How Terrorists use Encryption

 

How Terrorists Use Encryption

June 16, 2016

CTC: Abstract: As powerful encryption increasingly becomes embedded in electronic devices and online messaging apps, Islamist terrorists are exploiting the technology to communicate securely and store information. Legislative efforts to help law enforcement agencies wrestle with the phenomenon of “going dark” will never lead to a return to the status quo ante, however. With the code underlying end-to-end encryption now widely available, unbreakable encryption is here to stay. However, the picture is not wholly bleak. While end-to-end encryption itself often cannot be broken, intelligence agencies have been able to hack the software on the ends and take advantage of users’ mistakes.

Counterterrorism officials have grown increasingly concerned about terrorist groups using encryption in order to communicate securely. As encryption increasingly becomes a part of electronic devices and online messaging apps, a range of criminal actors including Islamist terrorists are exploiting the technology to communicate and store information, thus avoiding detection and incrimination, a phenomenon law enforcement officials refer to as “going dark.”

Despite a vociferous public debate on both sides of the Atlantic that has pitted government agencies against tech companies, civil liberties advocates, and even senior figures in the national security establishment who have argued that creation of “backdoors”[1] for law enforcement agencies to retrieve communications would do more harm than good, there remains widespread confusion about how encryption actually works.[a]

Technologists have long understood that regulatory measures stand little chance of rolling back the tide. Besides software being written in other countries (and beyond local laws), what has not been fully understood in the public debate is that the “source code” itself behind end-to-end encryption is now widely available online, which means that short of shutting down the internet, there is nothing that can be done to stop individuals, including terrorists, from creating and customizing their own encryption software.

The first part of this article provides a primer on the various forms of encryption, including end-to-end encryption, full device encryption, anonymization, and various secure communication (operational security or opsec) methods that are used on top of or instead of encryption. Part two then looks at some examples of how terrorist actors are using these methods.

Part 1: Encryption 101 

End-to-End Encryption
A cell phone already uses encryption to talk to the nearest cell tower. This is because hackers could otherwise eavesdrop on radio waves to listen in on phone calls. However, after the cell tower, phone calls are not encrypted as they traverse copper wires and fiber optic cables. It is considered too hard for nefarious actors to dig up these cables and tap into them.

In a similar manner, older chat apps only encrypted messages as far as the servers, using what is known as SSL.[b] That was to defeat hackers who would be able to eavesdrop on internet traffic to the servers going over the Wi-Fi at public places. But once the messages reached the servers, they were stored in an unencrypted format because at that point they were considered “safe” from hackers. Law enforcement could still obtain the messages with a court order.

Newer chat apps, instead of encrypting the messages only as far as the server, encrypt the message all the way to the other end, to the recipient’s phone. Only the recipients, with a private key, are able to decrypt the message. Service providers can still provide the “metadata” to police (who sent messages to whom), but they no longer have access to the content of the messages.

The online messaging app Telegram was one of the earliest systems to support end-to-end encryption, and terrorists groups such as the Islamic State took advantage.[2] These days, the feature has been added to most messaging apps, such as Signal, Wickr, and even Apple’s own iMessage. Recently, Facebook’s WhatsApp[3] and Google[4] announced they will be supporting Signal’s end-to-end encryption protocol.

On personal computers, the software known as PGP,[c] first created in the mid-1990s, reigns supreme for end-to-end encryption. It converts a message (or even entire files) into encrypted text that can be copy/pasted anywhere, such as email messages, Facebook posts, or forum posts. There is no difference between “military grade encryption” and the “consumer encryption” that is seen in PGP. That means individuals can post these encrypted messages publicly and even the NSA is unable to access them. There is a misconception that intelligence agencies like the NSA are able to crack any encryption. This is not true. Most encryption that is done correctly cannot be overcome unless the user makes a mistake.

Such end-to-end encryption relies upon something called public-key cryptography. Two mathematically related keys are created, such that a message encrypted by one key can only be decrypted by the other. This allows one key to be made public so that one’s interlocutor can use it to encrypt messages that the intended recipient can decrypt through the private-key.[d] Al-Qa`ida’s Inspire magazine, for example, publishes its public-key[5] so that anyone using PGP can use it to encrypt a message that only the publishers of the magazine can read.

