Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Friday, August 13, 2021

Microsoft protests Amazon win of big US cloud contract

SAN FRANCISCO, United States - Microsoft on Thursday confirmed it is challenging a decision to award a multibillion-dollar cloud computing contract to its rival Amazon.

US media reports said the contract valued at $10 billion is for modernizing storage of classified data at the National Security Agency (NSA).

"Based on the decision we are filing an administrative protest via the Government Accountability Office," Microsoft said in response to an AFP inquiry.

"We are exercising our legal rights and will do so carefully and responsibly."

The NSA spokesperson said that it "will respond to the protest in accordance with appropriate federal regulations," while Amazon declined to comment.

A post on the Government Accountability Office website showed that it is considering a protest filed by Microsoft in July concerning the NSA, but provided no details.

The move came as payback of sorts for Amazon successfully protesting a different $10-billion cloud computing contract that had been awarded to Microsoft.

The Pentagon in July scrapped the deal, known as the Joint Enterprise Defense Infrastructure (JEDI) contract, sidestepping a bitter dispute between Amazon and Microsoft over allegations of political bias that swayed the bidding.

Microsoft in late 2019 won the JEDI contract, sparking a challenge by Amazon on grounds that then president Donald Trump may have improperly influenced the outcome.

Amazon alleged it was shut out of the deal because of what it called Trump's vendetta against the company and its chief executive Jeff Bezos.

Agence France-Presse

Wednesday, January 15, 2020

Microsoft issues critical Windows security fix after tipoff from US NSA


WASHINGTON - Microsoft Corp on Tuesday rolled out an important security fix after the US National Security Agency tipped off the company to a serious flaw in its widely used Windows operating system, officials said.

Microsoft said the flaw could allow a hacker to forge digital certificates used by some versions of Windows to authenticate and secure data. Exploiting the flaw could have potentially serious consequences for Windows systems and users.

The NSA and Microsoft said they had not seen any evidence that the flaw had previously been abused, but both urged Windows users to deploy the update as soon as possible. NSA official Anne Neuberger noted that operators of classified networks had already been prodded to install the update and everyone else should now "expedite the implementation of the patch."

The Microsoft patch marks the first time the NSA has publicly claimed credit for prompting a software security update, although the agency said it has alerted companies in the past to flaws in their products. Neuberger said the agency was striving for more transparency with the information security research community.

"Part of building trust is showing the data," she told reporters in a call just minutes before the patch went live.

Experts said the move was unprecedented.

"I have never seen this before," said Tenable Chief Executive Amit Yoran, who previously served as founding director of the U.S. Computer Emergency Readiness Team.

"I cannot think of a single instance where government shared a zero-day with a vendor and took credit for it," he said in an email.

The NSA faces a balancing act when it comes across such vulnerabilities. The agency had been criticized after its cyberspies took advantage of vulnerabilities in Microsoft products to deploy hacking tools against adversaries and kept the Redmond, Washington-based company in the dark about it for years.

When one such tool was dramatically leaked to the internet in 2016, it was deployed against targets around the globe by hackers of all stripes.

In the most dramatic case, a group used the tool to unleash a massive malware outbreak dubbed WannaCry in 2017. The data-wiping worm wrought global havoc, affecting what Europol estimated was some 200,000 computers in more than 150 countries.

Neuberger did not directly address that controversy in her call but said that the NSA hoped to be "a good cybersecurity partner."

"We're working to evolve our mission," she said.

source: news.abs-cbn.com

Friday, January 12, 2018

U.S. lawmakers approve warrantless internet spying program


The U.S. House of Representatives on Thursday passed a bill to renew the National Security Agency's warrantless internet surveillance program, overcoming objections from privacy advocates and confusion prompted by morning tweets from President Donald Trump that initially questioned the spying tool.

The legislation, which passed 256-164 and split party lines, is the culmination of a years-long debate in Congress on the proper scope of U.S. intelligence collection - one fueled by the 2013 disclosures of classified surveillance secrets by former NSA contractor Edward Snowden.

Senior Democrats in the U.S. House of Representatives had urged cancellation of the vote after Trump appeared to cast doubt on the merits of the program, but Republicans forged ahead.

