Contact Form

Name

Email *

Message *

Showing posts with label linkedin. Show all posts
Showing posts with label linkedin. Show all posts

Thursday, May 29, 2014

Want To Know About NSA Programs, Go To Linkedin And Scan The Resumes! It's All There. Where Is Compliance At The Agency?

TECHNOLOGY

NSA CONTRACTORS USE LINKEDIN PROFILES TO CASH IN ON NATIONAL SECURITY

MARCIO JOSE SANCHEZ/AP
Employees and job seekers share surprisingly revealing spy project names in public posts on professional networking site
NSA spies need jobs, too. And that is why many covert programs could be hiding in plain sight.
Job websites such as LinkedIn and Indeed.com contain hundreds of profiles that reference classified NSA efforts, posted by everyone from career government employees to low-level IT workers who served in Iraq or Afghanistan. They offer a rare glimpse into the intelligence community's projects and how they operate. Now some researchers are using the same kinds of big-data tools employed by the NSA to scrape public LinkedIn profiles for classified programs. But the presence of so much classified information in public view raises serious concerns about security — and about the intelligence industry as a whole.
“I’ve spent the past couple of years searching LinkedIn profiles for NSA programs,” said Christopher Soghoian, the principal technologist with the American Civil Liberties Union’s Speech, Privacy and Technology Project.
After The Washington Post revealed details about the NSA’s Marina, Mainway and Nucleon databases on June 15, 2013, Soghoian tweeted out the results of one such LinkedIn search.
Many responses linked to profiles that listed ever more NSA programs. Soghoian’s tweet also prompted short posts at TechDirt, Gizmodo and Slashdot.
On Aug. 3, The Wall Street Journal published a story about the FBI’s growing use of hacking to monitor suspects, based on information Soghoian provided. The next day, Soghoian spoke at the Defcon hacking conference about how he uncovered the existence of the FBI’s hacking team, known as the Remote Operations Unit (ROU), using the LinkedIn profiles of two employees at James Bimen Associates, with which the FBI contracts for hacking operations.
“Had it not been for the sloppy actions of a few contractors updating their LinkedIn profiles, we would have never known about this,” Soghoian said in his Defcon talk. Those two contractors were not the only ones being sloppy.
The LinkedIn profile cited by Soghoian’s initial tweet mentions classified NSA programs like Nucleon, Dishfire, Octave, Pinwale, Mainway, Banyan and Marina. These were mentioned alongside one program that wasrevealed in the press only a month later: Trafficthief, a database for storing metadata from specific surveillance targets. Another profile, from Indeed.com, mentions Cultweave, XKeyscore and other previously unidentified programs.
And there are many more. A quick search of Indeed.com using three code names unlikely to return false positives — Dishfire, XKeyscore and Pinwale — turned up 323 résumés. The same search on LinkedIn turned up 48 profiles mentioning Dishfire, 18 mentioning XKeyscore and 74 mentioning Pinwale. Almost all these people appear to work in the intelligence industry.

