CRYPT NEWSLETTER 52
December 1998 - January 1999

Editor: George Smith, Ph.D.
INTERNET: 70743.1711@compuserve.com
          crypt@sun.soci.niu.edu
http://www.soci.niu.edu/~crypt

Mail to:
Crypt Newsletter
1635 Wagner St.
Pasadena, CA 91106
ph: 626-568-1748

Crypt Newsletter articles may not be copied or reproduced in or
on other media, on CD-ROM collections of data, or offered - in part
or in toto - as part of any database, data survey, information or
research service without prior consent of the editor. Rates based
on word count are reasonable. Queries by e-mail are welcome.


                                       
  Contents: Crypt Newsletter #52       
                                       

 THIS ISSUE

NEWS
The Joseph K Guide to Tech Terminology: Eligible Receiver

Reaction to "Electronic Pearl Harbor Not Likely:" John
Hamre, Michael Vatis, and an ex-Air Force info-warrior
speak.

A SAIC vice-president says it's time to reach for the
sick bag.

What's new in world paranoia:  The Pentagon fears the
Web, Moscow fears the Pentagon.

Bah Humbug! Network Associated fires up the media with
a computer virus scare story
===============================================

From the Crypt Newsletter (JOSEPH K) Guide To Tech Terminology:

Eligible Receiver: A Pentagon ghost story peddled to journalists
in which ludicrous or unsubstantiated claims about
menaces from cyberspace are passed off as astonishing deeds of
techno-legerdemain performed by cybersoldiers working within a
highly classified wargame.

Usage: Author James Adams claimed in Techweek magazine that
Pentagon hackers employed in _Eligible Receiver_ "did more than
the massed might of Saddam Hussein's armies, than the Nazis in
the Second World War."
======================================================

REACTION TO "AN ELECTRONIC PEARL HARBOR? NOT LIKELY"

Crypt News starts this issue with some reaction to its article,
"An Electronic Pearl Harbor? Not Likely!" in "Issues in Science
and Technology" which argued the case that the Pentagon -- in
its current paranoid spasm over potential threats in cyberspace --
had concocted enemies out of myths, poor understanding of
technical issues and misused statistics.

Crypt:

"I worked at the Air Force Information Warfare Center in San Antonio
from its inception in 1993 to 1995 under Colonel Osterloh. (This
time period encompasses the Rome Labs intrusions.) General Minihan,
now Director of the National Security Agency, was the commanding
general for Air Intelligence Agency. I argued against the "Wheelgroup"
crowd that much of this was all hype/bull and required intelligence
and tools that simply couldn't be compiled and developed.

"Osterloh went to BTG Inc, an 'associate' of what later
became Wheelgroup.  The atmosphere there was just comical, as these
guys were finding hackers under every rock, and when they couldn't find
them, they _became_ them and started yelling 'look, look, there they are!'
It was absolutely ridiculous. And then a Fortune magazine article came
out on what was supposed to a very classified subject . . . put out by
the same guys who classified it. What a circus!

"Technically it's worth noting that it was DoD regulation that no --
repeat no -- classified network, even if only confidential, could be
hooked up to the public phone system or Internet.  The Rome hackers,
or LANL hackers, or whomever, could only view unclassified information,
something rarely pointed out. All classified networks _were_ stand-alone.

"Your bottom line was correct. It's money for contractors who hire
retired colonels.  Same game, just a new board.  Same disservice to
the taxpayers."

An info-warrior Crypt News reader


Even more interesting was the response from the Pentagon's leading
doomsayer on information warfare and "electronic Pearl Harbor,"
John Hamre.  Crypt News readers will recall John Hamre and his
subordinates deigned not to respond to its original requests
for interviews on the subject of the Rome Labs hackers and 1998
cyberattacks on DoD _before_ "EPH Not Likely" was published. Instead,
it was left to others within the DoD bureaucracy to claim relative
ignorance on the subject, a position which subsequently made
Pentagon leadership appear foolish on this issue.

