Cyber Intrusions, National Security Threat to Visa System

Primer: Listing a few demonstrating how vulnerable all segments of government, personal databases and corporations have forced lower standards of national security protections. Now with the threat to the State Department U.S. Visa system, terrorists and spies may exploit software security gaps. Anyone fixing this anywhere?

Cyber attack on Office of Personnel Management

Cyber attack of Obamacare

Cyber attack on hospital systems

Cyber attack on law firms

EXCLUSIVE: Security Gaps Found in Massive Visa Database

ABCNews: Cyber-defense experts found security gaps in a State Department system that could have allowed hackers to doctor visa applications or pilfer sensitive data from the half-billion records on file, according to several sources familiar with the matter –- though defenders of the agency downplayed the threat and said the vulnerabilities would be difficult to exploit.

Briefed to high-level officials across government, the discovery that visa-related records were potentially vulnerable to illicit changes sparked concern because foreign nations are relentlessly looking for ways to plant spies inside the United States, and terrorist groups like ISIS have expressed their desire to exploit the U.S. visa system, sources added.

“We are, and have been, working continuously … to detect and close any possible vulnerability,” State Department spokesman John Kirby said in a statement to ABC News.

After commissioning an internal review of its cyber-defenses several months ago, the State Department learned its Consular Consolidated Database –- the government’s so-called “backbone” for vetting travelers to and from the United States –- was at risk of being compromised, though no breach had been detected, according to sources in the State Department, on Capitol Hill and elsewhere.

As one of the world’s largest biometric databases –- covering almost anyone who has applied for a U.S. passport or visa in the past two decades -– the “CCD” holds such personal information as applicants’ photographs, fingerprints, Social Security or other identification numbers and even children’s schools.

Those records could be a treasure trove for criminals looking to steal victims’ identities or access private accounts. But “more dire” and “grave,” according to several sources, was the prospect of adversaries potentially altering records that help determine whether a visa or passport application is approved.

“Every visa decision we make is a national security decision,” a top State Department official, Michele Thoren Bond, told a recent House panel.

Last year alone, the State Department received -– and denied –- visa applications from more than 2,200 people with a “suspected connection to terrorism,” a senior Homeland Security Investigations official, Lev Kubiak, told lawmakers last month.

One official associated with State Department efforts to address the vulnerabilities said a “coordinated mitigation plan” has already “remediated” the visa-related gaps, and further steps continue with “appropriate [speed] and precision.”

“[We] view this issue in the lowest threat category,” the official said, noting that any online system suffers from vulnerabilities.

But speaking on the condition of anonymity, some government sources with insight into the matter were skeptical that CCD’s security gaps have actually been resolved.

“Vulnerabilities have not all been fixed,” and “there is no defined timeline for closing [them] out,” according to a congressional source informed of the matter.

“I know the vulnerabilities discovered deserve a pretty darn quick [remedy],” but it took senior State Department officials months to start addressing the key issues, warned another concerned government source.

Despite repeated requests for official responses by ABC News, Kirby and others were unwilling to say whether the vulnerabilities have been resolved or offer any further information about where efforts to patch them now stand.

PHOTO: U.S. Customs and Border Protection test new biometric technologies with face and iris cameras at the Otay Mesa border pedestrian crossing in San Diego, Calif. on Dec. 10, 2015.Richard Eaton/Demotix/Corbis
U.S. Customs and Border Protection test new biometric technologies with face and iris cameras at the Otay Mesa border pedestrian crossing in San Diego, Calif. on Dec. 10, 2015.more +

Nevertheless, many State Department officials questioned whether terrorists or other adversaries would have the capabilities to access and successfully exploit CCD data — even if the security gaps were still open.

CCD allows authorized users to submit notes and recommendations directly into applicants’ files. But to alter visa applications or other visa-related information, hackers would have to obtain “the right level of permissions” within the system -– no easy task, according to State Department officials.

There is also continuous oversight of the database and a series of other “fail-safes” built into the process, including rigorous in-person interviews and additional background checks, the officials said.

Kirby, the spokesman, described any recent security-related findings as a product of his department’s “routine monitoring and testing of systems” to “identify and remediate vulnerabilities before they can be exploited.”

PHOTO: The U.S. Department of State non-immigrant visa application website is seen in a screen grab made on March 30, 2016.ceac.state.gov
The U.S. Department of State non-immigrant visa application website is seen in a screen grab made on March 30, 2016.

