefield and preparing to use it,” wrote Mike Jacobs, a former NSA director for information assurance, in a McAfee report on cyberwarfare. “In my opinion, these activities constitute acts of war, or at least a prelude to future acts of war.” The question is, who else is on the secretive company’s client list? Because there is as of yet no oversight or regulation of the cyberweapons trade, companies in the cyber-industrial complex are free to sell to whomever they wish. “It should be illegal,” says the former senior intelligence official involved in cyber­warfare. “I knew about Endgame when I was in intelligence. The intelligence community didn’t like it, but they’re the largest consumer of that business.”


And there you have it: US corporations happily cooperating with the US government's own espionage services, however since the only thing that matters in the private sector is the bottom line, the Endgames of the world will gladly sell the same ultra-secret services to everyone else who is willing to pay top dollar: China, Russia, Iran...







in their willingness to pay top dollar for more and better zero-day exploits, the spy agencies are helping drive a lucrative, dangerous, and unregulated cyber arms race, one that has developed its own gray and black markets. The companies trading in this arena can sell their wares to the highest bidder—be they frontmen for criminal hacking groups or terrorist organizations or countries that bankroll terrorists, such as Iran. Ironically, having helped create the market in zero-day exploits and then having launched the world into the era of cyberwar, Alexander now says the possibility of zero-day exploits falling into the wrong hands is his “greatest worry.”


Does Alexander have reason to be worried? Oh yes.







In May, Alexander discovered that four months earlier someone, or some group or nation, had secretly hacked into a restricted US government database known as the National Inventory of Dams. Maintained by the Army Corps of Engineers, it lists the vulnerabilities for the nation’s dams, including an estimate of the number of people who might be killed should one of them fail. Meanwhile, the 2013 “Report Card for America’s Infrastructure” gave the US a D on its maintenance of dams. There are 13,991 dams in the US that are classified as high-hazard, the report said.A high-hazard dam is defined as one whose failure would cause loss of life. “That’s our concern about what’s coming in cyberspace—a destructive element. It is a question of time,” Alexander said in a talk to a group involved in information operations and cyberwarfare, noting that estimates put the time frame of an attack within two to five years. He made his comments in September 2011.


In other words, this massive cyberattack against the US predicted by "Emperor" Alexander, an attack in which as Alexander himself has said cyberweapons represent the 21st century equivalent of nuclear arms (and require in kind retaliation) whether false flag or real, is due... some time right around now.