Hamre does not respond to the Crypt News demolition of the widely
quoted and misrepresented Defense Information Systems Agency figure
"250,000 hacks on Department of Defense in 1995."  Instead, he
produces yet another statistic attributed to a secret agency, in
effect, another source well out of reach of independent
civilian audit.

Surprisingly, instead of providing any clear explanation on alleged
national threats in cyberspace, Hamre's letter falls back upon the
dogged assertion that a classified wargame -- Eligible Receiver --
proved the U.S. vulnerable to devastating cyber-attack.

"Secrecy is for losers . . . " writes Daniel Patrick Moynihan in his
newly published book of the same title on the pernicious effect
of classification. Crypt Newsletter criticized Hamre and the Department
of Defense for abuse of the same, the utilization of classification
to fob off legitimate effort at analysis of Eligible Receiver
in "EPH Not Likely."

John Hamre's commentary:

"I applaud George Smith's ("An Electronic Pearl Harbor: Not Likely,"
Issues, Fall 1998) conclusion that '. . . computer security concerns
in our increasingly technological world will be of primary concern well
into the foreseeable future.' However, I disagree with his assessments
that downplay the seriousness of the threat. It may well be true
that hoaxes about viruses propagate more successfully than the real
thing and that many joy-riding hackers do not intend to do real harm.
It certainly is true that the cleared insider is a serious threat. But
these points do not mean that threats from external attack are not
serious, or that it is inappropriate for government
to be very concerned.

"From January to mid-November 1998, the National Security Agency (NSA)
recorded approximately 3,855 incidents of intrusion attempts (not
simply probes) against the Defense Department's unclassified computer
systems and networks. Of these, over a hundred obtained root-level
access, and several led to the denial of some kinds of service. These
figures, of course, reflect only what is reported to NSA, and the
actual number of intrusions probably is considerably higher.

"The concern, in a networked environment, is that a risk accepted by
one user becomes a risk shared by all. One is no more secure than
one's weakest node. We are working hard to improve our network security
posture. But intrusion tools are proliferating and becoming easier to
use, even as our own dependence on these networks is growing.

"Smith dismisses the concerns we had over the intrusions into our
networks last spring as a product of 'the Pentagon's short institutional
memory.' In fact, many in responsible positions during this incident
were well aware of the 1994 Rome Labs intrusions. However, a major
difference between 1994 and 1998 was that the intrusions last spring
occurred while we were preparing for possible hostilities in Southwest
Asia. Since we could not quickly distinguish the intruders' motives
or identities, we took this incident very seriously. In December 1941
there was no mistaking who our attackers were.
In the cyber world, penetrations for fun, profit, or intelligence
gain may be indistinguishable at first from intrusions bent on doing
serious harm.

"The fact that the perpetrators turned out to be a couple of teenagers
only reinforces the fact that such 'joyrides in cyberspace' are not
cost-free events. In addition to the laws that were broken, the
resources expended by the Departments of Defense and Justice, and the
impact on the private sector service providers who helped run the
intruders to ground, this case compounded an already tense international
situation. Future incidents may not work out so benignly.

"Smith downplayed the importance of the infrastructure vulnerabilities
simulated during the Eligible Receiver exercise. He should not. The
risks to our critical national infrastructures were described last year
by the President's Commission on Critical Infrastructure Protection,
and the importance of protecting them was reaffirmed in May by
President clinton [sic] in his Decision Directive 63. This is a
complicated area where solutions require an energetic partnership
between the public and private sectors. We are working to forge such
alliances.

