Thursday, February 24, 2011

Ahmedinejad's view

The Washington Post should really stop giving Ahmedinejad's shills space to write about the Middle East.

The Leverett's are a couple who used to do foreign policy for the neo-cons but for mysterious (ormore likely banal) reasons suddenly started spouting the Iranian government line in a series of tendentious opinion pieces.

According to the Leveretts, the Iranian elections were not stolen and Iran is poised to emerge more powerful as a regional player as Egypt defects from US control and thus submits to Iran's sphere of influence.

In European terms, this is like suggesting that Germany would be part of the sphere of influence of Ukraine. Egypt has a larger population than Iran, an economy that is diversified beyond oil and controls the Suez canal. In the highly unlikely event that Sunni Egypt would want to form an alliance with Shi'ia Iran under theocratic control, it is clear that Iran, not Egypt would be the junior partner.

While US influence in the region may have declined as a result of the changes of the past four weeks, the only point of having influence is to protect interests. And the interests of the US and the Western world in general are much better served by the spread of democracy than maintaining the rule of kelptocratic dictators.

As the largest remaining police state in the region, the sudden collapse of similar regimes in Egypt, Tunis and Libya must be a concern to the mullahs of Iran. And the process is far from complete. If Bahrain and Yemen fall, the regime in Saudi Arabia is going to come under further pressure. Should Saudi Arabia fall, Iran's system of government will become a glaring anomaly.

Tuesday, February 22, 2011

Shorter Gadhafi

Shorter Gadhafi: Claims in the foreign press that I am murdering opponents of my rule are lies and anyone who believes them is to be murdered. [Talking Points Memo]

Thursday, November 11, 2010

The New Generation of MacBooks...

I was rather surprised by Apple's tagline for the new MacBook Air, 'The New Generation of MacBooks' (Apple - Mac).


As a means of selling MacBooks, fine. But what does it say about their other models?

I have the first generation MBA. It is a great design apart from the design fault on the hinges. But my original plan was to get the 17" model which is great unless you don't mind carting a large, heavy slab of aluminium round with you.

No doubt some of the people who go for the 15 and 17" models really do need the extra performance of a 2.5 GHz processor over 1.8. But some would surely find a smaller machine more than made up for a modest reduction in speed.

Monday, November 08, 2010

Stuxnet: After the hype

By now most readers of this blog will be aware of the now infamous Stuxnet virus that allegedly targeted the Iranian nuclear program, was allegedly written by Israel, Russia, China, the US and Iran itself, had no fewer than 4 zero day attacks, cost over a million dollars to write, but was clearly an amateur job, which succeeded and failed. It has disabled security systems throughout the world and there are no confirmed reports of it breaking anything.

As with many media firestorms, the analysis has tended to run in advance of the facts. And when the facts didn't fit it was the facts that were ignored rather than the analysis.

I have not looked at the Stuxnet code directly, but I have spoken with several experts who have and they all tell me the same story: The code consists of a distribution mechanism and a payload. Both are targeted to a particular group of machines but the distribution mechanism is set to infect particular groups of windows machines while the payload appears to be set to target one very specific installation.

The code appears to have been written in a modular fashion with different attacks being written by different hands. The code is layered and we are not sure that all its secrets have been revealed even now.

As with many high profile attacks, various parties have taken the distribution vector and repackaged it to attack targets of their own choice. Those parties may or may not include the original authors.

The only firm geographic information we have is that the code has employed signed code components signed under two separate code signing certificates, both issued to Taiwanese companies. I think this is a particularly significant piece of evidence since there are not very many code signing certificates in circulation. It is not something a hacker is likely to come across unless they are looking for it. And whoever was looking for the code signing certs was almost certainly able to read Chinese.

That said, the modular nature of the code suggests that the virus was written by many hands. I suspect that the task of writing the code was outsourced to several independent contractors, none of whom would have needed to know the ultimate purpose. They may well have outsourced the task of obtaining code signing certificates to Chinese or Taiwanese hackers to throw investigators off the trail.

Anyone with sufficient money and criminal connections could have written the distribution code. The payload is rather different. It appears to be very closely focused on one single target. This was initially suggested to be the Iranian centrifuge enrichment plant but my sources suggest that the Iranian Bushehr nuclear power plant is a more likely target.

