Showing posts with label WikiLeaks. Show all posts
Showing posts with label WikiLeaks. Show all posts

Monday, February 14, 2011

More on the hacker war in the Internet

Here is some more background on the Internet war being battled around WikiLeaks. This is an Internet story with good guys, bad guys and no end of confusion regarding who is which.

Aaron burr of the security firm HBGary Federal has paid a high price for trying to expose the individuals behind Anonymous. so has HBGary Federal. I wrote last Friday about the The secret cyberwar being carried on by government and businesses to destroy Wikileaks. Aaron burr is the individual who named names behind Anonymous. This story shows what he was trying to do. The fact that he listed Glenn Greenwald as one of the Anonymous individuals certainly brings his methods and information into question.
Aaron Barr believed he had penetrated Anonymous. The loose hacker collective had been responsible for everything from anti-Scientology protests to pro-Wikileaks attacks on MasterCard and Visa, and the FBI was now after them. But matching their online identities to real-world names and locations proved daunting. Barr found a way to crack the code.

[...]

"At any given time there are probably no more than 20-40 people active, accept during hightened points of activity like Egypt and Tunisia where the numbers swell but mostly by trolls," he wrote in an internal e-mail. (All e-mails in this investigative report are provided verbatim, typos and all.) "Most of the people in the IRC channel are zombies to inflate the numbers."

The show was run by a couple of admins he identified as "Q," "Owen," and "CommanderX"—and Barr had used social media data and subterfuge to map those names to three real people, two in California and one in New York.

Near the end of January, Barr began publicizing his information, though without divulging the names of the Anonymous admins. When the Financial Times picked up the story and ran a piece on it on February 4, it wasn't long before Barr got what he wanted—contacts from the FBI, the Director of National Intelligence, and the US military. The FBI had been after Anonymous for some time, recently kicking in doors while executing 40 search warrants against group members.

[...]

When the liberal blog Daily Kos ran a story on Barr's work later that day, some Anonymous users commented on it. Barr sent out an e-mail to colleagues, and he was getting worked up: "They think all I know is their irc names!!!!! I know their real fing names. Karen [HBGary Federal's public relations head] I need u to help moderate me because I am getting angry. I am planning on releasing a few names of folks that were already arrested. This battle between us will help spur publicity anyway."

[...]

But within a day, Anonymous had managed to infiltrate HBGary Federal's website and take it down, replacing it with a pro-Anonymous message ("now the Anonymous hand is bitch-slapping you in the face.") Anonymous got into HBGary Federal's e-mail server, for which Barr was the admin, and compromised it, extracting over 40,000 e-mails and putting them up on The Pirate Bay, all after watching his communications for 30 hours, undetected. In an after-action IRC chat, Anonymous members bragged about how they had gone even further, deleting 1TB of HBGary backup data.

They even claimed to have wiped Barr's iPad remotely.

[...]

Were Barr's vaunted names even correct? Anonymous insisted repeatedly that they were not. As one admin put it in the IRC chat with Leavy, "Did you also know that aaron was peddling fake/wrong/false information leading to the potential arrest of innocent people?" The group then made that information public, claiming that it was all ridiculous.

Thanks to the leaked e-mails, we now have the full story of how Barr infiltrated Anonymous, used social media to compile his lists, and even resorted to attacks on the codebase of the Low Orbit Ion Cannon—and how others at his own company warned him about the pitfalls of his research.
This is a very modern story and it looks like it is not over yet.

Friday, February 11, 2011

The secret cyberwar being carried on by government and businesses to destroy Wikileaks.

I wasn't too sure what to make of the recent reports that Wikileaks has a bunch of documents about a major American bank that will demonstrate its corrupt activities. Apparently Bank of America is quite certain that the threat is real and that they are the target. It seems that there is a cyberwar going on right now. Glenn Greenwald, the human rights lawyer/blogger has written an interesting article at Salon that pulls together a lot of the story.
The story, first reported by The Tech Herald, has been been written about in numerous places (see Marcy Wheeler, Forbes, The Huffington Post, BoingBoing, Matt Yglesias, Reason, Tech Dirt, and others), so I'll provide just the summary.

Last week, Aaron Barr, a top executive at computer security firm HB Gary, boasted to the Financial Times that his firm had infiltrated and begun to expose Anonymous, the group of pro-WikiLeaks hackers that had launched cyber attacks on companies terminating services to the whistleblowing site (such as Paypal, MasterCard, Visa, Amazon and others). In retaliation, Anonymous hacked into the email accounts of HB Gary, published 50,000 of their emails online, and also hacked Barr's Twitter and other online accounts.

Among the emails that were published was a report prepared by HB Gary -- in conjunction with several other top online security firms, including Palantir Technologies -- on how to destroy WikiLeaks. The emails indicated the report was part of a proposal to be submitted to Bank of America through its outside law firm, Hunton & Williams. News reports have indicated that WikiLeaks is planning to publish highly incriminating documents showing possible corruption and fraud at that bank, and The New York Times detailed last month how seriously top bank officials are taking that threat. The NYT article described that the bank's "counterespionage work" against WikiLeaks entailed constant briefings for top executives on the whistle-blower site, along with the hiring of "several top law firms" and Booz Allen (the long-time firm of former Bush DNI Adm. Michael McConnell and numerous other top intelligence and defense officials). The report prepared by these firms was designed to be part of the Bank of America's highly funded anti-WikiLeaks campaign.

The leaked report suggested numerous ways to destroy WikiLeaks, some of them likely illegal -- including planting fake documents with the group and then attacking them when published; "creat[ing] concern over the security" of the site; "cyber attacks against the infrastructure to get data on document submitters"; and a "media campaign to push the radical and reckless nature of wikileaks activities." Many of those proposals were also featured prongs of a secret 2008 Pentagon plan to destroy WikiLeaks.