"In this context, I take particular exception to Smith's insinuation
that those who express concern about information warfare do so mainly
because they will benefit from the resulting government spending. For
several years a wide variety of sources in and out of government-private
industry advisory councils, think tanks, academia, as well as entities
such as the Defense Science Board--consistently have said we must do
more in the area of information assurance and computer security. It
is hardly surprising that some of the proponents of this research
should work for companies who do business with the Defense Department.
To impugn the integrity of their analysis on the basis of these
associations does a disservice to those whose judgment and integrity
I have come to value deeply.  [Hamre refers to Duane Andrews, a
head of Science Applications International Corporation [SAIC]. -- CN]

"The United States was fortunate in the 1920s and 1930s to have had a
foresighted group of military planners, the congressional leadership
to support them, and an industrial base to bring into being the weapons
and doctrine that survived Pearl Harbor and prevailed in World War II.
My goal is to ensure that we are similarly prepared for the future,
including the very real possibility of cyber attack."

John J. Hamre
Deputy Secretary of Defense


And here is a response from Michael Vatis, Deputy Director of the FBI
and Chief of the National Infrastructure Protection Center:

"As those familiar with George Smith's work would expect, his article is
timely and provocative. Although we might disagree with some specifics of
Smith's characterization of the past, the focus of the National
Infrastructure Protection Center (NIPC) is on the future. Based on
extensive study of the future global information environment, the
leadership of this country believes that the risk of a serious
disruption of our national security and economy by hostile sources
will grow in the absence of concerted national action.

"The U.S. intelligence community, including the director of the Central
Intelligence Agency, has noted the growing information warfare (IW)
capabilities of potential adversaries. Several foreign governments have
operational offensive IW programs, and others are developing the technical
capabilities needed for one. Some governments are targeting the U.S.
civilian information infrastructure, not just our deployed military forces.
Terrorists and other transnational groups also pose a potential threat.
However, a potential adversary would probably consider the ability of the
United States to anticipate, deter, and respond to its attacks. By
reducing the vulnerability of the national information infrastructure, we
raise the bar for those who might consider an attack and reduce the
national consequences if one occurs.

"The Presidential Commission report cited by Smith discusses in depth the
vulnerability of our national infrastructures across the board, including
the telecommunications, banking and finance, energy, and emergency service
sectors. All of these sectors in turn depend on the rapidly growing
information infrastructure. However, technologies to help protect
communications, their content, and the customers they serve have begun
receiving attention only recently as amateur hackers, disaffected
employees, unscrupulous competitors, and others have escalated attacks
on information systems. These types of relatively unstructured,
unsophisticated groups and individuals have already demonstrated the
vulnerability of some of our most sensitive and critical systems. Can
there really be any doubt that we need to take action now to prevent
the much more serious and growing threat posed
by more malicious, sophisticated, and well-funded adversaries, such as
terrorists and foreign governments? Given the demonstrated vulnerabilities
and the clear threats we already know about, it would be irresponsible
for the U.S. government to fail to act now.

"Presidential Decision Directive 63, the key outgrowth of the
commission's report, provides national strategic direction for redressing
the vulnerabilities in our information and other national infrastructures.
The Critical Infrastructure Assurance Office is developing a national
plan and organizing joint government-industry groups to begin to build
sector strategies to address these vulnerabilities. At the NIPC, we are
taking steps to design and implement a national indications and warning
system to detect, assess, and warn of attacks on critical private sector
and government systems. This involves gathering information from all
available sources, analyzing it, and sharing it with all affected
entities, public or private. We are also designing a plan to coordinate
the activities of all agencies and private sector entities that will
be involved in responding to an attack on our infrastructures. These
efforts to improve our ability to prevent and respond are critical if
we are to be prepared to face the most serous challenges of the
Information Age.

"Still, we cannot substantially reduce the vulnerability of our
national information infrastructure without close collaboration
between government and the private sector. As Smith states, neither
government nor industry has succeeded so far in sharing enough of the
information needed to help reduce vulnerabilities, warn of attacks or
intrusions, and facilitate reconstitution. We have made this an
important priority on our agenda. Public discussion of these issues
through media such as Smith's article provides an important opportunity
to foster the understanding that we are all in this together and that
we can reduce our vulnerabilities only through effective partnership. In
the absence of partnership, the only clear outcome is the greater
likelihood of the type of devastating information attack that
we all seek to avoid."

Michael A. Vatis
Chief
National Infrastructure Protection Center
Washington, D.C.


