CRYPT NEWSLETTER 55 May -- June 1999 Editor: George Smith, Ph.D. INTERNET: 70743.1711@compuserve.com crypt@sun.soci.niu.edu http://www.soci.niu.edu/~crypt Mail to: Crypt Newsletter 1635 Wagner St. Pasadena, CA 91106 ph: 626-568-1748 Crypt Newsletter articles may not be copied or reproduced in or on other media, on CD-ROM collections of data, or offered - in part or in toto - as part of any database, data survey, information or research service without prior consent of the editor. Rates based on word count are reasonable. Queries by e-mail are welcome. Contents: Crypt Newsletter #55 =============================================== WHO WERE THOSE MASKED MEN? From the Crypt Newsletter (JOSEPH K) Guide To Tech Terminology: Eligible Receiver: A Pentagon ghost story repeated ad nauseum to journalists and the easily frightened in which ludicrous or totally unsubstantiated claims about menaces from cyberspace are passed off as astonishing deeds of techno-legerdemain performed by cybersoldiers working within a highly classified wargame. Usage: Author James Adams claimed in Techweek magazine that Pentagon hackers employed in Eligible Receiver "did more than the massed might of Saddam Hussein's armies, than the Nazis in the Second World War." Since its first appearance in 1997, _Eligible Receiver_' like the phrase "electronic Pearl Harbor," has become a good touchstone for uncritical, unsophisticated journalism on the potential for cyberterrorism to lay low the nation. Although never substantiated with solid proof by Pentagon leadership, it has become an article of faith in the mainstream newsmedia and still appears regularly as prima facie evidence of what hackers could do to plunge the empire into chaos. Characteristics of invocations of _Eligible Receiver_ can include any or all of the following: there were 20 hackers, there were about 25 hackers, there were 35 hackers, there were 30 or 35 hackers, the hackers were from the [Pentagon, the NSA, the Joint Staff], the national power grid was taken down, the 911 service was taken down, troop movements were disrupted, laptops were bought, laptops were stolen, software was bought off-the-shelf, software was obtained from the Net, unspecified secret computer systems were compromised and/or unspecified public computer systems were compromised. Here then, a selection of examples of Eligible Receiver in the news: From the April 1999 issue of "Government Executive," a reporter writes on the danger of cyberterror to the national networks: "The liability posed by such dependence became clear when the Pentagon conducted an exercise known as Eligible Receiver in 1997. Using off-the-shelf technology and software downloaded from hacker Web sites, a team of about 20 employees from the National Security Agency hacked into unclassified Pentagon computer systems. The surprise exercise, designed to expose weaknesses in computer security, succeeded beyond the planners' wildest expectations. Among other things, the exercise showed how hackers might disrupt troop deployments. "It was startling," [Deputy Defense Secretary] John Hamre said. 'We didn't really let them take down the power system in the country, but we made them prove that they knew how to do it.'" [The previous quote is a year old. "What's startling" is that a reporter is still repeating it in April 1999.] ------------- From an April 22, 1999, issue of "Inside the Army:" "Two years after Eligible Receiver, a joint exercise conducted by DOD in which virtual 'terrorists' used stolen hardware from a government facility to gain control over secret computer systems without being detected, the military finds itself 'in full-scale conflict,' [Deputy Secretary of Defense] John Hamre said. Important lessons learned over this period include 'that cyperspace ain't for geeks, it's for warriors,' he said." ------------- From a March 22, 1999 report by Associated Press writer Laura Myers entitled "Study Finds Hacker Threat a Real Danger." Reporter Myers appears to be only vaguely familiar with the Pentagon claim and gets a figure wrong -- hardly a liability, even Pentagon proponents of "Eligible Receiver" can't seem to agree on the number of people involved -- but nevertheless passes on the growing legend as proof of national danger: "In 1997, a national security team of about 20 people, in a cyberwar game [Eligible Receiver] lasting three months, gained access to unclassified Pentagon computers, giving the team the ability to disrupt troops movements." ------------- From an interview on cyberterrorism conducted with Senator John Kyl by the United States Information Agency (USIA), published in November 1998: Kyl: Well, [cyberterrorism is] surprisingly easy. It's hard to quantify that in words, but there have been some exercises run recently. One that's been in the media, called Eligible Receiver, demonstrated