Full Device Encryption
If an individual loses his iPhone, for example, his data should be safe from criminals.[e] Only governments are likely to have the resources to crack the phone by finding some strange vulnerability. The FBI reportedly paid a private contractor close to $1 million to unlock the iPhone of San Bernardino terrorist Syed Rizwan Farook.[6]

The reason an iPhone is secure from criminals is because of full device encryption, also full disk encryption. Not only is all of the data encrypted, it is done in a way that is combined or entangled[7] with the hardware. Thus, the police cannot clone the encrypted data, then crack it offline using supercomputers to “brute-force” guess all possible combinations of the passcode. Instead, they effectively have to ask the phone to decrypt itself, which it will do but slowly, defeating cracking.[f]

Android phones work in much the same manner. However, most manufacturers put less effort into securing their phones than Apple. Exceptions are companies like Blackphone, which explicitly took extra care to secure their devices.

Full disk encryption is also a feature of personal computers. Microsoft Windows comes with BitLocker, Macintosh comes with FileVault, and Linux comes with LUKS. The well-known disk encryption software TrueCrypt works with all three operating systems as does a variation of PGP called PGPdisk. Some computers come with a chip called a TPM[g] that can protect the password from cracking, but most owners do not use a TPM. This means that unless they use long/complex passwords, adversaries will be able to crack their passwords.

Guccifer 2.0, the Hacked Trump Files from the DNC

The intrusions at the DNC are noteworthy for the sophistication of the groups behind it. One of the intrusions, by a well-known cyberespionage group called Cozy Bear, appears to have happened in the summer of 2015, according to Crowdstrike‘s CTO and co-founder Dmitri Alperovitch. The second breach, involving another Russian group, Fancy Bear, happened in April this year.

Cozy Bear has been previously associated with attacks on the White House and the US. State Department. The group has also been tied to numerous attacks on US defense contractors, government agencies, financial services companies, technology firms and think tanks, Alperovich said.  Fancy Bear, or Sofacy, as the group is also known, is similarly believed responsible for targeted attacks on various government and private sector organizations in multiple countries including the US, Canada, China and Japan, he said.

The two groups did not appear to be collaborating with each other or communicating in any fashion on the DNC attacks. But both targeted the same systems and the same data, employing a variety of sophisticated techniques in the process Crowdstrike’s CTO and co-founder Dmitri Alperovitch said in a blog post.

The Cozy Bear team used a Python-based malware tool dubbed SeaDaddy and another backdoor in Powershell to gain persistence on comprised DNC systems and to remain undetected on them for more than a year. According to Alperovitch, the Powershell backdoor was noteworthy for its use of a one-line command to establish an encrypted connection with command and control servers and for downloading additional modules.

The Fancy Bear group meanwhile used a different malware sample to remotely execute malicious commands on compromised DNC systems, to transmit files and to enable keylogging. The group deployed tactics like periodically clearing event logs and resetting the timestamps in files in an attempt to conceal their activities. More details here from DarkReading.

Gawker: A 200+ page document that appears to be a Democratic anti-Trump playbook compiled by the Democratic National Committee has leaked online following this week’s report that the DNC was breached by Russian hackers. In it, Trump is pilloried as a “bad businessman” and “misogynist in chief.”

The document—which according to embedded metadata was created by a Democratic strategist named Warren Flood—was created on December 19th, 2015, and forwarded to us by an individual calling himself “Guccifer 2.0,” a reference to the notorious, now-imprisoned Romanian hacker who hacked various American political figures in 2013.

The package forwarded to us also contained a variety of donor registries and other strategy files, “just a few docs from many thousands I extracted when hacking into DNC’s network,” the purported hacker claimed over email, adding that he’s in possession of “about 100 Gb of data including financial reports, donors’ lists, election programs, action plans against Republicans, personal mails, etc.”

Advertisement

His stated motive is to be “a fighter against all those illuminati that captured our world.”

The enormous opposition document, titled simply “Donald Trump Report,” appears to be a summary of the Democratic Party’s strategy for delegitimizing and undermining Trump’s presidential aspirations—at least as they existed at the end of last year, well before he unseated a field of establishment Republicans and clinched the nomination. A section titled “Top Narratives” describes a seven-pronged attack on Trump’s character and record.

