Turkey Hacks Library of Congress During Coup

Primer:

In part from Time: Kerry raised the question of Turkey’s NATO membership, suggesting that anti-democratic behavior by Erdogan could imperil the country’s place in the alliance. “NATO also has a requirement with respect to democracy,” Kerry said, and added said NATO would “measure” Turkey’s actions in days to come. “Obviously, a lot of people have been arrested and arrested very quickly,” Kerry said. “The level of vigilance and scrutiny is obviously going to be significant in the days ahead. Hopefully we can work in a constructive way that prevents a backsliding.”

Turkey’s membership in the NATO alliance is a matter of major strategic importance to the U.S., and talk of the country being ousted caught some experts by surprise in the U.S. Amb. Bryza of the Atlantic Council said Kerry’s comments were being taken as threats in Turkey, and that it was an “extreme misinterpretation that we would kick them out of NATO.” Much more detail here.

Turkish hackers claim credit for Library of Congress attack

FCW: A hacking group called the Turk Hack Team is taking credit for a shutdown of the Library of Congress website and hosted systems including Congress.gov, the Copyright Office, Congressional Research Service and other sites.

The group claimed credit on an online message board where users go for updates on the availability of websites.

The attack was launched July 17, in the midst of Turkey’s response to the military coup targeting the elected government of President Recep Tayyip Erdogan. Prominent Turkish officials have accused the U.S. of fomenting the coup; Secretary of State John Kerry issued a stern denial of such accusations.

The Turk Hack Team is not considered at the level of a nation-state sponsored group or an advanced persistent threat, former U.S. CERT director Ann Barron-DiCamillo told FCW. They’re more of a “middle-tier, hacktivist” type group, she said. They’ve gone after targets for perceived slights to Turkey’s honor in the past, including an April 2015 hack on the Vatican website made in response to comments from Pope Francis characterizing the 1915 massacres of Turkish Armenians as a genocide.

The group has not gone after U.S. targets in the past, but Baron-DiCamillo, currently partner and CTO at Strategic Cyber Ventures, said U.S. officials would likely be on the lookout for more hacktivist activity emanating from Turkey. “This is the first kind of visible activity generated post-coup, but it doesn’t mean it’s going to be the last,” she said.

Library of Congress CIO Bernard Barton said on July 20 that the attack had been successfully thwarted.

“This was a massive and sophisticated DNS assault, employing multiple forms of attack, adapting and changing on the fly,” he wrote in a blog post. “We’ve turned over key evidence to the appropriate authorities who will investigate and hopefully bring the instigators of this assault to justice.”

 

 

Congress is not covered by the Federal Information Security Management Act and is not required to report cyber incidents to the Department of Homeland Security.

Spokesperson Gayle Osterberg told FCW that the Library of Congress reports all cyber-related criminal activity to the FBI.

DHS is aware of the incident but is not involved in the investigation or mitigation of the attacks, according to an agency source.

DDOS attacks can be expensive to deal with, requiring network operators to obtain specialized routing services from their internet service providers. They can also potentially front for other attacks, or test systems to see what kind of defenses are in place.

Related reading: Turkey blocks access to WikiLeaks after ruling party email dump

Mostly, Barron-DiCamillo said, they are “distracting, causing pain to both users and customers, but not impacting back-end systems and more critical data.”

It is possible the hackers imagined that the Congress.gov and LOC.gov domains represented a more critical target than they actually are. Congress.gov is mostly a public-facing information warehouse that is not integral to the legislative function of the House and Senate. Most of the complaints about the site being down came from librarians and researchers looking to execute catalog searches.

The outage also affected the Congressional Research Service, the in-house think tank for Congress. CRS reports, available only to members and staff, are not published elsewhere except on an ad hoc basis legislators and public interest groups that obtain the odd document. A bill introduced by Rep. Mike Quigley (D-Ill.) just days before the hack would open up CRS reports to the public, and have the effect of creating a backup site for the material on the Government Publishing Office website.