State Department documents describe CCD as an “unclassified but sensitive system.” Connected to other federal agencies like the FBI, Department of Homeland Security and Defense Department, the database contains more than 290 million passport-related records, 184 million visa records and 25 million records on U.S. citizens overseas.

Without getting into specifics, sources said the vulnerabilities identified several months ago stem from aging “legacy” computer systems that comprise CCD.

“Because of the CCD’s importance to national security, ensuring its data integrity, availability, and confidentiality is vital,” the State Department’s inspector general warned in 2011.

The database’s software and infrastructure will be overhauled in the years ahead, according to the State Department.

Obama’s Next Gitmo Jailbreak

Obama to Release Ex-Fighter from Bin Laden’s  55th Arab Brigade From Gitmo

FreeBeacon:

The Pentagon plans to transfer roughly a dozen detainees from the Guantanamo Bay military prison to other nations, including an Islamic extremist who fought in Osama bin Laden’s 55th Arab Brigade.

The 055 Brigade (or 55th Arab Brigade) was an elite guerrilla organization sponsored and trained by Al Qaeda that was integrated into the Taliban army between 1995 and 2001.

File:ISN 00190, Sharif Fatham al-Mishad's Guantanamo detainee assessment.pdf

U.S. officials confirmed to the Washington Post Wednesday that Tarik Ba Odah, a Yemeni who has been on a hunger strike for more than nine years, would be among those resettled within the next few weeks in at least two cooperating countries.

The military has force-fed 37-year-old Ba Odah through a nasal tube since he began his fast in 2007, Reuters reported. In December, his body weight had dropped by half, falling from 148 pounds to 75.

The U.S. Department of Defense file for the detainee, published by the New York Times, provides insight into his ties to Osama bin Laden.

“[Ba Odah] is assessed to be an Islamic extremist and possible member of al-Qaida. Detainee served as a fighter in Osama bin Laden’s 55th Arab Brigade, and participated in hostilities against U.S. and coalition forces in [bin Laden’s] Tora Bora Mountain complex where he probably manned a mortar position. Detainee is reported as being an important man with close ties to senior al-Quaida members including [bin Laden],”the file reads.

Ba Odah also confirmed to U.S. officials that he received militant training and advanced artillery training from al Qaeda, according to the report.

When officials assessed Ba Odah in 2008 for continued detention, the Department of Defense classified him as a high risk threat to the U.S. and its allies.

He was also classified as a high-risk threat from a detention perspective for his noncompliance and hostility toward Guantanamo guards. As of January 2008, he had received 81 reports of disciplinary infraction. Incidents included Ba Odah spraying a mix of feces, urine, and water out of his cell and spitting on a guard, according to the file.

In 2009, Ba Odah was clear for transfer under certain security conditions, but Congress has since banned repatriations to Yemen.

The officials declined to identify the countries that agreed to resettle the prisoners.

Guantanamo currently holds 91 detainees. Thirty-seven prisoners have been approved for repatriation or resettlement.

President Obama vowed to close the military prison after taking office in 2009 and has since transferred, resettled, or repatriated 147 detainees. Obama’s plan to close the prison, which he recently delivered to Congress, would involve moving dozens of prisoners not approved for transfer to other countries to the United States.

Current law bars the transfer of Guantanamo prisoners to detention facilities inside the U.S., but Obama has threatened to circumvent the congressional ban through executive action.

****

In part from FNC: The next round of Gitmo transfers will begin this weekend with two detainees going an undisclosed country in Africa.

In January, the Pentagon conducted a bulk transfer of 10 detainees at once, the largest transfer from the U.S. Naval Station at Guantanamo, Cuba to date.

This next transfer of Gitmo detainees can’t happen all at once because the Pentagon is required by law to notify Congress 30-days before any transfers.

Capitol Hill sources tell Fox News that period has not elapsed yet for all the transfers.

The first notification went to Congress in early March and the second one in the middle of this month.

The president’s critics in Congress point out that in addition to keeping terrorists from returning to the fight, they also demand a plan for handling ISIS detainees, now that a 200-man special operations task force fighting ISIS and recently killed the group’s second in command last week.

The U.S. military has no plans to hold captured Islamic State operatives for more than a month before turning them over to the Iraqi government, a spokesman for the U.S.-led coalition based in Baghdad told reporters recently.

