SocraticGadfly: cybersecurity
Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

July 03, 2018

Mueller Time new angle: How serious to take Emptywheel? (Still not so much, as the 'big reveal' isn't)

Over the past year, as of the time I originally wrote this piece, I had believed, until recently, almost totally in the claims by Consortium News, and somewhat lesser by people like Mark Ames and Yasha Levine, that Putin Did NOT Do It on massive election interference in the US.

Marcy Wheeler, one of the first spinoffs from Orange Satan, aka, Markos Moulitsas of "sekrut librulz in the CIA fame," at first tempted me into jettisoning all this. But, she ultimately failed. And, as of late 2020, still has.

I still think there's blatant Hillbot claims that are overblown about what the Russians DID do, and I also know that much of what Robert Mueller has on Paul Manafort is him grifting for Ukraine, rather than Russia, as I noted here.

Marcy Wheeler, aka Emptywheel, has put forth a bombshell claim. Big enough to top Memeorandum.

She says she personally knows a journalist who was helping Russky operators. Helping them enough she turned said person into the FBI.
Sometime last year, I went to the FBI and provided information on a person whom I had come to believe had played a significant role in the Russian election attack on the US. Since that time, a number of public events have made it clear I was correct. 
I never in my life imagined I would share information with the FBI, especially not on someone I had a journalistic relationship with. I did so for many reasons. Some, but not all, of the reasons are:
  • I believed he was doing serious harm to innocent people
  • I believed (others agreed) that reporting the story at that time would risk doing far more harm than good
  • I had concrete evidence he was lying to me and others, including but not limited to other journalists
  • I had reason to believe he was testing ways to tamper with my website
  • I believed that if the FBI otherwise came to understand what kind of information I had, their likely investigative steps would pose a risk to the privacy of my readers
To protect the investigation, I will not disclose this person’s true identity or the identity and/or role I believe he played in the attack. … 
The other reason I’m disclosing this now is to put a human face to the danger in which the House Republicans are putting other people who, like me, provided information about the Russian attack on the US to the government.
Well, that's pretty serious. IF it's meaningful.

If this is even 50 percent true, it finishes sinking the Consortium News / Ray McGovern / VIPS battleship.

But is it? (MY big reveal? It's not.) Besides, just weeks after her bombshell, Marcy was undermining herself. Not just once, but twice.

Let's examine a bit further.

"Serious harm to innocent people"? Can't be physical harm, unless Wheeler is refusing to file charges against someone for aggravated assault. If she means something like gaslighting, well ... we don't know what it is since she didn't spell it out.

Most the rest of this is similarly vague.

And, "privacy of my readers"? Like she thinks the FBI is going to look up the IP addresses of every person reading, or even every person commenting? Yikes if you're really saying that.

And questionable. Unless the FBI thought you were a "person of interest" in this "Mister X's" shenanigans, there's little likelihood they would investigate all of your readers. They might investigate the set of readers that commented on your site and/or Twitter AND ALSO commented on "Mr X's" blog and/or Twitter or Effbook.

This comes off as a "Trust me, dear readers" post. Well, I'm not a regular reader, so I don't. I don't MIStrust, but I don't really trust this at face value, either. And, judging by July 5 and onward Twitter response ... yeah, some readers are going that route.

That said, there's an increasing belief in my mind that Seth Rich did  NOT steal any DNC emails. (Or, per that, other people at the DNC. [Sadly, it took me until 2018 to fully realize that Julian Assange had deliberately and perversely goosed a conspiracy theory.]) Related to that, at a minimum, there's the strong belief that the Consortium News / Veteran Intelligence Professionals for Sanity claims that Putin henchmen couldn't have downloaded the initial, spring 2018 emails quickly enough is on thin ice and was on thin ice from the time the claims were made.

Seeing all of this in light of Consortium News being riddled with conspiracy theorists is why I de-blogrolled it.

Update, Aug. 22: Sorry, Marcy, but the Manafort conviction proves nothing new.

Now, we have a counterbombshell at Consortium News, originally from his own site. Jack Matlock, former ambassador the USSR, says the "17 intelligence agencies" report of early 2017 was politically motivated. First, an overview, for those to whom this isn't already known:
The report states that it represents the findings of three intelligence agencies: CIA, FBI, and NSA, but even that is misleading in that it implies that there was a consensus of relevant analysts in these three agencies. In fact, the report was prepared by a group of analysts from the three agencies pre-selected by their directors, with the selection process generally overseen by James Clapper, then Director of National Intelligence (DNI).
In other words, the cherry-picking was set up in advance. Remember the "aluminum tubes" of 15 years ago?