Trump initially said on Twitter that the surveillance program, first created in secret after the Sept. 11, 2001, attacks and later legally authorized by Section 702 of the Foreign Intelligence Surveillance Act, had been used against him but later said it was needed.

Some conservative, libertarian-leaning Republicans and liberal Democrats attempted to persuade colleagues to include more privacy protections. They failed on Thursday to pass an amendment to include a warrant requirement before the NSA or other intelligence agencies could scrutinize communications belonging to Americans whose data is incidentally collected.

Thursday's vote was a major blow to privacy and civil liberties advocates, who just two years ago celebrated passage of a law effectively ending the NSA's bulk collection of U.S. call records, another top-secret program exposed by Snowden.

The bill as passed by the House would extend the NSA's spying program for six years with minimal changes. Some privacy groups said it would actually expand the NSA's surveillance powers.

Most lawmakers expect it to become law, although it still would require Senate approval and Trump's signature. Republican Senator Rand Paul and Democratic Senator Ron Wyden immediately vowed to filibuster the measure but it was unclear whether they could convince enough colleagues to force changes.

The White House, U.S. intelligence agencies and Republican leaders in Congress have said they consider the surveillance program indispensable and in need of little or no revision.

Before the vote a tweet from Trump had contradicted the official White House position and renewed unsubstantiated allegations that the previous administration of Barack Obama improperly surveiled his campaign during the 2016 election.

"This is the act that may have been used, with the help of the discredited and phony Dossier, to so badly surveil and abuse the Trump Campaign by the previous administration and others?" the president said in a tweet.

"WE NEED IT!"  

The White House did not immediately respond to a request to clarify Trump’s tweet but he posted a follow-up less than two hours later, after speaking on the phone with House Republican leader Paul Ryan.

"With that being said, I have personally directed the fix to the unmasking process since taking office and today’s vote is about foreign surveillance of foreign bad guys on foreign land. We need it! Get smart!" Trump tweeted.

Unmasking refers to the largely separate issue of how Americans' names kept secret in intelligence reports can be revealed.

After the vote Thursday, Ryan, asked about his conversation with the president, said Trump's concerns regarded other parts of the law.

"It's well known that he has concerns about the domestic FISA law. That's not what we're doing today. Today was 702, which is a different part of that law ... He knows that and he, I think, put out something that clarifies that," Ryan told reporters.

Asked by Reuters at a conference in New York about Trump's tweets, Rob Joyce, the top White House cyber official, said there was no confusion within Oval Office about the value of the surveillance program and that there have been no cases of it being used improperly for political purposes.

Without congressional action, legal support for Section 702 will expire next week, although intelligence officials say it could continue through April.

Section 702 allows the NSA to eavesdrop on vast amounts of digital communications from foreigners living outside the United States through U.S. companies such as Facebook Inc, Verizon Communications Inc and Alphabet Inc's Google.

The spying program also incidentally scoops up communications of Americans if they communicate with a foreign target living overseas, and can search those messages without a warrant.

source: news.abs-cbn.com

Friday, November 17, 2017

Kaspersky blames NSA hack on infected Microsoft software


Embattled computer security firm Kaspersky Lab said Thursday that malware-infected Microsoft Office software and not its own was to blame for the hacking theft of top-secret US intelligence materials.

Adding tantalizing new details to the cyber-espionage mystery that has rocked the US intelligence community, Kaspersky also said there was a China link to the hack.

The Moscow-based anti-virus software maker, which is now banned on US government computers because of alleged links to Russian intelligence, confirmed that someone did apparently steal valuable National Security Agency programs from an NSA worker's home computer, as first reported by the Wall Street Journal on October 5.

According to the Journal, the person had top secret files and programs from the NSA hacking unit called the Equation Group on his computer, which was also using Kaspersky software protection.

They believe that Russian spies used the Kaspersky program as a back door to discover and siphon off the files, reportedly causing deep damage to the NSA's own cyber-espionage operations.

US allegations that Kaspersky, which sold more than $600 million of anti-virus software globally in 2015, knowingly or unknowingly helped Russian intelligence in the theft have effectively killed its US business and hurt its worldwide reputation.