One of the reasons for thinking that the target was Iran was that the Iranians themselves complained about being subjected to a Western cyber attack. Then they suddenly stopped complaining and denied that there had been any impact whatsoever.

Whatever the target was, we are pretty sure that the code did not target any major installation that the operators were willing to admit was the target. It is possible that Stuxnet targeted a European or US plant, but I very much doubt that this could have been kept secret. We are also fairly certain that whoever wrote Stuxnet had a very good reason for wanting to disable the plant, even though this was unlikely to succeed for more than a few months.

This last aspect of the attack makes it very unlikely that Israel or any Western country would be responsible. Whatever the target, it is highly unlikely that any cyber-attack against a well designed control system can achieve more than a temporary denial of service. Whoever wrote the Stuxnet code was revealing that they knew a very great deal about the design of the target. It is not very likely that any intelligence agency would want to put such a valuable strategic asset at risk for the sake of some casual vandalism that would be repaired in a few months.

Even more compelling is the fact that the Bushehr plant is not yet operational. Disabling a running plant is one thing, disabling a plant that is not yet commissioned would require considerably greater and more detailed inside knowledge.

If the target was the Iranian centrifuges, the knowledge could only have come from inside Iran itself. That is not impossible, there is certainly a complex power struggle going on within the regime. But it seems very unlikely.

The Iranian Bushehr reactor seems a much more likely target than the centrifuges. At least two parties had access to detailed knowledge of the plant's design - the Iranians and the Russian's who designed it. It is also possible that there are plants in other countries built to the same design and that a third party could have learnt some of the details from them. I find this unlikely however since respect for Russian nuclear engineering was severely damaged after Chernobyl. Other than the Iranians, it is unlikely that the Russians have had many recent customers.

Why would Russia sabotage a plant they built themselves? Well it used to be standard operating procedure during the days of the Soviet Union. Countries would buy all manner of technology from Russia and then learn that it was not so much an outright purchase so much as a lease. Selling the Iranians a power plant and then sabotaging it to force the Iranians to pay for repairs is the way the Soviet Union did business and is the way that Russia does business today - as European countries buying Russian natural gas have found to their cost.

We certainly do not have conclusive proof, but the Russia theory is the only one that fits all the facts we know and is the best fit to those facts. Russia has built its cyber-warfare capability through an alliance with organized crime, commissioning the deployment code is certainly well within the type of favor that Kremlin-sponsored criminal groups such as the Russian Business Network have performed in the past.  The payload was probably written separately and tested out on an actual Russian power plant with the identical control system - presumably with the plant shutdown or otherwise safe.

In conclusion, the Stuxnet attack appears to me to be a highly professional attack perpetrated by the Russian government on their ally to coerce Iran into agreeing to accept Russia's proposal to reprocess Iranian fuel. This would allow Russia to recoup the cost of the attack through revenues from the reprocessing and would ensure that Iran remained dependent on Russian technology in the future.

Iran agreed to the reprocessing deal in 2005 and then backed out. A few months ago Iran changed course again and agreed to honor their earlier agreement. The Bushehr Nuclear plant began to be loaded with fuel on 21st August and is scheduled to begin generating power in the near future.

Sunday, October 31, 2010

Dalek Halloween


My halloween costume this year. It is a full scale dalek hero prop replica made from fiberglass, aluminium and rubber.

I did not quite manage to finish it on time due to a disaster with the trundling mechanism. The eyepiece is dodgy and dalek aficionados will not the absence of plunger and gun. Given that fitting them requires careful measurement and is a one time thing, I did not want to rush it.

The voice is produced by an authentic Moogerfooger ring modulator as used by the BBC that I bought off EBay. 

Monday, August 30, 2010

Red Cells

What is it about terrorism that makes US Commentators talk nonsense (Washington Post)?

Wikileaks recently obtained a document which asked what should be the rather unsurprising question 'Does the US export terrorism'.

Of course the US exports terrorism, for the simple reason that the US is a rich county with a very large population of second and third generation immigrants who can afford to engage in the irredentist politics of what they imagine to be their homeland.

The UK has the same problem. The causal nexus of the strife in the Punjab that led to the 1984 siege of the Golden Temple in Amritsar was almost entirely located in Birmingham England.