“Fourteen to 30 days is a ballpark figure, but even that is not really completely nailed down,” said Col. Steve Warren, a U.S. military spokesman based in Baghdad. “There isn’t a hard definition of short-term.”

Earlier this month, Pentagon Press Secretary Peter Cook also made clear that the policy for holding operatives is, at best, evolving. He said they would be handled on a “case-by-case” basis over a “short-term” period.

The lack of a well-defined policy for handling captured ISIS terrorists is in turn raising concerns on Capitol Hill.

“The law requires a comprehensive detainee policy,” a congressional aide said. “By definition, ‘we’ll figure it out if we ever capture anyone’ is not a comprehensive policy. “

Warren said that two airstrikes against ISIS chemical weapons facilities were conducted following a recent mission carried out by a US special ops assault force capturing an ISIS operative linked to its chemical weapons program.

*****

In part from Time: While hundreds of inexperienced Pakistani, Sudanese and other Muslim faithful enter Afghanistan every week to join the Taliban army, the estimated 1,000 Arabs of Brigade 055 have been in the country for years. Trained in bin Laden’s terror camps, they are the Taliban’s most dedicated and highly skilled soldiers–the elite of the roughly 5,000 al-Qaeda fighters on the ground.

About 100 of the very best serve as bin Laden’s personal security detail. Most are veterans of battles against regimes in their homelands or the mujahedin war against the Soviets in Afghanistan. Primarily led by Egyptian and Saudi revolutionaries, Brigade 055 (the unit began as a Soviet-era Afghan-government outfit) also includes volunteers from Chechnya, Pakistan, Bosnia, China and Uzbekistan.

Like most al-Qaeda terrorists, brigade members are fervently committed to bin Laden’s cause, and will literally fight to the death. “They give no quarter, and they expect no quarter,” says an official at the Pentagon’s Defense Intelligence Agency. At the moment, they’re helping out at key strategic northern cities like Mazar-i-Sharif, Taloqan and Jalalabad –and, not surprisingly, becoming a major target of U.S. firepower. More here.

 

ISIS Moving Prisoners for an Offensive Operation?

ISIS moving prisoners to Syria border town: monitor

The Syrian Observatory for Human Rights reported that prisoners were set to work digging trenches around Jarabulus.

BEIRUT – ISIS has begun to transfer its prisoners to a town along Syria’s border with Turkey in anticipation of a Kurdish-led offensive on the area, according to a monitoring NGO tracking developments in the country.

The Syrian Observatory for Human Rights reported Thursday that the jihadist group’s Hisbah religious police was moving both civilian detainees and imprisoned fighters from its own ranks and other factions to Jarabulus, a town lying on the Euphrates River across from Kurdish-controlled front-lines.

The NGO cited activists in Raqqa as saying that the prisoners were being moved from detention facilities from the city, which serves as ISIS’s de-facto capital, as well as from Al-Bab and Manbij, two towns south of Jarubulus in a stretch of territory that Turkey does not want Kurdish-forces expanding into.

“Sources confirmed that the transfer of prisoners was done in conjunction with the spread of [reports] that [the Kurdish-led] Syrian Democratic Forces (SDF) are preparing for an attack on the Jarabulus district and other areas controlled by ISIS in the northeastern countryside of Aleppo,” the SOHR said.

The report added that the transferred prisoners were pressed into manual labor to set up defensive measures around Jarabulus, including digging trenches and erecting earth mounds.

The SOHR’s report comes days after Turkey’s Turkey’s state-run Anadolu news agency claimed that the SDF was preparing for an assault on Manbij, a town 25 kilometers south of Jarabulus.

“Officials in the party have announced over their social media accounts the ‘Greater Manbij Operation’ to seize the town,” the news agency quoted sources as saying.

Kurdish outlets affiliated with local Kurdish forces have yet to make any mention of the purported offensive, however reports indicate the US-led coalition bombarding ISIS has stepped up its airstrikes around Manbij.

Ankara has repeatedly warned that it will not allow Kurdish forces to cross westward across the Euphrates—either toward Manbij or Jarabulus—and continue to expand its presence along Turkey’s border with Syria.

Turkey considers the Kurdish People’s Protection Units (YPG)—which are affiliated with the Turkish Kurdistan Workers’ Party (PKK)—to be a terrorist organization.