Sponsored

The first is the argument that “Trump has no core”:

One thing is clear about Donald Trump, there is only one person he has ever looked out for and that’s himself. Whether it’s American workers, the Republican Party, or his wives, Trump’s only fidelity has been to himself and with that he has shown that he has no problem lying to the American people. Trump will say anything and do anything to get what he wants without regard for those he harms.

Second, that Trump is running a “divisive and offensive campaign”:

There’s no nice way of saying it – Donald Trump is running a campaign built on fear-mongering, divisiveness, and racism. His major policy announcements have included banning all Muslims from entering the U.S., and calling Mexican immigrants “rapists” and “drug dealers” while proposing a U.S.-Mexico border wall. And Trump’s campaign rallies have become a reflection of the hateful tone of his campaign, with protestors being roughed up and audience members loudly calling for violence.

Third, Trump is a “bad businessman”:

Despite Trump’s continual boasting about his business success, he has repeatedly run into serious financial crises in his career and his record raises serious questions about whether he is qualified to manage the fiscal challenges facing this country. Trump’s business resume includes a long list of troubling issues, including his company’s record of forcing people from their homes to make room for developments and outsourcing the manufacturing of his clothing line to take advantage of lower-wage countries like China and Mexico. His insight about the marketplace has proven wrong many times, including in the run-up to the Great Recession. And Trump’s record of irresponsible and reckless borrowing to build his empire – behavior that sent his companies into bankruptcy four times – is just one indication of how out-of-touch he is with the way regular Americans behave and make a living, and it casts doubt on whether he has the right mindset to tackle the country’s budget problems.

Fourth, Trump espouses “dangerous & irresponsible policies”:

Trump’s policies – if you can call them that – are marked by the same extreme and irresponsible thinking that shape his campaign speeches. There is no question that Donald Trump’s rhetoric is dangerous – but his actual agenda could be a catastrophe.

Fifth, in classically corny Democratic Party style, Donald Trump is the “misogynist in chief”:

Through both his words and actions, Trump has made clear he thinks women’s primary role is to please men. Trump’s derogatory and degrading comments to and about women, as well as his tumultuous marriages, have been well publicized. And as a presidential candidate, Trump has adopted many of the backwards GOP policies that we’ve come to expect from his party.

Sixth, Donald Trump is an “out of touch” member of the elite:

Trump’s policies clearly reflect his life as a 1-percenter. His plans would slash taxes for the rich and corporations while shifting more of the burden to the shoulders of working families. He stands with Republicans in opposing Wall Street reform and opposing the minimum wage. Trump clearly has no conception of the everyday lives of middle class Americans. His description of the “small” $1 million loan that his father gave him to launch his career is proof enough that his worldview is not grounded in reality.

The seventh strategy prong is to focus on Trump’s “personal life,” including that “Trump’s Ex-Wife Accused Him Of Rape,” which is true.

What follows is roughly two hundred pages of dossier-style background information, instances of Trump dramatically changing his stance on a litany of issues, and a round-up of the candidate’s most inflammatory and false statements (as of December ‘15, at least).

It appears that virtually all of the claims are derived from published sources, as opposed to independent investigations or mere rumor. It’s also very light on anything that could be considered “dirt,” although Trump’s colorful marital history is covered extensively:

The DNC hack was first revealed Tuesday, when the cybersecurity firm CrowdStrike announced it had discovered two hacking collectives, linked to Russian intelligence, inside the DNC network after the DNC reported a suspected breach. In a blog post, the company identified the groups as “COZY BEAR” and “FANCY BEAR”—two “sophisticated adversaries” that “engage in extensive political and economic espionage for the benefit of the government of the Russian Federation.”

The hackers were able to access opposition files and may have been able to read email and chat traffic, but did not touch any financial, donor, or personal information, the DNC said Tuesday. However, the user who sent the files to Gawker refuted that claim, writing, “DNC chairwoman Debbie Wasserman Schultz said no financial documents were compromised. Nonsense! Just look through the Democratic Party lists of donors! They say there were no secret docs! Lies again! Also I have some secret documents from Hillary’s PC she worked with as the Secretary of State.”