Additional hate mail can be found at:

http://www.nap.edu/issues/15.2/forum.htm


======================

And in the November issue of the Federation of American Scientists'
Secrecy & Government Bulletin (www.fas.org/sgp), Steven Aftergood
elicits a comment on "electronic Pearl Harbor" from a vice-president
of a Pentagon vendor, SAIC, a privately-held corporation familiar
to Crypt Newsletter readers.

"I certainly agree that the notion of an electronic Pearl Harbor
specifically, and more generally of information warfare, has been
hyped to the point of nausea," said the VP to the FAS Secrecy and
Government Bulletin.  "This is but the latest in many fads in
'the Community' . . . and like most of its predecessors [it]
has just enough substance to require that serious attention
be paid, but not nearly as much substance as the Cassandras of
the community would have us believe."
=======================

Further fallout from the Crypt News's article appeared in
the January/February issue of the Bulletin of Atomic Scientists
and the January issue of Scientific American.

From the Bulletin's "In Brief:"

"Information warfare, says George Smith . . . has been vastly
overrated.  Smith . . . points out that the FBI's seminal article,
'Computer Crime: An Emerging Challenge for Law Enforcement,' relied
heavily on reports of a computer virus called 'Clinton.' But there
was no such virus -- it and other viruses cited in the FBI article
had come from an April Fool's Day column in a computer magazine.
Similarly, Smith points out that the Defense Information Systems
Agency (DISA) says there were 250,000 intrusions by hackers into
Defense Department computers in 1995. But this figure is an illusion.
DISA received reports of some 500 actual 'incidents,' but decided
arbitrarily that only 0.2 percent of cases were reported. Therefore,
DISA 'multiplied [actual incidents] by 500 and came up with
250,000.'"
==============

In the January 1999 issue of Scientific American, "EPH Not Likely"
is cited within the larger context of recent Pentagon reaction
to the Internet.

In "CyberView," reporter Daniel G. DuPont discusses how Pentagon
leaders were given an alarmist briefing stressing how the casual
Internet surfer could gather allegedly sensitive information on the
U.S. military.

In an effort to appear vigilant, the Pentagon subsequently
demonstrated not only that it knows little of the ways of the Web
but that some of its leaders appear to be gripped by an unreasoning
fear of it.

This news, first discovered by defense analyst William Arkin
and written about comprehensively in his on-line Washington Post
column, "dot.mil," shows the "professional paranoids" within the
defense establishment to be calling the shots vis-a-vis Internet
and World Wide Web policy.

The Pentagon, concerned over release of sensitive information
via the Web, called for a global review of all content on military
Websites in late 1998. The Army even went so far as to shut
down _all_ of its approximately 1,000 Websites for a period of
time.

The Federation of American Scientists' John Pike said for
Scientific American, "It's as though the [military has made]
a new category of information that is sufficiently boring to
be passed out in hard copy but is too sensitive to be available
in soft copy." Arkin commented that the Pentagon had grossly
misjudged the Internet and "the military's ability to control
it."

The always quotable Pike added that the Pentagon had constructed its
policy about the Web, not out of any genuine knowledge about
cyberspace, but as a consequence of "a profound lack of understanding
of information and computer security."


BAH! HUMBUG!

Network Associates (NAI) tried to put coal in the stockings
of consumers while lunging for their wallets by revisiting John
McAfee-style sales tactics with end-of-year vendor-driven scare
stories about a new Windows NT virus, Remote Explorer.

Inflated claims of a new virus infection on an anonymous Fortune 500
company were distributed the week before Christmas by press release
supplied by an NAI mouthpiece. The hapless victim's identity, MCI
WorldCom, was leaked a day later.

Standard big anti-virus company ethically bankrupt behavior applies:
The company has "official" policy of not releasing names of infected
clients it does business with but _accidentally_ "leaks" names
when such is deemed useful in a promotional campaign.  NAI officials
cynically believe computer press won't call them on these tactics,
snuck in at the end of the year to boost the company's stock price
(Rob Rosenberger's Virus Myths site showed NAI's stock value had
ticked up 22 percent during the "crisis") and massage consumer
interest.