Turkish daily Hurriyet reported Thursday Ankara was “closely following reports of a planned operation” by the SDF to take Manbij, adding that the Turkish military was ready to launch the “required response.”

In past months, the Turkish Armed Forces has shelled Kurdish units attempting to cross the Euphrates River to conduct raids on ISIS forces positioned around Jarabulus, in effect enforcing a “red line” between the YPG and Ankara’s planned “safe zone.”

*** Meanwhile:

‘ISIS is planning a major attack in Israel’

While Islamic State (ISIS) attacks in Europe and massacres in Syria and Iraq have dominated the headlines in recent months, the radical Islamic terror group may be shifting its focus, placing a greater emphasis on Israel and the United States.

This Sunday, a Gazan Salafist official and ISIS affiliate Abu al-Ayna al-Ansari spoke with an American journalist, Aaron Klein, about the terror organization’s capabilities and future plans.

Al-Ansari, who is believed to have close ties to ISIS, emphasized that the terror organization would be focusing on Israel and the US, and viewed those two nations as its primary enemies in the pursuit of an Islamic caliphate.

“Israel and the United States are at the top of the list of the targets of the Islamic State,” Al-Ansari said on the Aaron Klein Investigative Radio show. “The Islamic State educates its people that Israel and the United States are the leaders of the infidels and we believe that Israel should be disappeared [sic].”

Perhaps most disturbing, however, are reports that ISIS is building an extensive terror infrastructure along Israel’s southern border. Taking advantage of the minimal Egyptian presence in the Sinai, Wilayat Sinai (Sinai Province), an affiliate of ISIS, has expanded its capabilities for a potential attack on Israel.

According to Al-Ansari, ISIS is already planning its first major attack on Israeli soil. A major ISIS attack on Israel, he claims, is only a matter of time.

“I can confirm that it is only a question of time when there will be a big operation in Eilat and in the south of Israel. The Wilayat Sinai will be the ones responsible for the confrontation with Israel.”

Speaking with Israel Army Radio, Yehuda Cohen, the commander of the IDF’s Sagi Brigade which secures the border with Egypt, admitted that such an attack was indeed likely.

“In the end it must be remembered this organization was formed by terrorists that dream of a terror attack against Israel, and it will come. It’s clear that there will be a terror attack against Israel, I believe that it will happen during my tenure,” Cohen said.

While Israel has hitherto been spared the horrors ISIS has inflicted on Syria and Iraq, ISIS activity against Israel has been on the rise in recent months. In February a Sudanese national, allegedly inspired by ISIS, stabbed and wounded an Israeli soldier, in what is believed to be the first successful ISIS attack in Israel.

Earlier in March a suicide bomber affiliated with ISIS bombed a popular shopping center in Istanbul, murdering three Israelis and wounding dozens after tracking the Israeli tourists from their hotel.

Just this Monday two Arab residents of Jerusalem were charged with planning bombing attacks on Jerusalem for ISIS – the latest in a string of small ISIS cells broken up by Israeli security forces while planning attacks.

Turkey’s President Visit to DC Caused Major Chaos

Protests were to support Kurdistan, as Turkey under Erdogan has been killing Kurds.

Chaos Outside of Turkish President Erdogan’s Washington Speech

Chaos Outside of Turkish President Erdogan’s Washington Speech

A planned speech by the controversial Turkish leader Recep Tayyip Erdogan descended into violence and chaos Thursday, with one journalist physically removed from the event site by Turkish security personnel, another kicked by a guard, and a third — a woman — thrown to the sidewalk in front of a Washington think tank where he was to speak.

A small group of protesters gathered across the street from the Brookings Institute near Dupont Circle in Washington, with one holding a large sign reading “Erdogan: War Criminal On The Loose,” while another used a megaphone to chant that he was a “baby-killer.”

When the protesters tried to cross the street, Washington police officers blocked traffic and physically separated them from Turkish personnel. A Secret Service agent standing nearby told a colleague that “the situation is a bit out of control.”

Later, a shoving match between what appeared to be a Brookings Institute worker and Turkish security broke out. “I am in charge of this building,” the apparent Brookings employee shouted as the two tangled. A Foreign Policy reporter and others holding cameras outside the event were also scolded by Turkish security.  One cameraman was chased across the street by Turkish guards.