in real terms how vulnerable the transportation grid, the electricity grid, and others are to an attack by, literally, hackers -- people using conventional equipment, no "spook" stuff in other words. ------------- From the Fall 1998 issue of the University of Southern California's "Networker" magazine: "Operating under the code-name Eligible Receiver, 35 people working for the National Security Agency targeted unclassified computer systems across the country. Employing only hacking tools downloaded from the Net and standard-issue computers, the team reportedly accessed the U.S. Pacific Command in Hawaii - in charge of 100,000 troops - among other targets. "'We didn't really let them take down the power system in the country, but we made them prove that they knew how to do it,' Deputy Secretary of Defense John Hamre told the press. [Ahem.] "Before Eligible Receiver, what you had was a bunch of driven geeks and a few admirals and generals dotted around who said that 'this is really important stuff' and a bunch of traditionalists who were saying 'yeah, right. It's all just rubbish, really,' says Adams. 'Well, Eligible Receiver gave everyone a very nasty shock because it showed that the whole system could be devastated,' he adds. Editor's note: James Adams wrote a book called "The Next World War," published in 1998, that based most of its premises that computers would fight all future wars on Pentagon claims like "Eligible Receiver." The book was pilloried for passing on myths and April Fool's jokes, such as the Gulf War virus hoax, as fact. "[Eligible Receiver] resonated at the Department of Defense, which has 2.1 million computers, 100,000 local area networks, and more than 100 long-distance networks. Eligible Receiver was 'a very telling example for all of the senior leadership here,' says Susan Hansen, a [Pentagon flack] for Secretary of Defense William Cohen. ------------- From a USIA interview (published in November 1998) with reporter James Adams, here advertised as the CEO of "Infrastructure Defense," a firm presumably started to help protect from potential Eligible Receivers: "The 'hackers' taking part in the exercise -- called Eligible Receiver -- were, in fact, U.S.government employees. They were given no advance intelligence. They bought their laptops from a local computer store. "The hackers successfully demonstrated that they could with ease break into the power grids of all the major U.S. cities -- from Los Angeles to Chicago to Washington, D.C., to New York -- that were linked to the U.S. capability to deploy forces. At the same time they were able to break into the -911- emergency telephone system and could comfortably have taken both of those networks down . . ." ------------- From a September 2, 1998, Jane's Defense Weekly piece on information warfare and the Department of Defense: "In one Joint Chiefs of Staff simulation, known as Eligible Receiver, US officials posing as terrorists were able to shut down key command and control systems at US Pacific Command headquarters." ------------- In an August 2, 1998 story by Cox Newspapers' by Andrew Glass entitled: "Target America: Computer Warfare," the Pentagon grail is credited with turning off all operations of the DoD's Pacific Ocean/Asian command as well as the 911 system. Sun Tzu is credited with the germ of the idea, too. "Last June, the National Security Agency staged a 'red team' exercise, code-named Eligible Receiver, in which agents pretending to be North Koreans infiltrated the command-and-control facilities of the U.S. Pacific Command in Honolulu --- demonstrating their ability to neutralize most U.S. armed forces from Okinawa to San Diego for many hours without firing a shot. "Attaining 100 victories in 100 battles is not the pinnacle of excellence," [Sun Tzu] wrote in 'The Art of War,' the earliest known treatise on military science. 'Subjugating the enemy's army without fighting is the true pinnacle of excellence.'" And, further on: "Appearing last June before the Senate Judiciary subcommittee on technology, terrorism and government information, Ellie Padgett, deputy chief of the NSA's office of defensive information warfare, told of one aspect of the worrisome success in Eligible Receiver. In a phase of the exercise that simulated attacks, she said, 'we scripted (an) Internet message (that) would be sent out to everybody saying there was a problem with the 911 system, understanding that human nature would result in people calling the 911 system to see if there was a problem' --- thus causing the overloaded phone system to crash." ------------- In a speech in Aspen, Colorado, in late July 1998, the Pentagon's John Hamre said of Eligible Receiver: "A year ago, concerned for this, the department undertook the first systematic exercise to determine the nation's vulnerability and the department's