Obama/DoJ Allowing Foreigners to Serve Warrants

This sounds like selective investigations, prosecutions and collaborated witch hunts which all add up to an offshore shadow NSA and new type of Interpol. Is this something else that also will be under the purview of the United Nations? Hello Google?

 Photo: Leaksource

 Photo: Security Affairs

WSJ: The Obama administration is working on a series of agreements with foreign governments that would allow them for the first time to serve U.S. technology companies with warrants for email searches and wiretaps—a move that is already stirring debates over privacy, security, crime and terrorism.

Brad Wiegmann, a senior official at the Justice Department, discussed the administration’s efforts during a public forum on Friday at a congressional office building in Washington, D.C. The first such agreement is being assembled with the U.K., he said.

Word of the plans came one day after a federal appeals court ruled that federal warrants couldn’t be used to search data held overseas by Microsoft Corp. MSFT -0.07 % , dealing the agency a major legal defeat.

The court’s decision in favor of Microsoft could prove to be a major barrier to the Obama administration’s proposed new rules to share data with other nations in criminal and terrorism probes, which would be sharply at odds with the ruling. It might lead some companies to reconfigure their networks to route customer data away from the U.S., putting it out of the reach of federal investigators if the administration’s plan fails.

The Justice Department has indicated it is considering appealing the Microsoft ruling to the Supreme Court.

Meanwhile, Justice Department officials are pressing ahead with their own plan for cross-border data searches.

Under the proposed agreements described by Mr. Wiegmann, foreign investigators would be able to serve a warrant directly on a U.S. firm to see a suspect’s stored emails or intercept their messages in real time, as long as the surveillance didn’t involve U.S. citizens or residents.

Such deals would also give U.S. investigators reciprocal authority to search data in other countries.

“They wouldn’t be going to the U.S. government, they’d be going directly to the providers,’’ said Mr. Wiegmann. Any such arrangement would require that Congress pass new legislation, and lawmakers have been slow to update electronic privacy laws.

That U.K. agreement, which must be approved by the legislatures of both countries, could become a template for similar deals with other countries, U.S. officials said.

Mr. Wiegmann said the U.S. would strike such deals only with nations that have clear civil liberties protections to ensure that the search orders aren’t abused.

“These agreements will not be for everyone. There will be countries that don’t meet the standards,’’ he said.

Greg Nojeim, a privacy advocate at the Center for Democracy and Technology, criticized the plan. He said it would be “swapping out the U.S. law for foreign law’’ and argued that U.K. search warrants have less stringent judicial protections than U.S. law.

British diplomat Kevin Adams disputed that, saying the proposal calls for careful judicial scrutiny of such warrants. Privacy concerns over creating new legal authorities are overblown, he added.

“What is really unprecedented is that law enforcement is not able to access the data they need,’’ Mr. Adams said. The ability to monitor a suspect’s communications in real time “is really an absolutely vital tool to protect the public.’’

While Thursday’s court decision represented a victory for Microsoft, which strives to keep data physically near its customers, it may not be viewed as a positive development for all internet companies, said University of Kentucky law professor Andrew Woods. Yahoo Inc., YHOO -0.63 % Facebook Inc. FB -0.37 % and Alphabet Inc. GOOGL -0.02 % ’s Google operate more centralized systems. They didn’t file briefs in support of Microsoft’s position in the case, he noted.

Mr. Woods warned that increased localization of data could have the unintended consequence of encouraging governments to become more intrusive.

“If you erect barriers needlessly to states getting data in which they have a legitimate interest, you make this problem worse,’’ he said. “You increase the pressure that states feel to introduce backdoors into encryption.”

Microsoft President and Chief Legal Officer Brad Smith said the company shares concerns about the “unintended consequences” of excessive data localization requirements.