Kaspersky software 'disabled'

Using its own forensic analysis, Kaspersky said the breach of the NSA worker's computer took place between September and November 2014, rather than 2015 as the Journal reported.

Kaspersky said what was stolen included essential source code for some Equation Group malware, as well as classified documents. Based on the materials, it said the computer appeared to belong to someone involved in creating malware for the Equation Group.

The company claimed, however, that the computer was infected by other malware, including a Russian-made "backdoor tool" hidden in Microsoft Office.

Kaspersky said that the malware was controlled from a computer server base in Hunan, China, and would have opened a path into the computer for anyone targeting an NSA worker.

"Given that system owner's potential clearance level, the user could have been a prime target of nation-states," it said.

Kaspersky's own software would have detected that malware, the company said, except that its software had been turned off.

"To install and run this malware, the user must have disabled Kaspersky Lab products on his machine," it claimed.

pmh/jh

source: news.abs-cbn.com

Thursday, September 15, 2016

U.S. House panel slams former NSA contractor Snowden


WASHINGTON - A U.S congressional intelligence committee on Thursday issued a scathing report accusing former National Security Agency contractor Edward Snowden of leaking information that "caused tremendous damage" to U.S. national security, lying about his background and feuding with co-workers.

In a report endorsed by both its Republican and Democratic leaders, the House intelligence committee said Snowden was "not a whistleblower" as he has claimed.

Most of the material he stole from the NSA was not about invasions of privacy, but revealed intelligence and defense programs of great interest to America's foreign adversaries, it said.

The committee said that while the "full scope" of damage caused by Snowden's disclosures remains unknown, a review of materials he allegedly compromised "makes clear that he handed over secrets that protect American troops overseas and secrets that provide vital defenses against terrorists and nation-states."

The committee released only a four-page summary of what it said was a 36-page investigative report that remains Top Secret, but the summary contained strong words about Snowden's actions and background.

The report contains previously unreported allegations about Snowden and his possible motives for taking government secrets. It alleges that Snowden, who took refuge in Moscow after fleeing to Hong Kong, "was and remains a serial exaggerator and fabricator."

It says his official employment records show that while he claimed to have left U.S. Army basic training because of broken legs, in fact he "washed out because of shin splits." The report says Snowden claimed to have obtained a high-school graduation equivalent, but in fact never did.

It also says he claimed to have worked as a "senior advisor" for the CIA when in fact he was an entry-level computer technician.

While the report says Snowden "stole 1.5 million sensitive documents," other sources who have examined materials he turned over to media outlets say that the total is between 200,000 and 300,000 documents.

Some U.S. officials involved in Snowden-related investigations acknowledge that the U.S. government does not know how many documents Snowden downloaded, and that the 1.5 million figure is an estimate.

The report also disputes Snowden's motives for taking and leaking classified information, saying he got into a "workplace spat" with NSA managers in June 2012 over how to manage computer updates. It says a contracting officer reprimanded him for failing to follow proper grievance procedures, and he began downloading classified information two weeks later.

However, in 2013, Reuters quoted U.S. officials and other sources familiar with the matter as saying that Snowden began downloading such data in April 2012, almost a year earlier than had previously been reported at the time.

The issuance of the House committee report coincided with the release of "Snowden", a movie directed by Oliver Stone that portrays him as a whistleblower and hero. On Wednesday, prominent human rights advocates urged President Barack Obama to pardon Snowden before leaving office in January.

U.S. officials have said Obama is not considering a pardon for Snowden, who is facing U.S. criminal charges for providing classified information to unauthorized persons.

Ben Wizner, an attorney with the American Civil Liberties Union who represents Snowden, dismissed the House committee report as lacking substance.

Wizner said the report's release a day before the Snowden film opens "is evidence that people in the intelligence community are taking us seriously, that they are concerned that Oliver Stone's movie will help solidify Snowden's image as a true patriot, which he is." (Reporting By Mark Hosenball; Additional reporting by Dustin Volz; editing by John Walcott and Alan Crosby)

source: www.abs-cbnnews.com

Thursday, March 31, 2016

FBI's secret method of unlocking iPhone may never reach Apple


WASHINGTON - The FBI may be allowed to withhold information about how it broke into an iPhone belonging to a gunman in the December San Bernardino shootings, despite a U.S. government policy of disclosing technology security flaws discovered by federal agencies.