vulnerability to cyber war. And it was startling, frankly. We got about 30, 35 folks who became the attackers, the red team . . . We didn't really let them take down the power system in the country, but we made them prove that they knew how to do it." ------------- From a June 1998 Congressional Governmental Affairs Committee meeting chaired by former actor Fred Thompson who played a naval commander in the movie adaptation of Tom Clancy's "The Hunt for Red October": "Lt. General Minihan, the Director of the National Security Agency, will identify in greater detail the nation's vulnerability as revealed in a recent war game known as Eligible Receiver. The Committee also will explore whether the [Y2K] problem will increase America's vulnerability to attack. As we approach the 21st century, will terrorists and rogue nations test their information warfare weapons without fear of being caught and insert data smart bombs into the nation's computers for use at a later date?" ------------- From a May 24, 1998 story in the Washington Post written by Bradley Graham: "Many details of the exercise, dubbed Eligible Receiver, remain closely held. But according to official sources, a group of 35 NSA specialists simulated a series of rolling power outages and 911 emergency phone overloads in Washington and a handful of other cities. They showed that large-scale blackouts could be caused by targeting computerized sensing and control devices known as Supervisory Control and Data Acquisition systems, which have become common substitutes for human monitors in operating electrical, oil, gas, transportation and water treatment systems." ------------- From an April 23, 1998 press conference led by Kenneth Bacon, the Pentagon's head flack: "And that was one of the, as I said, one of the signal achievements of the exercise the Joint Staff ran, ELIGIBLE RECEIVER, to improve the awareness of people within the Department of what the computer security issue is." -------------- In World War II, the Wehrmacht rolled over Yugoslavia in about nine days. Where are the "Eligible Receiver" info-warriors now -- those [Pentagon hackers] who "did more than the massed might of Saddam Hussein's armies, than the Nazis in the Second World War"? STILL MORE NET PARANOIA, HYPOCRISY In an April 19, 1999, article published by Federal Computer Week Pentagon leadership once again took the opportunity to express its paranoia re anything cyberspace. It's time to disconnect from the Internet, some leaders said. Strangelovian quote was scattered throughout. "We don't have a prayer or a hope of defending ourselves unless we move large portions of the '.mil' [domain] onto a protected network," claimed Lt. General William Campbell of the Army. Late in 1998, Campbell was the Army leader who ordered suspension of all Army websites until they could be scrubbed of alleged "sensitive" data. Air Force Major General John Campbell, a director of the Pentagon's Joint Task Force for Computer Network Defense repeated the old myth that Department of Defense's unclassified networks are attacked over 250,000 times a year. Phil Loranger astonishingly claimed [the Army] "still [has] more public Web pages than necessary." Deputy Secretary of Defense John Hamre, having spent most of 1998 trying to convince the Department of Defense, the government, and anyone who in the mainstream media who would listen [see Eligible Receiver piece], that the Internet was a horrible menace filled with cyberterrorists just ready to strike found himself in the awkward position of advocating a less irrational approach. Hamre said the military was too plugged-in to back off the Internet. Having said that, Hamre quickly reverted to form, claiming that electronic commerce and business connectivity on the Net were the new threats to national security. The idea -- according to Hamre -- is that by allowing others to transact business on the Net, somehow, the one setting up the business becomes a horrible threat to security. Hamre attempted to explain this by airing the idea that if access software is handed out to potential customers, it creates a potential for abuse. Of course, if one follows this line of reasoning to its logical conclusion, then Compuserve, America On-Line, even Netscape -- all are insidious portals through which the stability of America can be undermined. [Editor: Actually, this appears to also be another extension of the paranoid belief that Y2K remediation has been a convenient smokescreen for many enemy agents unknown to plant viruses and logic bombs in domestic software.] The Pentagon's conclusion, if it adheres to its own unusual logic, translates to: Everyone must give up the Internet if the security of the nation is to be preserved. "There can only be porn on the Net," cracked Steven Aftergood of the Federation of American Scientists' Government & Secrecy Project, in a discussion on the Pentagon's attitude. Another Crypt Newsletter reader who has worked on DoD computer security projects was equally bemused. "Having recently been on the inside of said besieged service, I can recall only three potential attacks in 18 months . . . Hardly an epidemic," the Crypt News reader and infosec expert writes. "Besides . . . pulling all Army web sites down did absolutely nothing to reduce vulnerabilities to terrorist or hacker attacks. Consider: most of these sites were hosted by unit members on their private ISP accounts. If some 'Carlos the Jackal'-wannabe hacked his way into a unit's home page, all he was likely to do was annoy SpryNet or MindSpring or AOL . . . for about ten minutes. The Western world's defenses wouldn't exactly crumble under such an onslaught. "Do any of these chicken-littles EVER recount their grossly exaggerated testimony?" CIH VIRUS COAT-TAILS ON MELISSA INTEREST Chen Ing-hau, a former Taiwan college student, was detained by authorities in that nation after his school, the Tatung Institute of Technology, outed him as the author of the CIH computer virus. Ing-hau (his initials are "CIH," get it?) was reprimanded by school authorities in 1998, who knew about him as far back as April of that year, when CIH virus first emerged in world circulation. Although news stories about CIH circled the globe at the time, much like the current crop of news pieces, apparently few were interested enough to actually dig him up. In a news story distributed by the Associated Press on April 30, Ing-hau claimed he had "created" CIH to "humiliate and take revenge on . . . incompetent anti-virus software providers." The claim, a rather shopworn one among virus authors for the greater part of the decade, has been repeated so often in the virus underground as a rationalization for spreading the programs that even people who don't write viruses are often familiar with it. According to the Associated Press, Ing-hau created CIH because he was also irate that he had been a victim of computer viruses as a result of his trafficking in computer games. Ing-hau's claims, in addition to being unintentionally hilarious, paint a picture of someone completely unaware of his own hypocrisy. Rod Fewster, an Australian anti-virus expert commented in Crypt Newsletter 50 from August 1998 that the CIH virus was put into the wild by uploading infected copies to Gamerz sites -- legitimate and underground -- disguised as various software cracks and cheats and to pirated software sites as a phony serial number crack for the Windows98 beta. In June of 1998, after computer game fetishists and software pirates had downloaded CIH contaminated software, one of the biggest gaming sites on the Net posted a warning about the infected downloads along with an URL pointing to an anti-virus software program that detected and removed it. At the time, places that had infections seemed to have been predominantly universities where a student was using school computers and network time to satisfy his taste for pirated software or trivial computer games he couldn't afford in the store. "I had it on a university in the Netherlands," commented Fewster, adding it had spread very quickly in this environment. Ing-hau, apparently something of a PC game pirate himself, and angered over getting new computer viruses from downloaded games, wrote his own virus that was immediately seeded into the same types of sites he had been victimized from. In a simple stroke, CIH's author had made himself into that which he hated. Wire service news reports claimed Ing-hau had not been severely disciplined in April of 1998 because he had "warned fellow students not to spread the virus." Can you smell the burning odor of phlogiston? In America, CIH, just like most year-old viruses for which detection routines exist, proved to be a bust despite widespread mainstream media attention. The Associated Press reported a measly four site infections on thirty computers by mid-day of CIH high noon on Monday, April 26. Gossip on the Usenet put the figure considerably higher. Also overheard: Carey Nachenberg of Symantec reporting a couple of cases but many, many more telephone calls of concern as a consequence of media exposure. And ATLAS-T's author, Nick Brown, reported to Crypt News a couple of hits near Strasbourg on the 26th, owners of which fit the Western CIH victim: student warez-fetishists. However, Taiwanese authorities seemed nothing but bewildered after detaining Chen Ing-hau as a result of media attention and subsequently finding there were no initial complaints of damage against him. Astonishingly high figures of CIH's damage were circulated in the media: 600,000 dinged computers -- reportedly in Asia -- being the most widely reprinted. The figure was supplied by a collection of assumptions: 360,000 