Local Washington D.C. police officers were forced time and again to get between Erdogan’s security forces and journalists and protesters. At one point, an officer placed himself between one of Erdogan’s security guards and a cameraman he was moving to confront, while another angrily confronted several Turkish security guards in the middle of the street, telling them, “you’re part of the problem, you guys need to control yourselves and let these people protest.” Another Turkish security official pulled his colleague away after he began arguing with the officer. Other members of Ergodan’s team stood in front of the Brookings building, motioning for the protesters to come closer, and making obscene gestures.

There were also confrontations between Turkish security and D.C. police. The Turkish officials wanted police to remove protesters, and the cops refused.

In a statement late Thursday, Brooking’s spokesperson Gail Chalef said that the think tank did its “best to ensure that journalists and other guests who had registered in advance for the event were able to enter.” She added that she believes all journalists who registered were able to attend.

At one point, just before Erdogan arrived, the protest briefly turned violent.

***

As he arrived, law enforcement arranged a wall of large vehicles in front of Brookings, presumably to block anti-Erdogan protesters across the street.

***

Internet Provider Fees Going up to Subsidize the Poor?

More government freebies and paid for without your consent via hidden communications charges in those bills in your mailbox. No legislative measures for this? Sigh….

Commission voted 3-2 along party lines to approve Democrats’ plan:

WSJ: The expansion of the Lifeline subsidy, which has been in the works for several years, is intended to help lower-income people who have trouble affording broadband service on their own. Many experts worry that a digital divide is emerging between lower-income and higher-income households, at a time when Internet service has become important for everything from school work to job searches to veterans benefits.

Commissioners Mignon Clyburn and Jessica Rosenworcel cited examples of students who lurk on sidewalks outside coffee shops or schools to take advantage of Wi-Fi hot spots to complete schoolwork assignments.

FCC approves Internet subsidies for the poor

TheHill: Millions of poor Americans will be eligible for federal subsidies to help pay the cost of Internet service after new regulations were approved in a whirlwind Federal Communications Commission (FCC) meeting on Thursday.

The FCC voted to expand its 30-year-old Lifeline program, which has offered the monthly $9.25 subsidy for voice-only phone service.

The three Democratic commissioners approved the proposal over opposition from the two Republicans, who have concerns about the program’s budget.

The vote was delayed for more than three hours as Republicans accused FCC Chairman Tom Wheeler of scuttling a late-night compromise to bring them on board.

They said they had a deal with Democratic commissioner Mignon Clyburn before it fell apart under pressure from the chairman, members of Congress and outside groups.

“I must address the elephant in the room: the delay in the meeting and rumors about a proposed cap on the Lifeline program,” Clyburn said at the meeting. She said she engaged in negotiations with Republicans but ended up backing out because the deal did not “fully achieve my vision.”

Clyburn told reporters said she is five feet two inches tall but “not easily bullied.” Wheeler gave a one word response to charges that he bullied his fellow Democrat: “Balderdash.”

The expansion is a major win for advocates who increasingly see Internet access as a necessity for education, finding a job or simply communicating. They point to the 15 percent of Americans, concentrated in poor and rural communities, who do not use the Internet.

Families will only be able to receive one subsidy per household, which they can put toward paying for home Internet, phone or smartphone service — or a combination of the three under the program. Many current participants receive free basic cell service because the $9.25 subsidy covers the entire cost, but they would have to cover the remaining cost of a broadband connection.

The mobile industry waged a late lobbying campaign to get the FCC to lower some of its minimum standards of service, which cover the Internet speed, data allowance and minutes that companies must offer to participate. They also warned against completely phasing out voice-only cellphone service. They won some concessions, including reducing the number of minutes voice-only services will have to offer starting in December.

The rules approved Thursday would set up a single national database to allow phone and Internet providers to verify whether individuals are eligible by sharing information from other lower-income programs like Social Security, Medicaid and food subsidies.

One of the priorities was removing the burden on companies to determine whether a person is eligible for a subsidy. Some said that structure encouraged abuse and put companies in the uncomfortable position of holding sensitive customer information, opening them up to extra security and liability.

“The fox is no longer guarding the henhouse,” Wheeler said.

Lifeline currently has about 13 million subscribers, only a fraction of the 40 million who are eligible. The vote Thursday imposed a budget of $2.25 billion per year. The funds come from fees imposed by the phone companies.

The FCC expects the overhaul to increase participation, and it has projected that about 7 million more people could enroll before hitting the budget ceiling.