Among the files sent to Gawker are what appear to be several lists of donors, including email addresses and donation amounts, grouped by wealth and specific fundraising events. Gawker has not yet been able to verify that the Trump file was produced by the DNC, but we have been able to independently verify that the financial documents were produced by people or groups affiliated with the Democratic Party.

Also included are memos marked “confidential” and “secret” that appear to date back to 2008, and pertain to Obama’s transition into the White House, and a file marked “confidential” containing Hillary’s early talking points, at least some of which ended up being repeated verbatim in her April, 2015 candidacy announcement.

Finally, there is a May, 2015 memo outlining a proposed strategy against the field of potential GOP candidates. Donald Trump, who had not yet officially announced his candidacy, does not appear in the document.

The purported hacker writes “it was easy, very easy” to hack and extract thousands of files from the DNC network, “the main part” of which he or she claims are in the custody of Wikileaks. He or she also appears to have sent the documents to The Smoking Gun, which posted about the dossier earlier today.

Warren Flood did not immediately return a request for comment. DNC Press Secretary Mark Paustenbach was not able to immediately confirm the authenticity of the documents, but the party is aware that they’re circulating.

NATO Launches CyberSpace Mission

NATO to Recognize Cyberspace as New Frontier in Defense

 

Nasdaq: BRUSSELS—Allied defense ministers formally recognized cyberspace as a domain of warfare on Tuesday, an acknowledgment that modern battles are waged not only in air, sea and land, but also on computer networks.

The move comes the same day as the Democratic National Committee announced its computers had been hacked by the Russian government. DNC officials said the hackers made off with its opposition research related to Donald Trump, the presumptive Republican nominee for President.

The effort is designed to bolster allies’ cyberdefenses, but also will begin a debate over whether NATO should eventually use cyberweapons that can shut down enemy missiles and air defenses or destroy adversaries’ computer networks.

“This is important to all possible conflicts we can foresee,” he said.

Mr. Stoltenberg declined to address the suspected cyberhack on the Democratic National Committee by the Russian government, and wouldn’t name any potential cyber adversaries, noting that NATO’s cyberdefenses weren’t aimed at any one country. U.S. and allied officials have previously said Russia remains the greatest cyberthreat to the alliance.

Developing capabilities to more quickly attribute responsibility for cyberintrusions and cyberattacks is a priority for the alliance, Mr. Stoltenberg said.

“One of the challenge when it comes to cyber is it is not easy to tell who is attacking you,” he said.

The decision by the ministers will allow the alliance to better coordinate its cyberspace efforts and defenses, Mr. Stoltenberg said.

“This is about developing our abilities and capabilities to protect NATO cyber networks but also to help and assist nations in defending their cyber networks,” he said.

For now, the alliance is focused on defending its own secure networks and helping allies build their cyberdefenses.

Tuesday’s announcement to recognize cyberspace as new sphere of conflict or battleground constitutes a bit of catch- up by the alliance. The U.S. military, for example, has expanded its cyber command, improved its training and developed weaponry and defenses to deploy in cyberspace.

The change comes as the number of cyberattacks against the alliance and member states has been increasing, a senior NATO official said.

By making cyber a warfare domain, NATO will open the door to stepped up military planning, dedicate more officers to cyber operations and better integrate electronic warfare into its military exercises.

Two years ago, at the previous summit in Wales, NATO leaders announced a cyberattack on one ally could trigger the alliance’s collective defense provisions.

Under NATO’s founding treaty, each ally primarily has responsibility for its own defense. But NATO officials acknowledge that the alliance is only as strong as its weakest link, which makes helping nations improve their cyber capabilities a priority.

As part of efforts to counter so-called hybrid warfare threats, the use of covert forces to stir unrest or make military gains, NATO has been pushing member countries to improve their cyberdefenses.

Russia has made cyber and electronic warfare a key part of its military operations. U.S. and allied officials said that Russia has demonstrated its willingness to use such techniques to interfere with the military capabilities of its opponents in Ukraine. Russia denies it is involved militarily in Ukraine.

U.S. officials have said countering Russia’s improving militarily capabilities—such as its advanced missiles and air defenses in the Kaliningrad exclave on the border of Poland and Lithuania—could require cyber capabilities.