in China, 240,000 in South Korea. But none in Taiwan by the same types of news reports. Of this, Rob Rosenberger of Virus Myths wryly said: "Yeah, the numbers come from some bureaucratic assistant minister(s) for technology who 'speculated' on the total number of PCs destroyed in his ho-dink [Asian] country. We'll never know the magic equation used to calculate the arbitrary value . . . It'll go down in urban legends as a media-spouted, government-approved figure, just like the 250,000 hacker attacks on Department of Defense per year . . ." SOME REFLECTION ON MAINSTREAM REPORTING ON COMPUTER VIRUSES During the week leading up to the activation of the CIH virus, Crypt Newsletter fielded a number of telephone calls from journalists doing the usual pro forma computer virus story. And the discussions got Crypt Newsletter thinking about the practical utility of virus warnings. Mainstream media virus warnings don't serve much purpose to people who actually work with computer viruses. For the most part, they know the score well before the media does. In addition, while articles about computer virus outbreaks can sometimes be diverting reading, for a growing cadre of Internet users they don't do any good. Here's why: If one has spent any time at all hanging around anti-virus chat forums on the Net it's hard to miss the growing number of users who, even if given current anti-virus software, cannot figure out how to use it on a clean system, much less one infected by a computer virus. The phenomenon is similar to the case of the flat tire in American society. Despite the fact that almost every car comes with a spare, a jack, a tire iron and the instructions for changing a flat, a significant number of Americans _cannot_ or _are afraid to_ change a tire without the assistance of someone from the local garage or a good Samaritan passerby. We've been in the same position re computer viruses for some time, too. Even with anti-virus software, a fair number of people who have machine's infected by a computer virus are completely unable to remove the virus. They must summon qualified help or depend upon some good fellow they know to do the job for them. For this population, virus alarms in the media serve no practical purpose and aren't particularly educational. If their number comes up and they get infected in some manner, they will have to get someone else to bail them out of it, whether anti-virus software is present or not. If they never see a virus, the warnings don't matter because whatever anti-virus software is present is either not installed or incomprehensible. On the other hand, some in the same group can be counted on to waste time warning everyone they can reach about the current virus emergency, who -- more often than not -- are in the same boat as they. HOW NOT TO GO VIRUS-HUNTING As some readers may suspect, Crypt Newsletter gets a fair amount of mail composed by idiots. Most of it passes into the electronic dustbin but every once in a while something comes through so profoundly screwed up in some way, Crypt News is moved to share it. While CN has always been fond of the succinct put-down like: "Your [sic] weird, dude..." "Les Haines," from somewhere in Australia, perhaps returning to the school library computer kiosk after a few too many lagers at the pub, wrote: "Hi ,I am Les haines [sic], Clinton Haines was my son. I am looking to obtain any works he may have written whilst he was wandering through cyberspace. Any help would be appreciated." But first, a little history. Clinton Haines was a famous Australian virus-writer who died of a heroin overdose while a college student a couple of years ago. By "works," our "Les haines" means "send me viruses." However, any would-be virus-collector probably should not reveal that he does not actually know what a computer virus is. Unknown to "Les," his system was infected by a common piece of replicating software called Happy99. Happy99 has been in world circulation in recent months and attempts to spread itself by looking at an infected user's outgoing electronic mail and forwarding itself as a file attachment to the same address. And Crypt Newsletter had received a copy of Happy99 accompanying "Les'" request for computer viruses. I politely informed "Les" he should find someone to rid his PC of Happy99 and then reassess his approach to virus collection. Here is what he had to say: "thanks for your virus warning . I am in the process of cleaning the system." ------------------------------------------------------------- Acknowledgments: Electronic clippings courtesy of David Isenberg and Steven Aftergood to whom the Crypt Newsletter is mighty obliged. ------------------------------------------------------------- George Smith, Ph.D., edits the Crypt Newsletter from Pasadena, CA. copyright 1999 Crypt Newsletter. All rights reserved.