CRYPT NEWSLETTER 58 November 1999 Editor: George Smith, Ph.D. INTERNET: 70743.1711@compuserve.com crypt@sun.soci.niu.edu http://www.soci.niu.edu/~crypt Mail to: Crypt Newsletter 1635 Wagner St. Pasadena, CA 91106 ph: 626-568-1748 THE MEN WHO PROTECT AMERICA FROM CYBERTERROR: Volumes of smoke but little fire continue to be hallmarks of media coverage and government spin on cyberwar threat during last quarter of 1999. Rather predictably, the accumulation of "electronic Pearl Harbor" -- or EPH -- stories continues to accelerate as we approach the New Year. And if you don't read them with your sense of humor close at hand they become rather depressing in their imbalance and identical paranoid tone. In this regard, they are similar to Y2K stories dating from about a year ago when all that could be heard, viewed or read was a staggering series of anecdotes on how a variety of services and machines would fail catastrophically on the coming of the New Year. Four salient features exist in almost every single EPH piece seen in the mainstream media in the last quarter of 1999. 1. Obsession with hypotheses about what might happen -- -- not what has happened. 2. Rafts of generally insignificant computer security incidents accumulated as anecdotal evidence and delivered in out-of-context or exaggerated manner with the implication that something awful is about to transpire -- today, tomorrow, a month from now, a year from now, two years from now . . . always in the not easily glimpsed future. 3. Abuse of anonymous sourcing and slavish devotion to secrecy. All EPH stories usually contain a number of "anonymoids" -- from the Pentagon, the White House, Congressional staff, computer security firms, intelligence agencies, think tanks or unspecified consulting firms. Frequently the anonymoid will allude to even more secret and terrible things which cannot be mentioned in print or the Republic will crumble. The anonymoid will never reveal anything that extends beyond the equivalent of hearsay, opinion or happenings unverifiable by independent party. 4. Paranoid gossip -- the equivalent of which is offered up as still further proof the nation is in electronic danger. Russia, China, France, India, Israel . . . almost any country not-USA can or is portrayed as taking electronic aim at the American way of life. Programmers of foreign decent or mixed American-foreign decent are tarred as potential cybersaboteurs simply because they _are_ foreigners in a ritual of modern techno-McCarthyism. Teenagers are transformed into electronic bogeymen with more power at their fingertips than the Strategic Command. The allegations tend to be delivered by anonymous sources or "experts" not required to provide substantive examples backing up the gossip for the print journalists acting as their stenographers. Quite a few interesting examples appeared in the mainstream media since our last correspondence, not least of which was an Associated Press piece featuring National Security Council member Richard Clarke. On November 4, the AP published "US Said Vulnerable to Cyber Attacks" in which Clarke continued his obsession with hypothetical electronic doomsdays, a one-note tune he has been whistling ever since the Clinton administration unleashed him on the subject of cyber-terror in late 1998. ``We could wake one morning and find a city, or a sector of the country, or the whole country have an electric power problem, a transportation problem or a telecommunication problem because there was a surprise attack using information warfare,'' said Clarke for AP. In the AP feature, Clarke "compared the reliance [on computer networks] to former drug addicts enrolled in a recovery program." ``We need to take a lesson from that -- at least they know they have a dependency problem. Many of you are still in denial.'' Then the story took aim at foreign programmers: "[Clarke] said [programmers] hired to make a company's computer system Y2K compliant could easily slip `a little Trojan horse or malicious code' into the system instead." ``We expect that (terrorists) will attempt to use Y2K as a cover for putting some kind of attack into a vulnerable place . . . That is, when a Y2K solution goes in, they will fly underneath that with an attack of their own that will shut the system down . . . " echoed Utah Republican Senator Bob Bennett at a National Press Club event. The development of casting suspicion upon foreign programmers bears repeat scrutiny because it was given extra fuel in September by a report insinuating the same were installing trapdoors under the cover of Y2K remediation by National Infrastructure Protection Center analyst Terrill Maynard. Maynard's bibliographic citations recorded _no_ direct instances of any such sabotage but his analysis nevertheless maintained that Y2K remediation