Until September 11, Rudy Giuliani would never pass up an opportunity to attend an IRA fundraiser. But support from New York City flowed to both sides of the sectarian conflict in Ireland, just as they do to both sides of the Israeli/Palestinian issue.

Expatriate irredentists are often the biggest obstacle to a peace process. They fund the conflicts but experience none of the consequences. They collect the money to buy bullets and bombs to murder and maim, but they only every acknowledge the injuries caused against their side. So the expatriates are always the last holdouts.

This is of course known to anyone who specialized in counter-terrorism before 9-11. But since then everyone in the security world has declared themselves an expert in counter-terrorism, most basing their models on the experience of the cold war era when the most visible terrorist groups were state sponsored.

Sunday, August 22, 2010

How an Israeli attack on Iran might proceed.

Glenn Greenwald is engaged in another argument with Jeffrey Goldberg over the latter's article in the Atlantic in which he is very clearly beating a drum for a US war on Iran.

Greenwald initially pointed out that Goldberg had something of a credibility problem given his earlier role in peddling some of the stories used to claim a casus belli for the US invasion of Iraq. Since then it appears that he has caught Goldberg in an outright lie. Even so, Goldberg appears to have been largely successful in framing the debate on war with Iran as to whether the US should attack first or let Israel start the war.

The argument from Goldberg et. al. appears to be that if Israel attacks Iran, Iran will retaliate and that this will force the US to come to Israel's defense following Iran's inevitable retaliation. I find this a rather unlikely scenario as it leaves out of consideration the reaction of China, Russia and US public opinion and the fact that any US response would be constrained by time and logistics.

Planning for wars takes a considerable amount of time. Even if the US was minded to immediately declare war on Iran, it could not do so immediately and the costs of doing so would be rather obvious. The US public would wake up to the possibility of being drawn into a third neo-con war in defense of the country that was unambiguously the aggressor. It is doubtful that a majority of Republicans would support that proposition, let alone Obama's base.

When Obama addressed the nation from the oval office, his only real option would be to call on all sides to accept a cease fire on the basis of a US-Russian-Chinese plan being voted on by the UN security council and look to take credit for saving Israel from its own foolish leaders.

Netanyahu is no fool, he knows that he can't launch an attack against Iran and then go run crying to the US's skirt after the inevitable retaliation. Those are the tactics of cowards and schoolyard bullies. Netanyahu would only launch an attack if he is certain he knows where the nuclear material is and he is certain that Israel would win the inevitable war that would follow. Since only a lunatic would be certain of either proposition the prospects of an Israeli attack on Iran are rather small.

Wednesday, August 11, 2010

BadB and anti-Americanism

Its good to hear that Alleged Carder ‘BadB’ has been busted.

But take a look at his business card and remember that this is a Ukraine/Israeli citizen. Then ask yourself if the people who are doing Internet crime are purely in it for the money.


While the money is certainly a large part of their motivation, there is clearly a nationalist motivation as well. While the fall of the Soviet Empire was considered a very good think in the West, some people in the East were not so happy. And Horohorin, 27 was 8 when the communist system collapsed. He probably does not remember the secret police or the gulags.

It is strange but true that some people find the most bizarre, abominable things imaginable to idolize. When I was in college some students used to love to shock people by declaring their support for General Pinnochet, a man they knew to be responsible for several tens of thousands of murders.

Sunday, July 11, 2010

How to bias a poll

Selection bias free, I am sure.

Take Our Obama Socialism Survey And Receive Free "Impeach Obama" Sticker | The Conservative Caucus

Thursday, July 01, 2010

Spies amongst us

Yesterday I discovered I have been living near to a pair of Russian spies for the past ten years and never noticed. Today we start to discover just how lame those spies were. Shoddy tradecraft, falling for ridiculous ruses, what clowns!

I beg to differ.

Looking at the tradecraft described in the complaints it does not appear to be markedly different from the methods used by the KGB in the Soviet era. Some of the tools had changed, wireless laptops had replaced the old dead drops. But they were using the exact same methods that they had used in the Soviet era when the KGB successfully infiltrated both MI5 and the FBI.

And that for me is the real reason why the Russian spying antics were so pathetic: the times had changed, they had not. Which at root is the whole problem with the Putin crowd and its attempt to turn the clock back to the Breshniev era of 'Stalinism-Lite'.