“But rather than worry about the problem, we should simply solve it” through legislation, Mr. Smith said. Microsoft supports the proposed International Communications Privacy Act. That legislation would, among other provisions, create a framework for law enforcement to obtain data from U.S. citizens, regardless of where the person or data was located.

Companies and governments generally agree that the current legal framework for cross-border data searches is far too slow and cumbersome. Though major tech firms don’t always agree on the particular changes they would like to see, the industry has long sought to get clearer rules from the U.S. and other governments about what their legal obligations are.

A coalition of the country’s largest tech companies, including Microsoft, Facebook and Google, created a group called Reform Government Surveillance that is pushing for updating data-protection laws. The group has said it was “encouraged by discussions between the U.S. and the U.K.”

Thursday’s ruling could lead some Microsoft rivals that offer email, document storage, and other data storage services, but which haven’t designed systems to store data locally, to alter their networks, said Michael Overly, a technology lawyer at Foley & Lardner in Los Angeles.

Google, for example, stores user data across data centers around the world, with attention on efficiency and security rather than where the data is physically stored. A given email message, for instance, may be stored in several data centers far from the user’s location, and an attachment to the message could be stored in several other data centers. The locations of the message, the attachment and copies of the files may change from day to day.

“[Internet companies] themselves can’t tell where the data is minute from minute because it’s moving dynamically,” Mr. Overly said.

The ruling could encourage tech companies to redesign their systems so that the data, as it courses through networks, never hits America servers.

A person familiar with Google’s networks said that such a move wouldn’t be easy for the company.

Terror at the Olympics in Brazil?

Brazil police arrest 10 men pleading ISIS allegiance, search for two more

WashingtonTimes: RIO DE JANEIRO (AP)— Federal police in Brazil have ordered the detention of 12 people who allegedly pledged allegiance to the Islamic State group via social media.

Justice Minister Alexandre de Moraes told journalists in Brasilia on Thursday that 10 had been arrested and two more were being sought.

Moraes says police acted because the group had been discussing the use of weapons and guerrilla tactics to potentially launch an attack during the Olympics, which begin Aug. 5.

The arrests were made in the southern states of Sao Paulo and Parana. Moraes says there were no specific targets for attack.

Last week, Brazil’s interim government’s top military aide said the concerns with terrorism had “reached a higher level” after the attacks of six days ago in Nice, France.

Previously, this website predicted these conditions at the Olympics.

****

In part from the NYT’s: The Federal Police said in a statement that the suspects belonged to a group called the Defenders of Sharia. Agents from an antiterrorism unit are investigating the group’s activities in the several states, including Rio de Janeiro, where the Games will take place.

In part from the NewYorkDailyNews: The arrests were made in 10 different states, including Sao Paulo and Parana in the southern part of the country, and it was not clear whether the suspects knew each other beyond their online contacts. Moraes said there were no specific targets for an attack.

Moraes said they had all been “baptized” as Islamic State sympathizers online and that none had actually traveled to Syria or Iraq, the group’s stronghold, or received any training. Several were allegedly trying to secure financing from the group, known by the acronym ISIS.

The justice minister added that one of the suspects communicated with a Brazilian store in an alleged attempt to by an AK-47  assault rifle, apparently the most concrete action taken toward a possible attack.

Last week, Brazil’s interim government’s top military aide said the concerns with terrorism had “reached a higher level” after the attacks of six days ago in Nice, France.

More Hidden News/Facts on Iran

Here’s Hezbollah’s game-changing secret drone base

For years, the Lebanese Shi’ite militant organization Hezbollah has incorporated unmanned aerial vehicles into their arsenal, developing perhaps the most sophisticated aerial capabilities of any non-state armed group on earth.

IHS Jane’s has now used Google Maps to locate their airbase in northern Lebanon, according to an analysis published on April 23rd.