Under the U.S. vulnerabilities equities process, the government is supposed to err in favor of disclosing security issues so companies can devise fixes to protect data. The policy has exceptions for law enforcement, and there are no hard rules about when and how it must be applied.

Apple Inc has said it would like the government to share how it cracked the iPhone security protections. But the Federal Bureau of Investigation, which has been frustrated by its inability to access data on encrypted phones belonging to criminal suspects, might prefer to keep secret the technique it used to gain access to gunman Syed Farook's phone.

The referee is likely to be a White House group formed during the Obama administration to review computer security flaws discovered by federal agencies and decide whether they should be disclosed.

Experts said government policy on such reviews was not clear-cut, so it was hard to predict whether a review would be required. "There are no hard and fast rules," said White House cybersecurity coordinator Michael Daniel, in a 2014 blog post about the process.

If a review is conducted, many security researchers expect that the White House group will not require the FBI to disclose the vulnerability it exploited.

Some experts said the FBI might be able to avoid a review entirely if, for instance, it got past the phone's encryption using a contractor's proprietary technology.

Explaining the policy in 2014, the Office of the Director of National Security said the government should disclose vulnerabilities “unless there is a clear national security or law enforcement need."

The interagency review process also considers whether others are likely to find the vulnerability. It tends to focus on flaws in major networks and software, rather than individual devices.

During a press call, a senior Justice Department official declined to disclose whether the method used on Farook's phone would work on other phones or would be shared with state and local law enforcement.

Apple declined to comment beyond saying it would like the government to provide information about the technique used.

PROTECTING "CRUCIAL INTELLIGENCE"

The government reorganized the review process roughly two years ago and has not disclosed which agencies regularly participate other than the Department of Homeland Security and at least one intelligence agency. A National Security Council spokesman did not respond to a request for comment about agency participation.

In his April 2014 blog post, White House cybersecurity coordinator Daniel, who chairs the review group, said secrecy was sometimes justified.

“Disclosing a vulnerability can mean that we forego an opportunity to collect crucial intelligence that could thwart a terrorist attack stop the theft of our nation’s intellectual property,” Daniel wrote.

On Tuesday, a senior administration official said the vulnerability review process generally applies to flaws detected by any federal agency.

Paul Rosenzweig, a former deputy assistant secretary at the Department of Homeland Security, said he would be “shocked” if the Apple vulnerability is not considered by the group.

“I can’t imagine that on one of this significance that the FBI, even if it tried to, would succeed in avoiding the review process,” said Rosenzweig, founder of Red Branch Consulting, a homeland security consulting firm.

He predicted the FBI would not be forced to disclose the vulnerability because it appears to require physical possession of a targeted phone and therefore poses minimal threat to Internet security more broadly.

Many security researchers have suggested that the phone's content was probably retrieved after mirroring the device's storage chip to allow data duplication onto other chips, effectively bypassing limitations on the number of passcode guesses.

Kevin Bankston, director of the think tank Open Technology Institute, said there is no public documentation of how the review process has worked in recent years. He said Congress should consider legislation to codify and clarify the rules.

Stewart Baker, former general counsel of the NSA and now a lawyer with Steptoe & Johnson, said the review process could be complicated if the cracking method is considered proprietary by the third party that assisted the FBI.

Several security researchers have pointed to the Israel-based mobile forensics firm Cellebrite as the likely third party that helped the FBI. That company has repeatedly declined comment.

If the FBI is not required to disclose information about the vulnerability, Apple might still have a way to pursue details about the iPhone hack.

The Justice Department has asked a New York court to force Apple to unlock an iPhone related to a drug investigation. If the government continues to pursue that case, the technology company could potentially use legal discovery to force the FBI to reveal what technique it used, a source familiar with the situation told Reuters.

At least one expert thinks a government review could require disclosure. Peter Swire, a professor of law at the Georgia Institute of Technology who served on the presidential intelligence review group that recommended the administration disclose most flaws, said there is “a strong case” for informing Apple about the vulnerability under the announced guidelines.

“The process emphasizes the importance of defense for widely used, commercial software,” he said.

source: www.abs-cbnnews.com