“Russia has sophisticated cyber capabilities,” said Vaidotas Urbelis, the defense policy director for the Lithuania ministry of defense. “But, come on, NATO nations have invested a lot in cyber and we have the capacity to defend ourselves.”

On Monday, Douglas Lute, the U.S. ambassador to NATO said cyber operations could be a key part of the alliance’s defense against stepped up Russian advances in anti-access weaponry.

“A networked air defense system can be jammed. It can be disrupted by way of cyber techniques,” Mr. Lute said.

A discussion of additional NATO cyber capabilities—or offensive capabilities—is likely to wait until after the conclusion of the alliance summit in Warsaw next month.

The alliance lags well behind its most militarily advanced members, including the U.S. and Britain, in developing its cyber capabilities. In any potential conflict, the alliance would need to rely on the U.S. and its use of cyber weaponry.

“We welcome the decision to recognize cyber as a domain,” said British Defense Secretary Michael Fallon, adding the U.K. has committed some $2 billion for its own cyberdefenses and capabilities.

The U.S. Army has been increasing its cyberdefense training at its training centers in the U.S. and Europe. A pilot program begun last year has aimed embedding “cyber elements” with tactical units.

“We know a variety of countries have increasing cyber capabilities that can interfere with your communications, your global position and navigating systems, your targeting systems,” said a U.S. defense official.
*****

Defense Secretary Ash Carter, left, talks with NATO Secretary General Jens Stoltenberg, right, at NATO headquarters in Brussels, June 14, 2016, during a meeting of NATO defense minister. The two leaders met to discuss matters of mutual importance. DoD photo by Air Force Senior Master Sgt. Adrian Cadiz

Last year saw was a small uptick in defense spending across Europe and Canada, Stoltenberg said. “Our estimates for 2016 show a further increase across NATO’s European allies and Canada,” said he added. “These are only estimates. But they are encouraging.”

The annual real change in NATO defense spending, he said, currently stands at around 1.5 percent, which represents an increase of more than $3 billion.

Plans to Boost Defense Spending

Some 20 NATO allies plan to spend more in real terms on defense this year, Stoltenberg said.

“So, this is real progress,” he said. “After many years of going in the wrong direction, we are starting to go into the right direction.”

With more money comes increased capabilities, Stoltenberg said, noting that NATO has agreed to place four battalions in the eastern nations of the alliance.

“Based on the advice of our military planners, we will agree to deploy by rotation four robust multinational battalions in the Baltic states and in Poland,” he said. “This will send a clear signal that NATO stands ready to defend any ally. More from the Department of Defense.

 

WikiLeaks to Provide Hillary Secret Emails

Nevermind, State Dept. – WikiLeaks is about to publish a batch of Hillary’s secret illegal emails

BizPac: WikiLeaks founder Julian Assange has not been in the news much recently, but the online provocateur is roaring back in the forefront this week with an announcement that will bedevil the Hillary Clinton campaign anew. Assange said he is set to release another large batch of emails Hillary sent from her illegal, secret server while she was Obama’s Secretary of State.

The announcement comes as the presumptive nominee for the Democrat Party presidential candidate essentially clinched the delegates needed to become the nominee even as she continues to fend off suspicions over whether or not the FBI will recommend she be indicted for breaking the nation’s security laws with her private, hackable email accounts.

According to The Guardian, Assange made his comments on the British political TV show “Peston on Sunday” saying, “We have upcoming leaks in relation to Hillary Clinton … We have emails pending publication, that is correct.”

 

Assange’s WikiLeaks already has a searchable data base of over 30,000 Clinton emails encompassing over 50,000 pages of documents sent from June 30, 2010, to August of 2014. The trove of information can be seen at WikiLeaks’ Hillary Clinton Email Archive.

When asked if he thought the U.S. Department of Justice would indict Hillary for breaking U.S. national security laws, Assange said that Obama would never allow it. Speaking of U.S. Attorney General Loretta Lynch, Assange said, “he’s not going to indict Hillary Clinton, that’s not possible. It’s not going to happen. But the FBI can push for concessions from a Clinton government.”

Assange, no fan of Hillary, also insisted she is a warmonger saying, “she has a long history of being a liberal war hawk.”

The WikiLeaks chief also slammed Internet giant Google for being “intensely aligned” with Clinton’s campaign.