First off, lets get the terminology right. The spies that were just caught were not agents, they were operatives. That is the field level spy masters. A real life James Bond does not go and steal the information himself, he recruits locals who have already have access to the information to act as agents. The division between operatives and agents is an important one in intelligence work: the agencies will generally do whatever they can to protect operatives, agents are generally considered expendable.

The Russian ten spies did not attempt to burrow into government agencies or perform classified work directly. Their covers were only designed to be good enough to fool immigration and would almost certainly have been exposed in a positive vetting process. To be effective as spies following the old KGB model the Russians would have to recruit agents with access to the information they wanted.

We yet don't know if the spies were successful in recruiting agents, though we may well find out if there are further arrests. While the tools of the operative are money, ideology and blackmail, it is only the last one that is practical with respect to cold-calling in a democratic society. Mercenaries such as Hanssen and Ames are typically walk-ins. They decide they are going to betray their country by themselves and then make contact. The same is typically true of ideologues.

Lets say you are an NSA employee and have been identified as a target by a Russian operative who approaches you with an offer of money in return for secrets. Even if the amount of money on offer is tempting (a million dollars say), the risks are enormous and the approach is very likely to be a trap. The competent traitor knows that they have to reject any unsolicited offers and be the party that makes contact themselves.

This leaves blackmail, which has always been the primary tool of the field operative. An offer of money is likely to be rejected and reported, an offer of money coupled with a threat is much less risky. Later this year the IETF will be holding a meeting in Beijing. As a somewhat senior information security professional I would consider it something of an insult if I was not targeted by a honey-trap operation. A few years back a police raid on an 'Asian massage parlor' in Silicon Valley uncovered hidden cameras in all the rooms. While it is possible that the owner was merely a pervert, many of the clients captured on the tapes would have access to technology that China would very much like to acquire.

In the Soviet era, the KGB could use a very powerful form of blackmail: reprisals against relatives still in their power. Co-operation might mean permission to live in Moscow for a parent or sibling, refusal might mean loss of a job, internal exile or being denied critical medical care.

Putin's modern day spies had much less to work with. The US is a far more open society than it was ten or twenty years ago. Exposure as an adulterer or homosexual might damage personal relationships but is not going to end a career or result in prison unless your job happens to be running an anti-gay bigotry association.

Its not just the tools that have changed, the objectives have as well. Twenty years ago an operative who obtained an internal telephone directory for a government agency would be a hero. Today the information is most likely up on a Web site (and more likely to be up to date). Want a background profile on the new assistant director for widget command? His kids are probably on Facebook, his classmates certainly are.

For the past couple of years I have been attending weekly seminars at MIT on cybernetic aspects of international relations. In a nutshell the Internet is having major effects on national security, diplomacy and the way that wars are fought in future. Russia, China and the US are each attempting to work out what military and foreign policy doctrine is going to be in the Internet age. The MIT/Harvard project funded by the Minerva Institute is looking into these issues.

Isn't this exactly the sort of stuff that Russia would want to send a spy to sit in on? Is it likely that any of them did? Well not if they were illegals unless they wanted to attract quite a bit of attention.

And here we get to the real incompetence of the whole affair. We do not know what the spies may have acquired but the fact that they were allowed to operate, observed for over a decade shows that they probably didn't acquire very much that was damaging. How much more could the Russians have acquired if they had spent the same amount of money on a room full of clerks searching Google?

The Chinese espionage activities leave me equally skeptical. I do not doubt that they exist, the documentation is conclusive. I just think that they are more likely harming the Chinese economy as helping it. As long as China focuses on stealing foreign innovation, development of their own technology base will suffer.

We do not yet know, we may never know the reason that the arrests happened now, but one possibility is that the spies were so incompetent that they were actually hurting US interests. This may sound odd to someone brought up with the notion that being spied on is a bad thing. But in international relations terms there is a real value in transparency. If I do not have anything to hide, I want my adversary to know that I do not have anything to hide. If I stop him from confirming that I have nothing to hide he is going to go off and invent an explanation for my refusal and plan against it. that is going to make his behavior more random (bad) and possibly more aggressive (very bad).

We may never know, but it does not look like the Russian ten were doing much to improve transparency. The Russians probably knew less as a result of their efforts than they would have without them.