From there, Matlock said he found unusual both the omission of the State Department's intelligence arm and the inclusion of the FBI.

That leads to this:
As I was recently informed by a senior official, the State Department’s Bureau of Intelligence Research did, in fact, have a different opinion but was not allowed to express it. So the January report was not one of the “intelligence community,” but rather of three intelligence agencies, two of which have no responsibility or necessarily any competence to judge foreign intentions.
But wait, that's not all.

Matlock calls Guccifer 2.0 a "fabrication."

Sorry, Jack, but that part? You've got it wrong. I'll venture that the "retired NSA technical experts" may be the people who worked to compile evidence for VIPS. Does that mean that Forensicator is one of them? (Oh, and contra one Twitter buttinski, of course's it's of value to know who Forensicator is, given VIPS split report and other things. This isn't like blind-screening male vs female first violin candidates, or other issues in the arts. Unlike you, I try to avoid buying anonymous pigs in pokes on science or technology issues, and since he pops up nowhere before the DNC emails download question, I can't find other stuff on him.)

(Update, Aug. 6: Forensicator, if Computer Weekly is right, is possibly a front man for a British self-described black hat hacker and pro-Trumpist Tim Leonard playacting as. And, Duncan Campbell says that Bill Binney, at least, within VIPS, flipped his stance on the "impossible to download internationally claims" after taking a second look at the files, with Campbell. But Binney claims that Campbell misinterprets him. But, Binney himself misinterprets the VIPS statement. Per the "minority report" linked above, it's clear that not all of VIPS accepted that this had to be a download, not a hack.

And, as for Disobedient Media lamenting a "smear" of Leonard/Carter? Good for the goose, good for the gander — Bill Binney apparently believes in microwave mind control weapons. And, the person whose show he is on thinks this is a plot to remove gun rights.)

(Update, April 8, 2021: Until reading Glenn Greenwald's "No Place to Hide," I didn't know Campbell's background. Well, Duncan Campbell, as the man who first exposed the GCHQ by name and the "Five Eyes," knows his shit. As a man earlier targeted for prosecution under Britain's Official Secrets Act, he has no love lost for the national security state or its smears. So, his pronouncements re the Seth Rich case, and his skill in getting the information, should be taken with the utmost seriousness.)

And, speaking of, Matlock notes that Ray McGovern helped in preparation of the document. On the third hand, with this originally at his own website / blog, heading there, Matlock decried "Russiagate hysteria" a month ago.

To which Wheeler says, on Twitter:
And, this, when I told her I'd take Matlock first.
And, I've exited the conversation there, and made sure that I don't see more conversation for right now. That's because I DO care about facts, and since I'm not one of your "Dear Readers," I don't buy your claims at face value.

Speaking of?

The really big issue is Wheeler calling on people to refute her.

HOW, as I told her back on Twitter. You have an unnamed "Mr. X" with no details of what info you gave the FBI. There's nothing to be refuted without empirical data. Again, back to the "Dear Readers, just trust me" angle.

The real bottom line?

As Ryan Cooper notes? The 2016 election issues were about AMERICAN corruption. And, no, TrumpTrain riders, other wingnuts, and fellow travelers, no Deep State involved.

But, that corruption, though manifesting itself more in the GOP, is bipartisan within the duopoly.

UPDATE, July 26: Actually, in a new piece about the FBI's history on FISA warrant applications on Carter Page and the value of the Steele Dossier, Wheeler offers material to refudiate herself even while squirming to escape that trap. She does this with her cite of former CIA agent Daniel Hoffman:
There is a third possibility, namely that the dossier was part of a Russian espionage disinformation plot targeting both parties and America’s political process. This is what seems most likely to me.
Exactly. And, it's what a lot of we "skeptics" have said all along. Whatever was being done, to the degree it was semi-official Russian government disinformation, it was done to monkey-wrench in general, not elect Trump.

Wheeler wriggles out by claiming that rather, any disinfo in the dossier was to make the Dems complacent. 

Hey, Marcy? The Dems were willfully complacent after a Sanders staffer got on DNC servers in 2015. They were complacent before that, but willfully so afterward.  ☹️

As far as some of the other stuff, as Aaron Mate noted on Twitter, that Trump wanted to talk to Syria is nothing new. And? Maybe not in the exact way Trump is doing it, and not for forming an anti-Iran coalition, we need to get out of Syria, period.

In fact, much of the piece seems to focus on "Mr. X" and his relation to Syria issues.