Network-mapping the data

Fabio Pietrosanti of the Hermes Center for Transparency and Digital Human Rights noticed all the code names on LinkedIn last December. While sitting with M.C. McGrath at the Chaos Communication Congress in Hamburg, Germany, Pietrosanti began searching the website for classified program names — and getting serious results. McGrath was already developing Transparency Toolkit, a Web application for investigative research, and knew he could improve on Pietrosanti’s off-the-cuff methods.
“I was, like, huh, maybe there’s more we can do with this — actually get a list of all these profiles that have these results and use that to analyze the structure of which companies are helping with which programs, which people are helping with which programs, try to figure out in what capacity, and learn more about things that we might not know about,” McGrath said.
He set up a computer program called a scraper to search LinkedIn for public profiles that mention known NSA programs, contractors or jargon — such as SIGINT, the agency’s term for “signals intelligence” gleaned from intercepted communications. Once the scraper found the name of an NSA program, it searched nearby for other words in all caps. That allowed McGrath to find the names of unknown programs, too.
Once McGrath had the raw data — thousands of profiles in all, with 70 to 80 different program names — he created a network graph that showed the relationships between specific government agencies, contractors and intelligence programs. Of course, the data are limited to what people are posting on their LinkedIn profiles. Still, the network graph gives a sense of which contractors work on several NSA programs, which ones work on just one or two, and even which programs military units in Iraq and Afghanistan are using. And that is just the beginning.
Dishfire network map
Click on the image to view an interactive network illustration of the relationships between specific national security surveillance programs in red, and government organizations or private contractors in blue.
“People mention the level of security clearance they have, so it’s possible to learn the security clearance you need for some of these programs based on this data,” McGrath said. “You can also uncover new program names. Someone found [a program] called Blackmagik … even if you just have a [program] name, you could use it to determine information about the content — where they're based, what language skills they have, just generally to better understand these things that we have very little information about.”
Intelligence contractors and military personnel have been referencing classified programs on sites like LinkedIn and Indeed for years, but the obscure code names — like Mainway, Dishfire and Pinwale — did not mean much outside of the intelligence community. What little the public did know tended to circulate among a small, wonky group of national security journalists, researchers and privacy advocates. Edward Snowden changed all that, leaking documents that revealed dozens of previously unknown programs in great detail.
“Before, they were just these code names, and we really didn't know what any of them were,” McGrath said. “Now that we know how they operate, we can start to figure things out a little bit more.”
NSA personnel often make that easier by grouping similar programs together, Soghoian said.
“They’ll have all the telephone metadata programs in one place, all the geo-location programs in another,” he said. “So if you know what one thing is, you can figure the others out.”
Before, they were just these code names, and we really didn’t know what any of them were. Now that we know how they operate, we can start to figure things out a little bit more.
M.C. McGrath
Transparency Toolkit
It is hard to say how worrisome this is for the intelligence community.
NSA spokeswoman Marci Green Miller said the agency requires all current and former personnel — including contractors and military members — to submit for prepublication review “any information intended for public disclosure which is or may be based on protected information while associated with NSA/CSS [Central Security Service].”
But Miller did not respond to a question about whether the NSA has reviewed or cleared any of the numerous LinkedIn and Indeed profiles that reference classified programs. She also did not respond to questions about whether the NSA monitors these sites for violations of its policies, or whether it has ever contacted individuals about profiles that reference classified information. LinkedIn and Indeed both declined to comment on the specific issue.

Contractors’ self-interest

Still, even some privacy advocates are surprised at how much information intelligence contractors are willing to publicly reveal.
“Defense Department and intelligence agency contractors say probably more than they should about what they’re doing on LinkedIn because they want to get a job,” Soghoian said. “It’s the self-interest of these contractors versus the national security interest of the state.”
According to Tim Shorrock, author of “Spies for Hire: The Secret World of Intelligence Outsourcing,” websites like LinkedIn and Indeed are not even the worst offenders. Contractors regularly post public job announcements that mention details of classified programs. They even disclose classified information to potential investors.
“There’s no control over what the contractors list in their job applications. They should have some oversight and some better rules about it, but you find this stuff all the time,” Shorrock said. “When I was researching my book, I went to numerous dog-and-pony shows for investors … They'll say, ‘This program was developed by the National Security Agency.’ Then you’ll look it up and see that in the past it’s never been associated with the National Security Agency. Basically, it's bravado, hubris.”
There’s no control over what the contractors list in their job applications. They should have some oversight and some better rules about it, but you find this stuff all the time.
Tim Shorrock
Intelligence commentator
That boasting appears driven by the intelligence community’s heavy dependence on contractors, the high rate of turnover among agencies and their staff, and the amount of money backing the intelligence industry.
“It's constant movement. People get to a senior position in a contractor, and they decide to form their own company,” Shorrock said. “It’s no longer a revolving door; it’s a spinning door. People leave, they come back, they go back to government, they go back to the private sector.”
The number of contractors began to climb in 2001 with the Bush administration’s overall emphasis on privatization and outsourcing, Shorrock said.
After 9/11, it skyrocketed. At least 452,102 contractors had top-secret access as of October 2013, with another 45,581 cleared for access, according to the Office of the Director of National Intelligence’s 2013 Report on Security Clearance Determinations (PDF). That means almost 60 percent of people with a top-secret clearance are contractors — and that number does not include an additional 180,185 people whom the report does not categorize by personnel type.
Shorrock said 70 percent of the U.S. intelligence budget ends up in the hands of private defense contractors. So it is little wonder that intelligence personnel are scrambling to get in on the cut — even if that means being less than discreet when pitching to potential employers.
“There are millionaires all over the northern Virginia and Maryland areas who have gotten rich,” Shorrock said, “by cashing in on national security.”