It was another in a long line of shabby attempts at manipulating
the media and hoodwinking consumers with grossly exaggerated and
presented out of context cyberscare stories hooked to computer
viruses.

Thousands of computer viruses are written every year. Only a small
subset actually make it into circulation.  Of the smaller number,
even fewer are interesting from a technical standpoint.  During the
past decade, no computer virus for the IBM PC has turned out to
warrant the periodic media explosions that have occurred when a
company like Network Associates attempts to steal attention at the
expense of a handful of unsophisticated editors and reporters in the
mainstream media. Computer viruses remain a constant in networked
computing but are not harbingers of a revolution in "cyberterrorism"
as Network Associates and other pundits like to claim.

A thorough trashing of the original _computer virus as sales tool_
weapon, as perfected by Network Associates in 1992 is republished on
the Crypt News website (www.soci.niu.edu/~crypt/other/michey.htm).
Originally appearing in the American Journalism Review in 1992, the
names are different but the story of predatory business practices
run amok remains immediately recognizable.


SO WHAT ELSE IS NEW IN WORLD COLLECTIVE PARANOIA? Russian publication
claims U.S. military is readying "electronic Hiroshima" for
Moscow. [Another in an infrequent series.]

  "Mr. President, we must not _allow_ a mine-shaft gap!"
              -- General Buck Turgidson in "Dr. Strangelove"

For this issue the CIA's Foreign Broadcast Information Service
yielded some radioactive phlogiston, smelling strongly of the
Cold War, generated as a consequence of the continued hype on
information warfare emitted by the Pentagon.

On December 16, Komsomolskaya Pravda, one of "Russia's
largest circulation and most outspoken dailies," according to the CIA
service, published a feature entitled: "Electronic 'Hiroshima' Already
Hidden in Moscow; 21st Century Wars Will Be Like Computer Horror
Games."

The hysterical tone of the article was underlined by a series of
panicked statements: "'Logic Bombs'" Will Cause End of the
World," "a [virus] infecting computers and destroying their
content . . . could have the effect of dozens of Hiroshimas" and
"Hackers Have Become [the] Pentagon's Teachers."

One interesting myth delivered by it is framed around the appearance
of Richard Pryce, one of the British teenagers who broke into the
Department of Defense's Rome Labs installation at Griffiss Air Force
Base in 1994. Pryce and his accomplices, claims the Russian article,
launched a "[space] shuttle" remotely and switched all of "New York's
traffic lights to green."

The CIA, continues the article, has also tried to attack Russian
computers with viruses.

The Komsomolskaya Pravda piece opines that Russia will retaliate
with electromagnetic pulse weapons, here called "beer cans," an
armament that can "cut down" U.S. "supercomputers."

   "I commissioned a study of this project by the Bland Corporation
                            last year." -- "Dr. Strangelove"

-------------------------------------------------------------
Acknowledgments: Electronic clippings courtesy of David Isenberg
and Steven Aftergood to whom the Crypt Newsletter is mighty obliged.
-------------------------------------------------------------
George Smith, Ph.D., edits the Crypt Newsletter from Pasadena,
CA.

copyright 1998 Crypt Newsletter. All rights reserved.

Crypt Newsletter's PGP public key.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.1

mQBtAy9uMW0AAAEDAMU9Dj5kvpNLBfD04jwBd7r07/c+uH/MtH8yKGEvR/y5wJUz
I0BYZ+v1lFi6qIBuMJDzDzgOtvxKRV+wFW3AjqsHHX6m64VX/S9a0QqsTyLN71WE
e5a4cFjN1fh1QnW9uQAFEbQoR2VvcmdlIFNtaXRoIDw3MDc0My4xNzExQGNvbXB1
c2VydmUuY29tPg==
=IyYG
-----END PGP PUBLIC KEY BLOCK-----
 