Given that Ray McGovern is so nutbar as to think Devin Nunes is a genius, here's Marcy's latest take on him, "the half-wit running our intelligence oversight." I'd agree with that. So would a lot of others like me, who do NOT think "Putin Did It," certainly not to the degree Wheeler claims.

That said, Marcy Wheeler is ultimately a Democrat. She's a Democrat who is a Kossack alumnus. Is Markos still looking for sekrut librulz in the CIA? She's a Democrat who tosses around allegations as though they were proven fact — not as badly or as baldly as a David Corn, but not incredibly behind him, either.

She's a Democrat who is right half-right about the Jill Stein recount, (update: Stein has actually achieved some good, even if for the wrong motives) but overblown at best and wrong at worst about Jill Stein the person. (Update: It was actually fellow former Kossack "Bmaz" who wrote this post. Given that the byline line of her site isn't highly visible, yes, I missed that this was a guest post. And, Marcy, if that's the first thing you found to nitpick ... that to me is just further indication of how thin your stance is.)

I searched Marcy's site, and she has basically no postings about the Green Party. She has just a couple of late-2016 ones about Stein, which come off as sour grapes. So, I quote (from the Bmaz post):
Jill Stein, admittedly, always struck me as a bit of a naive and somewhat unhinged candidate.
Naive? Not at all. Ardent, but short of unhinged? Yes. And, I've criticized both her campaign and her recount.
What Jill Stein is doing is blatant self promotion, list building, reputational repair where it is undeserved, and slush funding for an incoherent Green Party.
This is pure ignorance, re the Green Party. Given that the Party executive committee refused to support the recount, they get no money from this. Only Stein does. (And I just Tweeted her this.)

And, her response? She does note that the post is by Bmaz. OK .... my countertweet:
That's that. And Bmaz was an even bigger deep-fried anti-Green Dem-only Kossack disciple than Wheeler was, IIRC. AND !!!! Bmaz on his Twitter lists Emptywheel as his web location. So, that's that, Marcy. Bite me.

And, ironically, in another blog post of mine where I had previously linked to that post AND noted that Bmaz had written it, I have confirmation of Bmaz being a deep-fried anti-Green Dem-only Kossack dumb fuck. I excerpt the following:

Kos, yes, THAT Kos, (said) that West Virginia coalminers deserve to lose their insurance and die early if that's a result of voting Trump.

Then, there's Kos alum Bmaz:
Not even worth responding to, though I've gotten part of a group fire on Twitter on this.

Hilariously, on Emptywheel, he tells people in this post (the same as I misidentified the authorship this time) its time to move beyond 2016. But, on Twitter, he still can't do that. THAT, in a nutshell, is Clintonistas' own Clinton Derangement Syndrome.

That said, I agree with "moving on." But, I don't practice unilateral disarmament, or singing Kumbaya.

Actually, Bmaz does deserve a response, now.

I'd like to be crystal clear: You're a fucking asshole and have been so ever since Kos days. And, you and Marcy probably both support Jill Stein being hauled before the Senate Intelligence Committee.

Back to the original thread.

And, yes, I think you are touchy, Marcy, if you're going to bitch about a byline on a secondary link — and one with which I said I partially agree. I think you're even more so if that was the first thing you picked out when you Tweeted back to me.

At the same time, Wheeler fully rejects the Hillbot route:
The vote differential, again in Wisconsin for instance, between Clinton and Trump currently stands at 27,259 votes. Yes, that is less than the total of Stein, so despite the wild claim she threw the election that some Clinton supporters have thrown, I will not. Some Stein voters were never going to vote for Clinton; so while Stein’s vanity run deserves ridicule, it does not, in and of itself, “prove” Clinton would have won but for Stein.
At the fourth time, the picture for this blog post is Stein at Putin's table. (That said, one Green Party presidential nomination candidate, Bill Kreml, is on record as it being a dumb idea.)

At the sixth time, Wheeler has a past history as a Democratic Party operative at the county level, per Wiki.

I think all of this is necessary for background.

I await finding out who Wheeler's fellow journalist is. And, even more, beyond Wheeler's blog post, how likely Wheeler's claims are about this person.

That's because, while the VIPS claim is not fully proven, it may well still be true, among other things. And, state election departments have already rejected claims their systems were hacked.

So, per a further review of Wheeler's site, already in December 2016 Wheeler was making claims not proven then nor proven today, such as: 
This is the part that has always been missing in the past: how the documents got from GRU, which hacked the DNC and John Podesta, to Wikileaks, which released them.
That came up when I did the "17 intelligence agencies" search.