programmers, primarily those from India and Israel, could be engaged in installing boobytraps in American systems. Crypt Newsletter then undertook a comprehensive media survey to late 1998 on the topic and found only that documented evidence on sabotage under the cover of Y2K was extremely thin. That is, it found ZERO documented cases of such. The search did net statements like this: "We've discovered bugs and backdoors being put in software from remediation efforts from foreign nationals . . ." --No examples given, Mark Gembicki, head of a small computer security consulting company called WarRoom Research, on October 24, in "Some Fear Sabotage by Y2K Consultants" in the Los Angeles Times. Gembicki "declined to specify whose systems were involved." "Michael Vatis of the [NIPC], the top U.S. `cybercop,' warned . . . that changes to computer software that might threaten security could have been planted by foreign contractors under the guise of Year 2000 bug fixes." --No examples given, Reuters, October 7, "Y2K seen as possible cover for Cyberwars." "[Terrill Maynard] calls Israel and India the key suspects for planting software backdoors in American systems . . . Maynard claims Israel has already hacked its way into U.S. computer systems to steal information about the Patriot missile." --No examples given, no substantiating material on Patriot missile information theft provided, Terrill Maynard, paraphrased at a computer security conference, in "Threat of 'infowar' brings CIA warnings," September 15, Network World. "[Science Applications International Corporation's] Constance Fortune said the programmers handling the heavy amounts of programming to fix Y2K problems may have left 'backdoor' openings for hackers to enter." --No examples given, in NetTrends, August 31, distributed by Reuters. "There is proof the Mafia was backing hackers posing as year 2000 programmers." --Proof not forthcoming, Matthew Bevan, ex-hacker of DoD Air Force systems posing as computer security consultant, August 25, in "Millennium hackers plan City of London assault," Network News, VNU Business Publications. "The Y2K bug had created a diversion large enough for cyberterrorists to wreak more havoc on the world's computer systems than any computer virus, a computer security conference [in Brisbane] was told today." --No examples given, Science Applications International Corporation marketing rep Constance Fortune, June 15, in "Y2K problem opens door for cybercrime," in the Australian AP. "We have seen multiple times where Y2K activity has resulted in trap doors being placed in commercial systems." --No examples given, Duane Andrews, Science Applications International Corporation, USA Today, ca. November 1998. Anonymous sources also tend to check in with their two cents, to the same effect: " 'We think there's a vulnerability' to such nefarious activity, said an official of the White House National Security Council who focuses on cyber-terrorism. 'That doesn't mean we know any malicious code was inserted.'" -- October 24, the Los Angeles Times. Another hallmark of the current surge in EPH reporting is the repetition in the delivery of received wisdoms. In this respect, it is not unreasonable to regard them as a consequence of a clumsy propaganda campaign run by the Pentagon and the Clinton administration's "cyber-terror" experts. In October, Eligible Receiver -- the Pentagon's secret wargame that allegedly "proved" electronic hackers could lay low the nation in 1997 -- was reinvented as Zenith Star. Again and again, the fetish centered around the hypothetical turning off of the electricity and/or telephone service appears. For example, "For two days, [officials from the NSA, CIA, FBI and DoD] huddled behind closed doors to test America's response to a simulated surprise attack by electronic evildoers [in Zenith Star] . . . enemy hackers supposedly had triggered blackouts around major military facilities . . . They paralyzed 911 emergency response systems . . . Then they started disrupting crucial Pentagon computer networks." --"US Scurries to Erect Cyber-Defense," October 31, the Los Angeles Times. "In [Eligible Receiver], a team of NSA hackers proved that they could easily disable power, telephones . . . as well as Pentagon warfighting capabilities." -- Ibid. In EPH stories, the word "proved" also takes on new meaning. If your definition of "proved" is restricted to "demonstrated by a reproducible public testing process," EPH stories become confusing. In EPH news, the standard of "proof" is quite different, equivalent to "a fantastic but undemonstrated claim, often passed along by employees of the Pentagon or the National Security Council." To wit, a couple of average examples: "The Pentagon reckons that last year [1998] the Taiwanese spread two viruses, known