One section of the leaked report focused on attacking WikiLeaks' supporters and it featured a discussion of me. A graph purporting to be an "organizational chart" identified several other targets, including former New York Times reporter Jennifer 8 Lee, Guardian reporter James Ball, and Manning supporter David House. The report claimed I was "critical" to WikiLeaks' public support after its website was removed by Amazon and that "it is this level of support that needs to be disrupted"; absurdly speculated that "without the support of people like Glenn, WikiLeaks would fold"; and darkly suggested that "these are established professionals that have a liberal bent, but ultimately most of them if pushed will choose professional preservation over cause." As The Tech Herald noted, "earlier drafts of the proposal and an email from Aaron Barr used the word 'attacked' over 'disrupted' when discussing the level of support."

Then there is this interesting report from Think Progress.
ThinkProgress has learned that a law firm representing the U.S. Chamber of Commerce, the big business trade association representing ExxonMobil, AIG, and other major international corporations, is working with set of “private security” companies and lobbying firms to undermine their political opponents, including ThinkProgress, with a surreptitious sabotage campaign.

According to e-mails obtained by ThinkProgress, the Chamber hired the lobbying firm Hunton and Williams. Hunton And Williams’ attorney Richard Wyatt, who once represented Food Lion in its infamous lawsuit against ABC News, was hired by the Chamber in October of last year. To assist the Chamber, Wyatt and his associates, John Woods and Bob Quackenboss, solicited a set of private security firms — HB Gary Federal, Palantir, and Berico Technologies (collectively called Team Themis) — to develop tactics for damaging progressive groups and labor unions, in particular ThinkProgress, the labor coalition called Change to Win, the SEIU, US Chamber Watch, and StopTheChamber.com.

According to one document prepared by Team Themis, the campaign included an entrapment project. The proposal called for first creating a “false document, perhaps highlighting periodical financial information,” to give to a progressive group opposing the Chamber, and then to subsequently expose the document as a fake to undermine the credibility of the Chamber’s opponents. In addition, the group proposed creating a “fake insider persona” to “generate communications” with Change to Win.
Digby has weighed in with her take on the story. She focuses on Aaron Barr, an executive at the private security firm HB Gary, who obtained and published detailed information about political opponents’ children, spouses, and personal lives. When Anonymous, in defending WikiLeaks, learned what he had done they hacked into his accounts and published some 40,000 documents on his activities and on his family. After having done the same thing to other, Barr was very upset that someone might have named his family on line.

This is stuff that is not going away. We are going to see more of organizations like banks, governments and criminal organizations going after other people on the Internet. Think not? Here is more from Glenn Greenwald:
...it turns out that the firms involved here are large, legitimate and serious, and do substantial amounts of work for both the U.S. Government and the nation's largest private corporations (as but one example, see this email from a Stanford computer science student about Palantir). Moreover, these kinds of smear campaigns are far from unusual; in other leaked HB Gary emails, ThinkProgress discovered that similar proposals were prepared for the Chamber of Commerce to attack progressive groups and other activists (including ThinkProgress). And perhaps most disturbing of all, Hunton & Williams was recommended to Bank of America's General Counsel by the Justice Department -- meaning the U.S. Government is aiding Bank of America in its defense against/attacks on WikiLeaks.

That's why this should be taken seriously, despite how ignorant, trite and laughably shallow is the specific leaked anti-WikiLeaks proposal. As creepy and odious as this is, there's nothing unusual about these kinds of smear campaigns. The only unusual aspect here is that we happened to learn about it this time because of Anonymous' hacking. That a similar scheme was quickly discovered by ThinkProgress demonstrates how common this behavior is. The very idea of trying to threaten the careers of journalists and activists to punish and deter their advocacy is self-evidently pernicious; that it's being so freely and casually proposed to groups as powerful as the Bank of America, the Chamber of Commerce, and the DOJ-recommended Hunton & Williams demonstrates how common this is. These highly experienced firms included such proposals because they assumed those deep-pocket organizations would approve and it would make their hiring more likely.

But the real issue highlighted by this episode is just how lawless and unrestrained is the unified axis of government and corporate power. I've written many times about this issue -- the full-scale merger between public and private spheres -- because it's easily one of the most critical yet under-discussed political topics. Especially (though by no means only) in the worlds of the Surveillance and National Security State, the powers of the state have become largely privatized. There is very little separation between government power and corporate power. Those who wield the latter intrinsically wield the former. The revolving door between the highest levels of government and corporate offices rotates so fast and continuously that it has basically flown off its track and no longer provides even the minimal barrier it once did. It's not merely that corporate power is unrestrained; it's worse than that: corporations actively exploit the power of the state to further entrench and enhance their power.

That's what this anti-WikiLeaks campaign is generally: it's a concerted, unified effort between government and the most powerful entities in the private sector (Bank of America is the largest bank in the nation). The firms the Bank has hired (such as Booz Allen) are suffused with the highest level former defense and intelligence officials, while these other outside firms (including Hunton & Williams and Palantir) are extremely well-connected to the U.S. Government. The U.S. Government's obsession with destroying WikiLeaks has been well-documented. And because the U.S. Government is free to break the law without any constraints, oversight or accountability, so, too, are its "private partners" able to act lawlessly. That was the lesson of the Congressional vesting of full retroactive immunity on lawbreaking telecoms, of the refusal to prosecute any of the important Wall Street criminals who caused the 2008 financial crisis, and of the instinctive efforts of the political class to protect defrauding mortgage banks.

The exemption from the rule of law has been fully transferred from the highest level political elites to their counterparts in the private sector. "Law" is something used to restrain ordinary Americans and especially those who oppose this consortium of government and corporate power, but it manifestly does not apply to restrain these elites.