Government whistleblowers are increasingly being charged under laws such as the Espionage Act, but they aren’t spies.
They’re ordinary Americans and, like most of us, they carry smartphones that automatically get backed up to the cloud. When they want to talk to someone, they send them a text or call them on the phone. They use Gmail and share memes and talk politics on Facebook. Sometimes they even log in to these accounts from their work computers.
Then, during the course of their work, they see something disturbing. Maybe it’s that the government often has no idea if the people it kills in drone strikes are civilians. Or that the NSA witnessed a cyberattack against local election officials in 2016 that U.S. intelligence believes was orchestrated by Russia, even though the president is always on TV saying the opposite. Or that the FBI uses hidden loopholes to bypass its own rules against infiltrating political and religious groups. Or that Donald Trump’s associates are implicated in sketchy financial transactions.
So they search government databases for more information and maybe print some of the documents they find. They search for related information using Google. Maybe they even send a text message to a friend about how insane this is while they consider possible next steps. Should they contact a journalist? They look up the tips pages of news organizations they like and start researching how to use Tor Browser. All of this happens before they’ve reached out to a journalist for the first time.
Read More
Zero Hedge
The United States is no longer supplying its enemies only with
conventional weapons – that list now also includes cyberweapons. While
Baltimore has been struggling with an aggressive cyber-attack over the
last three weeks, previously profiled here , it has now been revealed that a key component of the malware used by cyber-criminals was actually developed just a short drive from Baltimore - at the NSA, according to the New York Times.
The tool used - called EternalBlue – has been used by hackers in
North Korea, Russia and China to "cut a path of destruction around the
world", and resulted in billions of dollars in damages.
Now, it has come full circle and is back in the US, wreaking havoc just miles from Washington. In fact, security
experts say that attacks using EternalBlue have soared and
cyber-criminals are honing in on vulnerable towns and cities, using it
to paralyze governments. The NSA's connection to the attacks
had previously not been reported and the NSA hasn’t commented about it
since an unidentified group leaked the weapon online in April 2017.
The NSA and the FBI still don’t know whether or not it was leaked by foreign spies or US insiders.
The leak has been referred to as “the most destructive and costly
N.S.A. breach in history,” by Thomas Rid, a cybersecurity expert at
Johns Hopkins University. He continued: “The government has refused to
take responsibility, or even to answer the most basic questions.
Congressional oversight appears to be failing. The American people
deserve an answer.”
An answer that we're sure they won't get.
Commenting on the leak in April 2017, Edward Snowden said that the "NSA just lost control of its Top Secret arsenal of digital weapons; hackers leaked it."
Read more
Martin Giles
MIT Tech Review
The rogue code can disable safety
systems designed to prevent catastrophic industrial accidents. It was
discovered in the Middle East, but the hackers behind it are now
targeting companies in North America and other parts of the world, too.
s an experienced cyber first responder, Julian Gutmanis had been
called plenty of times before to help companies deal with the fallout
from cyberattacks. But when the Australian security consultant was
summoned to a petrochemical plant in Saudi Arabia in the summer of 2017,
what he found made his blood run cold.
The hackers had deployed malicious software, or malware, that let
them take over the plant’s safety instrumented systems. These physical
controllers and their associated software are the last line of defense
against life-threatening disasters. They are supposed to kick in if they
detect dangerous conditions, returning processes to safe levels or
shutting them down altogether by triggering things like shutoff valves
and pressure-release mechanisms.
The malware made it possible to take over these systems remotely.
Had the intruders disabled or tampered with them, and then used other
software to make equipment at the plant malfunction, the consequences
could have been catastrophic. Fortunately, a flaw in the code gave the
hackers away before they could do any harm. It triggered a response from
a safety system in June 2017, which brought the plant to a halt. Then
in August, several more systems were tripped, causing another shutdown.
The first outage was mistakenly attributed to a mechanical glitch;
after the second, the plant's owners called in investigators. The
sleuths found the malware, which has since been dubbed “Triton” (or
sometimes “Trisis”) for the Triconex safety controller model that it
targeted, which is made by Schneider Electric, a French company.
In a worst-case scenario, the rogue code could have led to the
release of toxic hydrogen sulfide gas or caused explosions, putting
lives at risk both at the facility and in the surrounding area.
Gutmanis recalls that dealing with the malware at the petrochemical
plant, which had been restarted after the second incident, was a
nerve-racking experience. “We knew that we couldn’t rely on the
integrity of the safety systems,” he says. “It was about as bad as it
could get.”
In attacking the plant, the hackers crossed a terrifying Rubicon.
This was the first time the cybersecurity world had seen code
deliberately designed to put lives at risk. Safety instrumented systems
aren’t just found in petrochemical plants; they’re also the last line of
defense in everything from transportation systems to water treatment
facilities to nuclear power stations.
Triton’s discovery raises questions about how the hackers were able
to get into these critical systems. It also comes at a time when
industrial facilities are embedding connectivity in all kinds of
equipment—a phenomenon known as the industrial internet of things. This
connectivity lets workers remotely monitor equipment and rapidly gather
data so they can make operations more efficient, but it also gives
hackers more potential targets.
Read more