Indeed, Assange’s comments come on the heels of charges that Google cooks its algorithms in order to hide the many decades of scandals connected to the Clintons when Google users search her name.

Recently Danny Sullivan of the website Search Engine Land realized that there is no automatic search parameter recommendation in the Google Search bar for “Crooked Hillary.” In contrast,”Lying Ted” comes up in the search bar as soon as users start typing the word “lying.”

Search Engine Land even discovered that searches for “Lying Ted” and “Crooked Hilary,” both terms used on the campaign trail by GOP front-runner Donald Trump, have been searched a similar number of times, yet the Hillary search still doesn’t afford users an automatic recommendation.

This led many to charge that Google is trying to make sure Hillary’s lies and criminal charges are harder for users to find.

This also led Robert Epstein, a psychologist at the American Institute for Behavioral Research and Technology, to say Google could help throw the presidential election to Hillary.

“We estimate, based on win margins in national elections around the world that Google could determine the outcome of upwards of 25 percent of all national elections,” Epstein said in a new study of Google’s search algorithm as reported in Wired magazine.

 

Russian Govt Hackers broke into DNC, Stole Trump Oppo

They have been inside for a year.

Last month May, ODNI James Clapper already testified to this.

The director of national intelligence on Wednesday said officials had seen signs of attempted cyberattacks on 2016 presidential campaigns.

“We’ve already had some indications of that,” James R. Clapper Jr. said at a cyber-event at the Bipartisan Policy Center in Washington.

He did not indicate whether the attempted intrusions were successful or whether they were by foreign or domestic hackers. Nor did he specify whether the websites or campaign networks of Democratic candidates Hillary Clinton and Bernie Sanders or Republican presumptive nominee Donald Trump were targeted.

“We’re aware that campaigns and related organizations and individuals are targeted by actors with a variety of motivations — from philosophical differences to espionage — and capabilities — from defacements to intrusions,” said Brian P. Hale, director of public affairs for the Office of the Director of National Intelligence. “We defer to FBI for specific incidents.” More here from WaPo.

   

 

Russian government hackers broke into DNC servers, stole Trump oppo

The hackers had access to the information for approximately one year.

Politico: Russian government hackers broke into the computer systems of the Democratic National Committee and accessed information about Democratic candidates as well as a database on opposition research against Donald Trump, POLITICO has confirmed.

The Washington Post first reported on Tuesday that the DNC was aware of suspicious activity in April; within 24 hours of the first signals that something was amiss, cyber firm CrowdStrike was brought in to install monitoring software to analyze the details of who was responsible.

The hackers had access to the information for approximately one year but were all cleared out over the last weekend, the Post reported, noting that the DNC said that no personal, financial or donor information had been accessed or taken.

“The security of our system is critical to our operation and to the confidence of the campaigns and state parties we work with,” said Rep. Debbie Wasserman Schultz (D-Fla.), the DNC chairwoman, in a statement. “When we discovered the intrusion, we treated this like the serious incident it is and reached out to CrowdStrike immediately. Our team moved as quickly as possible to kick out the intruders and secure our network.”

A spokesman for the Russian Embassy told the Post that he had no knowledge of the hacking.

Shawn Henry, the president of CrowdStrike, told MSNBC moments after the story broke that the DNC was “very responsive” to the hack.

“They immediately recognized and had a high degree of urgency that this was important by calling us in,” Henry said. “The key piece is moving towards remediation. How are we able to quickly kind of stop the flow of intelligence that’s leaving that network and move the attackers off the network and provide the organization, allow them to build a network that is free from this type of tools that the Russians had put on to the network.”

Henry, former executive assistant director at the FBI, said the DNC contacted his organization through their legal counsel.

“We deployed certain pieces of technology that we use to try to get some visibility into the extent, the depth and breadth of this particular breach. In the course of this, working very closely with the I.T. staff of the DNC, we were able to identify with a very high degree of confidence a group that we have attributed back to the Russian government targeting that DNC network,” Henry said. “We know with certainty my time in the bureau and now at Crowd Strike that foreign intelligence services are constantly interested in political processes. They’re interested in strategies. They’re interested in foreign policy, et cetera. And the DNC and other NGOs that have been targeted over the years by this very, very sophisticated group with a high degree of capability and some very, very sophisticated technology.”