The U.S. Nazi dirty bomb plot

Remember how the press was all over the story of the 29-year-old millionaire white supremacist and fan of Adolf Hitler in Maine who was building a dirty bomb that he planned to set off at Obama’s inauguration, but it didn’t happen because his wife shot and killed him? Me neither, but James G. Cummings of Belfast, Maine, had (quoting Wikileaks) “four lots of one gallon containers of bomb-grade hydrogen peroxide, uranium, thorium (also radioactive), lithium metal, thermite, aluminum powder, beryllium (radiation booster), boron, black iron oxide and magnesium ribbon” which he somehow planned to set off at the inauguration. Personally, I don’t think that volume of material could have been easily smuggled in anywhere near the inauguration activities without raising suspicion. Why no press coverage of this story, apart from the Bangor Daily News? Wikileaks has a summary; Wonkette has summarized that; the Washington D.C. Regional Threat and Analysis Center report (PDF) is here. ...

March 15, 2009 · 2 min

PATRIOT Act NSL gag order unconstitutional

For a second time, a U.S. appeals court has found unconstitutional the provision of the USA PATRIOT Act which forbids recipients of National Security Letters from disclosing that they have received them. After the first time around, Congress amended the law to introduce some minimal judicial review, but maintained the burden of proof on the recipient if the government claimed there were national security reasons for the NSL to remain secret. The courts have ruled that this burden needs to fall on the government. If this continues to stand, then perhaps the rsync.net warrant canary will become superfluous.

December 19, 2008 · 1 min

White House may be forced to recover "lost" emails

Lawsuits by the National Security Archive of George Washington University and the watchdog group Citizens for Responsibility and Ethics in Washington (CREW) have won a ruling from a U.S. district court judge that the White House can be forced to recover the five million “lost” emails that were deleted between March 2003 and October 2005. Those emails were required to have been preserved under the Presidential Records Act. Another set of emails from the office of Vice President Dick Cheney from September 30, 2003 to October 6, 2003 were found to be “lost and unrecoverable” by an Office of Administration investigation. 65,000 backup tapes have been preserved as part of the litigation, and those tapes will apparently be available for review to recover some of the five million lost emails. More details at IntelDaily.

November 14, 2008 · 1 min

Criminal activity by air marshals

Looks like the air marshals have a problem similar to the TSA and the Border Patrol: Shawn Nguyen bragged that he could sneak anything past airport security using his top-secret clearance as a federal air marshal. And for months, he smuggled cocaine and drug money onto flights across the country, boasting to an FBI informant that he was "the man with the golden badge." Michael McGowan used his position as an air marshal to lure a young boy to his hotel room, where he showed him child porn, took pictures of him naked and sexually abused him. And when Brian "Cooter" Phelps wanted his ex-wife to disappear, he called a fellow air marshal and tried to hire a hit man nicknamed "the Crucifixer." Since 9/11, more than three dozen federal air marshals have been charged with crimes, and hundreds more have been accused of misconduct, an investigation by ProPublica, a non-profit journalism organization, has found. Cases range from drunken driving and domestic violence to aiding a human-trafficking ring and trying to smuggle explosives from Afghanistan. More details at USA Today. UPDATE (8 March 2015): Another air marshals scandal: What began as an internal investigation into allegations of harassment and threats stemming from a spat between ex-lovers has expanded into a criminal inquiry focused on the Federal Air Marshal Service’s dispatch hub in Herndon, Virginia. More than 60 federal employees are under scrutiny as investigators look into whether flights considered at risk of hijacking or a terrorist attack were left without marshals on board, sources with knowledge of the investigation told Reveal. Historical Comments Sheldon (2008-11-18): Wow! Thats 36 Federal law enforcment officials who had passsed the background checks to fill those positions, and then went bad, some very bad. Pretty scary when you think about it.Thanks. ...

November 14, 2008 · 2 min

Behind the scenes during the election process

Newsweek reports some interesting tidbits from behind the scenes of the election process in both the McCain and Obama campaigns: Both the McCain and Obama campaigns had computers compromised by “a foreign entity or organization [which] sought to gather information on the evolution of both camps’ policy positions.” And that entity was successful in collecting such data, apparently. Palin’s shopping spree was more extensive and expensive than has previously been reported: “While publicly supporting Palin, McCain’s top advisers privately fumed at what they regarded as her outrageous profligacy. One senior aide said that Nicolle Wallace had told Palin to buy three suits for the convention and hire a stylist. But instead, the vice presidential nominee began buying for herself and her family—clothes and accessories from top stores such as Saks Fifth Avenue and Neiman Marcus. According to two knowledgeable sources, a vast majority of the clothes were bought by a wealthy donor, who was shocked when he got the bill. Palin also used low-level staffers to buy some of the clothes on their credit cards.” The spending was allegedly tens of thousands of dollars more than reported. McCain rarely spoke to Palin during the campaign, and although she wanted to speak in Phoenix along with McCain for his concession speech, this was vetoed by McCain’s campaign strategist, Steve Schmidt.The Secret Service reported “a sharp and disturbing increase in threats to Obama in September and early October, at the same time that many crowds at Palin rallies became more frenzied."Palin attacked Obama about his connection to William Ayers before the campaign had finalized its plan about that issue–McCain had not given his approval, and a top advisor was resisting it.Hillary Clinton was on much better terms with McCain than with Obama, and McCain feared that Hillary Clinton would be named as Obama’s VP, and was glad when he chose Biden.There are lots of other interesting bits in the article, as well.