Wheeler seems to have had some degree of skepticism, but ... scratch that. Any possible skepticism of hers is pretty modest. Anyway, her claims about "hacked the DNC" remain unproven, at least for public consumption. There also, at least at one time, were other candidates besides Seth Rich and Putin both on the possible hacking.

Anyway, that was one of only two hits on that search. Why? Maybe Marcy lost interest. Maybe, as other people noted even more than her the Mack-truck sized loopholes on that, she moved on.

Or because she believes "Putin Did It" is a slam dunk after all. (And she may be calling interest in the Steele Dossier overrated because of reported Clinton campaign connections to it.) And, she'd be wrong. Bmaz also drinks deeply from the Putin Did It Kool-Aid. (Theft of emails is not the same as Putin-Trump collusion. Period.)

Also, she thinks the Internet Research Agency indictments are a much better deal than Mate, per my Manafort link above, believes. (She also ignores that such indictments violate at least the spirit of the First Amendment, or so I see them doing.)

In other words, on her "journalist" claim, I just don't know at this time how much of Wheeler's skin in the game is her actual cybersecurity knowledge and writing about that, and how much of it is Democratic Party former operative background. (For the one snarker on Twitter, that's a use of quote marks as reference quotes, not scare quotes. Derp.)

But, given what I've grokked, I'll call it a 50-50 split off the top of my head.

And so, while thinking her reporting is interesting, I'd take it with a grain of salt, starting with the header: 
Putting A Face (Mine) To The Risks Posed By GOP Games On Mueller Investigation
Yes, the GOP has played games. So have Democrats, specifically, various iterations of the "Russiagate Hysteria" mentioned by Matlock. And, since I'm not part of the duopoly, I can say there are more than two sides here.

And, although page clicks are much less important than in the past, I put a "no follow" on Marcy's post.

So, again, no more than 50-50 on seriousness level. If some wingnutistan blogger was the attempted computer hacker, and allegedly was helping Putin from his parents' basement, we'll laugh about Marcy later.

That said, it's almost certainly not a stereotypical wingnut blogger. She claims to be "friendly" with the person.

And, no, I'm not wasting further time fishing through all her posts and guest posts to see exactly where she falls on "Putin Did It." I did tell her that I still stand pretty much where I did before reading.

Meanwhile, Jon Chait and David Corn are doing their best to stay ahead of Wheeler in the Putin Did It nutbar competition.

Updates below:

August 03, 2012

#Cybercrime, #NSA, #new snooping

ProPublica has a decent story asking whether an often-bandied figure of $1 trillion isn't at least a touch, if not way more than a touch, too high a figure. (Cyberespionage, and even cyberwar is included here, even when, in the case of China, Team Obama refuses to call a spade a spade.)

That said, there's the lead-in for saying why this is only a decent and not a great story.

For it to be that, we'd have to have ProPublica ask:
1. How much does cyberespionage/cybercrime cost globally?
2. How much of that is US caused?

And, by that, I don't mean spammers and hackers who live in the US rather than China, Russia or Nigeria.

 I mean (ahem, Stuxnet) how much does US government-caused cybercrime (or, arguably, cyberwar, with Stuxnet) cost elsewhere in the world? I mean (ahem, BushCo [and probably, Team Obama, too] spying on UN Security Council members, including ways that could be considered cyberspying?


Other questions abound.


Does the National Security Agency endorse, and regularly use, McAfee's $1 trillion estimate because it's angling for new budget dinero? Or, even worse, for even more "black arts" countermeasures, with a likely further eroding of American civil liberties.


In other words, the NSA is into "marketing" just like McAfee. Only thing, this is a lot scarier, if you really think about it.

Beyond that, this is an issue of American exceptionalism.

The story could be seen as implying that only the US has that serious of worries about cybercrime. Or that the US doesn't really do it that much itself. Or both. 


That's just not true.



Beyond the government-side issues, how much cybercrime on the corporate side is done by American companies?

July 11, 2009

Evidence mounts – North Korea army behind cyberattacks

Well, it looks like some U.S. media haven’t been probing American “security experts” hard enough about last week’s cyberattacks. The government of South Korea is gathering more evidence that the North Korean Army was behind the computer attacks on South Korean and U.S. government financial and national security websites and computers just before the Fourth of July.
Members of (South Korea’s) parliamentary intelligence committee have said in recent days that the National Intelligence Service has also pointed to a North Korean boast last month that it was “fully ready for any form of high-tech war.”