as the Bloody 6/4 and Michelangelo . . . They damaged some 360,000 computers in China, at a cost of $120 million." [1] --from The Economist, in "Asia's lethal computers," an editorial which coupled the fear of Auslanders to the "cyberterror" topic, October 30. "[Info-war] is not benign. It can potentially be very, very deadly." --attributed to Michael Swetnam, "a CIA veteran and consultant to the White House and Senate" from "US Opened Cyber-War During Kosovo Fight," distributed by Scripps Howard on October 24. The previous quote, predictably, is referenced only by the "proof" of Eligible Receiver. "[Civilians will suffer] as a result of the cyber-targeting of . . . a power grid . . ." Another glaring facet of EPH stories is the not uncommon presence of representatives of national security organs making what would appear to be amusingly incompatible or hypocritical statements. Crypt Newsletter asks its readers to review, for example, more recent quote on EPH, starting with the following blurb from the National Security Council's Jeffrey Hunker: "[The term Electronic Peal Harbor] connotes this 'lights-out' idea," said Jeffrey Hunker for Defense Information & Electronic Report magazine on October 22. "It tends to oversimplify the threat, which ranges from existential terrorism to overt acts to overthrow the military. . . . It trivializes the real [danger], which I think is much more than what's been understood." >From the Los Angeles Times on October 31, attributed to CIA director George Tenet: "Potential targets are not only government computers but the lifelines we all take for granted -- our power grids and our water and transportation systems." Again, from the LA Times, attribution by way of the Pentagon's John Campbell of the Zenith Star "operation" -- "enemy hackers supposedly had triggered blackouts . . ." And from Jeffrey Hunker's colleague on the National Security Council, Richard Clarke, in the August issue of Signal magazine: "Envision all of these things happening simultaneously - electricity going out in several major cities; telephones failing . . ." And earlier, from an appearance on February 1 in the New York Times: "I'm talking about people shutting down a city's electricity . . . shutting down 911 systems, shutting down telephone networks and transportation systems. You black out a city, people die. Black out lots of cities, lots of people die." The following statement is taken from the Los Angeles Times on October 24 and is, again, attributed to an "anonymoid," this time from the Clinton White House: "There's a lot of silly talk out there" -- this with regards to the alleged threat of foreign Y2K programmers sabotaging American systems. And the next material is taken from an interview with the White House's Richard Clarke, again from the August issue of Signal magazine: "It is at least theoretically possible that a nation could insert such trapdoors, and then make demands of the United States under threat to our infrastructure . . . I think the capability to do that probably exists in the hands of several nations . . . I think it could exist in the near future in the hands of criminal and terrorist organizations." In conclusion, I leave you with another piquant citation, one with -- perhaps -- a great deal of meaning with regards to the current dissemination of talk of cyberterror in the media. It comes from the New York Times, in its previously mentioned February 1, 1999 piece on Richard Clarke, "The Man Who Protects America From Terrorism." "Clarke's profile first surfaced in 1986," reads the Times. "He was an intellectual author of a plan to use psychological warfare against the Libyan leader, Moammar Gadhafi. Under his plan, flights of SR-71 spy planes set off 'sonic booms over [Gadhafi's] head, to tell him his air defenses couldn't stop us' . . . The operation backfired when the Reagan White House was caught planting a false report in The Wall Street Journal about Libya's support of terrorism." ======================================= Notes: 1. CN has no idea where this wild-ass "Pentagon" quote in The Economist came from but it can tell its readers that the idea of using the Michelangelo and Bloody computer viruses in a "cyberwar" in 1998 is absurd. Neither virus, for example, is spread on the Internet or by networked computer connections. Both are *very old* boot sector computer viruses -- infectious programs that add themselves to the system sectors of diskettes, floppies and a PC's hard disk. They are -- or rather more accurately -- *were* spread in the first years of the decade by exchange of infected floppy disks. Both have long been essentially extinct on western computers. The idea that one could have a "cyberwar" in which the enemies throw virus-infected diskettes back and forth at one another