Tuesday, October 22, 2013

The ObamaCrapCare Plan--Hide The Truth, Promote the Lies And Move Toward Medicare For Everyone

Expensive Obamacare Website Crashed Purposely, To Hide Expensive Obamacare Plans

October 22, 2013 by  
Expensive Obamacare Website Crashed Purposely, To Hide Expensive Obamacare Plans
PHOTOS.COM
Conservative estimates of the amount of taxpayer dollars spent on President Barack Obama’s glitch-ridden healthcare exchange website place its cost somewhere in the range of $500 million.
According to figures from the Government Accountability Office, nearly $394 million from fiscal year 2010 through March 2013 was spent on contracts to build the “federally facilitated exchanges.” An estimated additional $150 million has been spent on administrative costs associated with the implementation of the Affordable Care Act.
By comparison, here’s what similar investments have garnered in the private tech industry in the United States, according to an assessment by Digital Trends:
  • After receiving an initial round of investment in June 2004, Facebook grew and improved until 2010 without spending $500 million.
  • Twitter operated with $360.17 million in funding from 2006 until 2011, when it received an additional $400 million in funding.
  • Before being bought by Facebook for $1 billion, the wildly popular photo sharing company Instagram operated with just $57.5 million in funding from 2010 to 2012.
  • Linkedin, the preferred social network of business professionals, has raised only $200 million in funding.
Facebook has more than 1 billion active users. Twitter handles more than 340 million tweets each day. On any given day, more than 7.3 million people might be active on Instagram. And Linkedin is helping more than 225 million professionals throughout the world network at the moment.
Obama’s online health insurance exchange, after being online for just more than two weeks, is falling apart. And while it may seem natural for glitches to be part of the initial rollout process, reports indicate that the Obamacare website is rife with problems that are much more serious than a few lines of errant computer code.
On Monday, The New York Times reported that up to 5 million lines of coding could need to be rewritten in order to improve the Obamacare enrollment system to the point that users can actually make it through the enrollment process. The Department of Health and Human Services (HHS) said over the weekend it was bringing in “some of the best and brightest” to fix the website. But the job may not be finished in time for uninsured Americans to sign up for health insurance in time to comply with the Affordable Care Act’s individual mandate.
“Administration officials approached the contractors last week to see if they could perform the necessary repairs and reboot the system by Nov. 1,” the Times report said. “However, that goal struck many contractors as unrealistic, at least for major components of the system.
“Some specialists working on the project said the online system required such extensive repairs that it might not operate smoothly until after the Dec. 15 deadline for people to sign up for coverage starting in January, although that view is not universally shared.”
Even once the surface problems are repaired, one expert told the Times, other malfunctions are certain to become apparent.
The President assured Americans in a speech from the White House Rose Garden on Monday: “Nobody’s madder than me about the fact that the website isn’t working as well as it should, which means it’s going to get fixed.”
Flocked by what the White House described as a group of people who “have either benefited from the health care law already or are helping consumers learn about what the law means for them and how they can get covered,” Obama went on the say that the website failures are not representative of the Affordable Care Act’s overall effect.
“The essence of the law, the health insurance that’s available to people, is working just fine,” Obama said.
But, some observers believe that the President is lying.
Writing for Forbes, Senior Fellow at the Manhattan Institute for Policy Research Avik Roy, posited earlier in the month that part of the reason the healthcare exchange website is so dysfunctional is related to a lack of transparency over the massive healthcare cost increases that accompany Obamacare.
Roy wrote: “Healthcare.gov forces you to create an account and enter detailed personal information before you can start shopping. This, in turn, creates a massive traffic bottleneck, as the government verifies your information and decides whether or not you’re eligible for subsidies. HHS bureaucrats knew this would make the website run more slowly. But they were more afraid that letting people see the underlying cost of Obamacare’s insurance plans would scare people away.”
Later in the article he continued: “A Manhattan Institute analysis I helped conduct found that, on average, the cheapest plan offered in a given state, under Obamacare, will be 99 percent more expensive for men, and 62 percent more expensive for women, than the cheapest plan offered under the old system. And those disparities are even wider for healthy people.
“That raises an obvious question. If 50 million people are uninsured today, mainly because insurance is too expensive, why is it better to make coverage even costlier?”
In short, the White House likely knew that its health insurance exchange websites would crash once opened. It has even been suggested that Administration officials were repeatedly warned by IT experts that the bottleneck created by making Americans sign in and provide mountains of information before getting to see the actual cost of the Obamacare plans would crash the site. But, it seems, the President and his Administration officials made the determination that criticism over a broken website was better than the alternative of not hiding the prices, thereby revealing that, for the average American, the Affordable Care Act is anything but affordable.