The spy agency told lawmakers Friday that a research institute affiliated with the North's Ministry of People's Armed Forces received an order to “destroy the South Korean puppet communications networks in an instant,” the mass-circulation JoongAng Ilbo newspaper reported.

To me, it’s clear for the reasons I originally reported, that Washington doesn’t even want to discuss this because it’s kind of pooping its collective national security pants. Is it just “coincidence” that the Obama Administration proposed new cybersecurity legislation at the same time?

Anyway, since the WaPost, NYT, etc. aren’t covering the story with much depth, the AP story a must read.

As I blogged two days ago, and the mainstream media is finally catching up to, that’s the best explanation I can think of for cyberattacks that knocked out financial and national security websites in both the U.S. and South Korea over the Fourth of July.

And, here is the bottom line of why I said then that Washington was being tight-lipped:
Remember how North Korea partnered with Pakistan’s A.Q. Khan to spread rocket technology and nuclear know-how? Don’t you doubt for a second that Pyongyang will sell this technology wherever possible.


Also, assuming my original rhetorical question about North Korean has a “yes” answer, U.S. and South Korean officials both have to be pooping their pants. The Kims, father and son, are both not the most mentally stable world leaders.

That is why Team Obama won’t say anything of substance.

At the same time, many South Koreans say they don’t like the hardline stance toward Pyongyang of South Korean President Lee Myung Bak, elected in 2007.

July 09, 2009

North Korea – cyberterrorist or not?

As I blogged two days ago, and the mainstream media is finally catching up to, that’s the best explanation I can think of for cyberattacks that knocked out financial and national security websites in both the U.S. and South Korea over the Fourth of July.

And, here's what the MSM is saying.

The Washington Post says it has the earmarks of North Korea, also citing South Korean official government suspicions.

But Reuters says, wait a minute, citing experts who claim the attacks did not originate from computers inside North Korea, claiming the attacks were “unsophisticated,” too, for North Korea.

Update, July 11: Well, it looks like some U.S. media haven’t been probing American “security experts” hard enough about last week’s cyberattacks. The government of South Korea is gathering more evidence that the North Korean Army was behind the computer attacks on South Korean and U.S. government financial and national security websites and computers just before the Fourth of July.

On the other hand, back to the Post story, cyberexperts there note that, alongside the “amateurish” part was the high volume of the attack, something most amateurs could’t deliver.

Now, in contrast to South Korea, U.S. government officials are still being tight-lipped,

If my question has a “yes” answer, U.S. and South Korean officials both have to be pooping their pants. The Kims, father and son, are both not the most mentally stable world leaders.

And, remember how North Korea partners with Pakistan’s A.Q. Khan to spread rocket technology and nuclear know-how? Don’t you doubt for a second that Pyongyang will sell this technology wherever possible.

July 08, 2009

Is North Korea into cyberterror?

That’s the best explanation I can think of for cyberattacks that knocked out financial and national security websites in both the U.S. and South Korea over the Fourth of July.

Now, government officials are being tight-lipped, for obvious reasons, but there’s no other country I can think of that would target us and South Korea and nobody else.

If my question has a “yes” answer, U.S. and South Korean officials both have to be pooping their pants. The Kims, father and son, are both not the most mentally stable world leaders.

And, remember how North Korea partners with Pakistan’s A.Q. Khan to spread rocket technology and nuclear know-how? Don’t you doubt for a second that Pyongyang will sell this technology wherever possible.

Update, July 9: Finally, just a couple of days after I mentioned the idea, the MSM is catching up on the possible North Korea angle.

The Washington Post says it has the earmarks of North Korea, also citing South Korean official government suspicions.

But Reuters says, wait a minute, citing experts who claim the attacks did not originate from computers inside North Korea, claiming the attacks were “unsophisticated,” too, for North Korea.

On the other hand, back to the Post story, cyberexperts there note that, alongside the “amateurish” part was the high volume of the attack, something most amateurs could’t deliver.

Update No. 2, July 11: Well, it looks like some U.S. media haven’t been probing American “security experts” hard enough about last week’s cyberattacks. The government of South Korea is gathering more evidence that the North Korean Army was behind the computer attacks on South Korean and U.S. government financial and national security websites and computers just before the Fourth of July.

May 29, 2009

Cyber-czar – yet the latest Obama czardom

Hey, I have no problem with the White House wanting to increase its focus on cybersecurity issues. But, the appropriate place for that focus is where the Bush Administration had it, within the Department of Homeland Security, and NOT with yet another White House-based czar, yet another Obama management tool of dubious constitutionality.

More creeping presidentialism.