in the wishful hope that the mass effect might cause something bad to transpire illustrates only the rather quaint technical ignorance about computer viruses in those who would believe the claim. AN OPEN LETTER TO MICHAEL VATIS, RICHARD CLARKE AND COLLEAGUES Dear Sirs: Your concern that foreign programmers have been inserting trapdoors and malicious code into the nation's software has not gone unnoticed at Crypt Newsletter. Since you obviously feel that it has great bearing upon the security of the nation's infrastructure, Crypt Newsletter challenges you to broaden your investigative work on the matter. Because this is such an important issue, you will, of course, wish to carefully examine the Microsoft model for programming currently in use for that company's Word, Internet Explorer, Outlook and related programs. All of these programs contain application code functions embedded in areas formerly reserved in computing only for data. The most common example: simple documents are never just "electronic paper," anymore (and they haven't been for some time), under the Microsoft plan. They are frequently redistributed programs which can directly manipulate a computing environment. And for real purposes, most people who use computers have no real idea where this code resides, let alone what it does. These embedded code functions are used as a strong marketing feature for Microsoft products. Paradoxically, many of these functions serve no particularly indispensable purpose to the average user although they have proven exceptionally useful to virus-writers and other garden-variety types of malicious programmers, both domestic and foreign, internal and external. Currently, almost ninety percent of all computer viruses found in circulation on the nation's computers take advantage of these embedded code functions. In fact, it would not be reaching to say that Microsoft's programming in this area has been directly responsible for the growth in their numbers. >From the standpoint of the average user, these viruses and related malicious software agents exploit pre-installed programming trapdoors in Microsoft code to produce many well-documented, unauthorized functions on the nation's networked computer systems including, but not limited to: *corruption of data *denial of service *seizure and export of private information *and system crashes. Microsoft code can easily be found in use in many of the nooks and crannies of the national infrastructure. On the other hand, it's also in use in the nooks and crannies of the networks of allies and enemies. Just as you have done with your analysis of Y2K programmers, you will wish to examine in detail what implications this has for national security. You should also feel free to make recommendations that might augment and/or strengthen national security with regards to such programming. You will find this analysis much easier to conduct than your exposes on saboteur Y2K programmers. Microsoft documents much of its code in this area and the company can be visited. You can actually interview programmers and explore their motivations while conducting your research -- all under the rubric of improving national security. You will not have to rely upon unproven theories, hearsay or secondary reports in the mainstream media. Your experts will find they can actually lay their hands upon examples of malicious code, look over the Microsoft code used by malicious remote agents, and trace where it has gone into the nation's software as well as when and how it has been exploited. In one respect, though, you will find this analysis more fraught with potential difficulty. Unlike nebulous Y2K programmers who cannot protest the potential besmirching of reputations, Microsoft has a not inconsiderable legal and promotional presence. And, as you well know, this presence acts aggressively and forcefully against outsiders considered to be involved in any action that might be construed as "negative" with regards to its products. You will doubtless wish to have the analysis well-lawyered at the National Security Council and National Infrastructure Protection Center prior to publication. Yours in our mutual desire for a more secure nation, Crypt Newsletter CYBERWAR IN BELGIUM! -or- THE EMPTY-HEADED BLOWHARD: Threat or Menace? Readers may recall mention of the Euro-hacker who had sucked Reuters into believing he was going to turn off the power in Belgium between the hours of 1 and 3:30 in the afternoon in our last issue. CN has said again and again that the best thing about cyberwar is that it's not even necessary to actually have one. It's quite sufficient to find an editorial organ stupid or irresponsible enough to take unsubstantiated terroristic threats issued by teenagers and send them worldwide. On September 30, Reuters published