Hezbollah is arguably the Arab world’s most capable military force. The group is a direct proxy of the revolutionary regime in Iran, which sends the group perhaps as much as $350 million in aid a year, according to Matthew Levitt’s Hezbollah: The Global Footprint of Lebanon’s Party of God.

Hezbollah has an estimated 100,000 rockets — an arsenal that likely includes Russian-made precision-guided missiles. Its infusion of fighters is largely responsible for the survival of Syria’s Assad regime after four years of war against ISIS, Al Qaeda, and secular armed groups. Hezbollah has operated cells and smuggling networks on every continent, and it’s the only Arab military force that can plausibly claim a battlefield victory against Israel.

The airbase is alarming evidence of the group’s vaunted operational capabilities — as well as the depth of its relationship with Tehran.

The airstrip includes a 2200-foot unpaved runway, several outbuildings, and an antenna that “could potentially be used to extend the range of a UAV ground control station.” (It can be found at 34.3109624, 36.3492857 on Google Maps).

Hezbollah airfield Business Insider via Google Maps

It’s located a few miles south of the town of Hermel in northern Lebanon, and about 10 miles to the west of the border wt ih Syria.

As the Jane’s report notes, the airstrip is too short to accommodate most manned aircraft, while its unpaved surface and mountainous surrounding terrain make it largely off-limits to planes that technically capable of landing on a runway of its length. That means there’s a strong possibility it was “built for Iranian-made UAVs, including the Ababil-3, which has been employed over Syria by forces allied to the Syrian regime, and possibly the newer and larger Shahed-129.”

The Ababil-3 is a small reconnaissance drone with limited range and flight endurance; it’s also been deployed by the Sudanese armed forces in the former Iranian ally’s various civil conflicts. But as The Aviationist notes, the Shahed-129 is superficially similar in design to the US’s Reaper and Predator platforms, and Iranian military officials claim that the drone can carry as many as 8 Sadid missiles.’  Read more here from BusinessInsider

Hezbollah airstrip Google Maps

Yes there is more to know about Iran, that country which is designated by the United States as the largest state sponsor of terror, and the one that the Obama White House normalized relations with and a country forced upon the global stage for economic development. This is the country that can build, is building a nuclear program that is the precursor to nuclear weapons.

Iran Deploys Hezbollah-Trained Afghan Sniper Brigade in Syria

DefenseNews: TEL AVIV — An Israeli intelligence source confirmed Monday that a new unit of Afghan snipers trained by Lebanese-based Hezbollah and financed by Iran is now operating beyond its northern border on behalf of Syrian President Bashar Assad.

In a July 18 interview, the source said the sniper unit – part of the Afghan Fatemiyoun Brigade – is one of several additional groups of special forces that are being deployed in the fight against the Islamic State organization, also known by its Arabic acronym Da’esh.

“These Afghan Shias are battle-hardened and focused at the moment on fighting Da’esh. But we’re obviously following with interest any introduction of new forces and capabilities in that theater that may turn their attention to us when the time is right for them,” said the Israeli analyst, who insisted on anonymity because the interview did not take place through normal authorization channels.

The Israeli source validated reports earlier this month from Iran’s Tasnim, a news agency affiliated with the Iranian Revolutionary Guard Corps (IRCG), that a new group of snipers specializing in camouflage and concealment tactics was now operational in Syria.

According to a July 9 report, Tasnim acknowledged that the unit was part of the Afghan Fatemiyoun Brigade trained by Hezbollah, which operates in Syria under the command of the IRGC.

Another Tasnim report from July 12, translated by Amir Toumaj, a research analyst at the Foundation for Defense of Democracies in an account published by the online Long War Journal, noted that “Hundreds of special Fatemiyoun snipers have been deployed to defend sacred shrines across Syria and have joined Fatemiyoun combat units.”

According to Toumaj’s translation, “additional groups of special Afghan forces with advanced training in combat, commando capabilities, guerilla warfare, anti-armor missiles, shoulder-launched missiles, etc. are expected to join” Fatemiyoun ranks.