in follow-up, "Hacker backs down from Belgium power threat." "ReDaTtAcK 2 has ended his campaign to shut down power in Belgium," read the Reuters missive. ------------------------------------------------------------- Acknowledgments: Electronic clippings courtesy of David Isenberg and Steven Aftergood to whom the Crypt Newsletter is mighty obliged. ------------------------------------------------------------- George Smith, Ph.D., edits the Crypt Newsletter from Pasadena, CA. copyright 1999 Crypt Newsletter. All rights reserved. ========= The next piece is another short bit by CN derived from material on Moonlight Maze published in previous issues. It appeared in the premier issue of Privacy Place, a new Net publication devoted to all things privacy-related. Edited by Tom Maddox, Privacy Place features news and viewpoint by Mike Godwin, "Paranoid Paul" and other luminaries. Find it on the Web at www.privacyplace.com . =============================================================== Surely you have noticed the grim dramas playing themselves out in the pages of the mainstream media as we near the end of the year. Time and time again, the prophets -- in this case, the mandarins of national security -- appear to warn that our safety and security are at stake on the Internet and that fantastical threats and intrigue are mounting in the corridors of foreign power. The solutions offered are always depressingly similar. Spend more taxpayer dollars. Give the dollars to the Pentagon or law enforcement, proxies of the Pentagon, and/or consultants offering guidance to the Department of Defense. The dollars are always supposed to be for the creation of new agencies or getting the military involved in domestic law enforcement for the sake of computer security. It's an old story. On my desk I have a study commissioned in 1995 by the Pentagon tabulating the agencies in the continental US that already exist to allegedly perform this task. It's as thick as a phonebook. Once, I started reading off agency acronyms from it for a reporter who had a few questions about such matters. After a while she started laughing. However, for the most part, your average journalist never questions the methods or recommendations of the prophets of national security. The sad truth is that if a few more of the nation's editors had the stones to stand up and laugh at stories about cyberterror, we would probably get fewer stupid recommendations and media eruptions like Moonlight Maze. Moonlight Maze was originally deployed as a scary-sounding prop in March of this year just as budget requests for FY2000 were going before Congress. It was depicted then, as it was again last week, as a concerted attack on American military assets by Russian hackers. (The year before, around the same time, the Pentagon had rolled out another such prop, called Solar Sunrise. It too was originally billed as a concerted attack by Russian hackers. Solar Sunrise turned out to be teenagers from northern California.) However, Moonlight Maze was recycled mostly as a consequence of copycat journalism stemming from a luridly sensational story on it which ran in the London Sunday Times over the summer. One of the piece's more absurd and unsubstantiated claims was that Moonlight Maze "could cause damage to America in excess of that caused by Chinese espionage in nuclear laboratories . . ." The story titillated an assortment of DC journalists over the summer and was helped along by a little pumping courtesy of an anonymous Pentagon source. In September, Newsweek regurgitated what had been published by the London Times. A Congressman read it and brought it up in a committee meeting on terrorism and technology. Then the rest of the media piled on. Typically, there was another thick-witted recommendation aired for a new agency -- "an electronic FEMA" -- to protect us from future Moonlight Mazes. And Moonlight Maze was? Well, the FBI didn't really know but no evidence of damage to US national security has been shown. And since the Russians stood accused, a spokesman for their intelligence service commented it was probably just more "ordinary amateur hackers." An important point illustrated by Moonlight Maze is that the big stories about alleged cyberattacks over the past few years, those used as justification for more snooping or more secret cooperation between the Pentagon and the FBI, almost never result from true investigative reporting. They are mostly products of clumsy exaggeration, lemming-like journalism and Pentagon or law enforcement spin gone out of control. The good news is that many people who use the Internet realize the process is decadent and the game rigged. The bad news is that the people making national policy -- and way too many in the media who act as their seeing-eye dogs -- are not.