“The notable point is that the special Fatemiyoun forces have been trained under skilled Afghan instructors who themselves have completed training in special courses under the supervision of skilled Hezbollah forces,” noted the Tasnim report.

According to Toumaj’s research of Iranian media, the IRGC expanded the ranks of Fatemiyoun forces from a brigade to a full division last year; and some 380 have been killed thus far in Syria.

A recent study by Israel’s Meir Amit Intelligence and Terrorism Information Center noted that one year after signing of the nuclear deal between Iran and world powers, Tehran has no intention of reducing its ties to Hezbollah, a designated terror organization.

In its report “Spotlight on Iran” for the week of July 4-17, the Center cited a July 12 interview on state-run Fars TV with Abbas Araghchi, Iranian deputy foreign minister, in which the official characterized the Iran-Hezbollah axis as “a priority… that could not be changed.”

“Araghchi’s remarks reinforce our assessment that no significant change can be expected in the quality and quantity of Iran’s support for Hezbollah, despite its effort to lift the international economic restrictions imposed on the country in recent years,” the Center noted.

It added, “Iran will be prepared to continue paying the diplomatic, media and even financial price in its relations with the United States and the West for continued fostering of Hezbollah as a military-political force and an Iranian proxy.”

 

John Kerry Issuing an Idle Threat to Turkey?

Power has not be restored at the U.S. coalition airbase, Incirlik, Turkey. Erdogan conducted a raid at the base arresting top Turkish commanders there. Further, there are an estimated 3000 Americans stationed in Turkey.

Turkish NATO membership may be in danger

US Secretary of State John Kerry warned Turkey, saying NATO will be scrutinising Turkey in coming days to ensure that it fulfils the alliance’s requirements.

Kerry said:

“NATO also has a requirement with respect to democracy,” Kerry said. Obviously, a lot of people have been arrested and arrested very quickly.

The level of vigilance and scrutiny is obviously going to be significant in the days ahead. Hopefully we can work in a constructive way that prevents a backsliding.”

A Number 10 spokesperson said:

“The National Security Adviser chaired a COBR meeting of senior officials this morning to discuss the situation in Turkey. Representatives from the Foreign and Commonwealth Office, the intelligence agencies, the Ministry of Defence, the Home Office and the Department for Transport attended. The ambassador and embassy staff in Ankara also joined by video link.

They noted that the situation in Turkey continued to stabilise, but that we needed to maintain our focus on the situation and monitor any developments over the coming days and weeks, including close cooperation and dialogue with the Turkish government.

British consular staff are working around the clock to support and reassure British nationals in Turkey at the moment, with a particular focus on supporting those waiting for planes in Turkey’s main airports. Flights are starting to get back to normal and backlogs of passengers are beginning to ease.

Officials agreed that we should monitor the situation on the ground closely over the coming days and keep the travel advice to Turkey under review.”

The Turkish military coup failed on Saturday morning as soldiers surrender after many dead and hundreds arrested.

Turkish President Erdogan had made a statement on Turkish television using his iPhone and FaceTime, calling on people to take to the streets to oppose the uprising.

Crowds confronted the coup plotters and gunfire and explosions were heard. The president has now returned to Istanbul, calling the coup attempt an “act of treason” and saying the army must be cleansed. He told crowds the government was now back in control.

Prime Minister Binali Yildirim ordered the military to shoot down aircraft being used by coup plotters, with a helicopter being shot down by an F-16.

17 Turkish police officers were killed in a helicopter attack at the police special forces headquarters just outside of Ankara.

Reuters reported that in early hours of Saturday local time, the coup appears to have “crumbled” as crowds defied pro-coup military orders and gathered in major squares of Istanbul and Ankara to oppose the coup. Reuters also reported pro-coup soldiers surrendering to the police in Taksim Square, Istanbul.