November 6, 2008 · 2 min

TSA airport security is a waste of time and money

Jeffrey Goldberg explains why in The Atlantic. The check for whether you’re on the no-fly list is at the time of ticket purchase and check-in; there is no validation of your actual ticket against your ID at the TSA checkpoint (you can easily print and use a fake boarding pass at the TSA checkpoint); there is no check of ID when you board the plane. The checks for substances and items at the TSA checkpoint are easily subverted, with the restrictions on liquids probably the most absurd and pointless. We’re throwing away billions of taxpayer dollars per year on security theater. (Hat tip to John Lynch.) (Previously, previously, previously, previously, previously, previously.)

October 18, 2008 · 1 min

EFF sues the NSA, Bush, Cheney, Addington, etc.

The Electronic Frontier Foundation has filed Jewel v. NSA to try another tactic in stopping unconstitutional warrantless wiretapping of U.S. residents. Their previous lawsuit against AT&T, Hepting v. AT&T, is still in federal court as the EFF argues with the government over whether the telecom immunity law passed by our spineless Congress is itself constitutional or applicable to the case. Jewel v. NSA names as defendants the National Security Agency, President George W. Bush, Vice President Dick Cheney, Cheney’s chief of staff David Addington, former Attorney General Alberto Gonzales, and “other individuals who ordered or participated in warrantless domestic surveillance.”

September 20, 2008 · 1 min

Sarah Palin's Yahoo account hacked

Sarah Palin has apparently been using a personal email account for State of Alaska business (perhaps following Republican precedent on how to avoid subpoenas?), and it’s been compromised. Wikileaks has the documents. UPDATE (September 19, 2008): The screenshots used by the attacker showed that he used ctunnel as his web proxy, and contained enough information to identify his source IP in ctunnel’s logs. As pointed out by commenter Schtacky, it looks like they’ve identified the culprit, who used some Google research and Yahoo’s password recovery feature to change the password on the account to break in. This shows the problem with choosing “security questions” for password recovery that have answers which are easily publicly available. I hope that this kid’s actions don’t sabotage the corruption case against Palin that may have been supported by evidence in her Yahoo email, evidence that is now tainted by the fact that it was compromised (and subsequently deleted). ...

September 17, 2008 · 1 min

Virginia Supreme Court strikes down anti-spam law

Spammer Julian Jaynes now gets off as a result of a bad decision from the Virginia Supreme Court, reversing its own previous decision from six months ago. The court ruled that the Virginia anti-spam law’s prohibition of header falsification constitutes an unconstitutional infringement of the right to anonymous political and religious speech, suggesting that it would have been acceptable of it was limited to commercial speech. The court’s decision was predicated on the assumption that header falsification is a necessary requirement for anonymity, but this is a faulty assumption. All that is needed for anonymity is the omission of identity information that leads back to an individual, not the falsification of headers or identity information. That can be done with remailers, proxies, and anonymously-obtained email accounts, with no header falsification required. I previously made this argument in more detail in response to the arguments given by Jaynes’ attorney in the press. I also disagree with the court’s apparent assumption that commercial speech is deserving of less protection than religious or political speech. What makes spam a problem is its unsolicited bulk nature, not its specific content.

September 12, 2008 · 1 min

When t-shirts, coffee tables, and screws are munitions

One of my prized possessions, now in a box in a closet somewhere, is a T-shirt that says on its front “This T-shirt is a munition.” Underneath it is some machine-readable barcode that encodes the RSA public-key encryption algorithm expressed in Perl. As the seller of the shirt advertised, “it’s machine washable and machine readable." When I bought and regularly wore that shirt, taking it out of the country was a crime punishable by up to a $1 million fine and 10 years in federal prison. This is because U.S. rules under the International Traffic in Arms Regulation (ITAR), then enforced by the Department of Commerce, ruled that strong encryption qualified as a munition subject to export controls and requiring a special license for export. After the Dan Bernstein case was decided in 1996, computer source code printed in a book (human readable format) was not subject to export controls, but computer source code in a machine readable format, such as on my shirt, still was. So I could wear my other T-shirt with RSA Perl code on it, which had a program in the shape of a dolphin, out of the country, but not the machine readable “This T-shirt is a munition” shirt. The implication was that you could take a copy of Bruce Schneier’s Applied Cryptography out of the country without an export license, but not a disk containing the very same code fragments printed in the book. This website authored by Adam Back, written at the time, proposed some possible motives for government restrictions on cryptography. What the ITAR regulations on cryptography did for Internet software development was prohibit web browsers and server software from implementing the strong encryption necessary to protect electronic commerce from being exported from the United States. The result was that this development work simply occurred offshore. There were no barriers to importation of the software into the U.S., only to export it out. So the software was developed and sold by companies in places like Canada, Russia, and Estonia, which had no such inane restrictions. Finally, in 1999, the U.S. wised up and relaxed the ITAR restrictions on encryption, allowing export without a license to most countries (the exceptions being countries with links to state-sponsored terrorism). But ITAR is still around, and still having the unintended effect of pushing business out of the United States. The current victim is commercial satellite production. In 1999, ITAR authority over satellite technology export was shifted from the Department of Commerce to the Department of State, and since that time the U.S. share of commercial satellite manufacturing has dropped from 83% to 50%. The company Alcatel Alenia Space, now known as Thales Alenia, took steps in the late nineties to eliminate all U.S.-manufactured components from its satellites, with the result that it has subsequently doubled its market share to over 20%. The European Space Agency, Canada’s Telesat, and the French company EADS Sodern, that makes satellite control and positioning systems, have all been phasing out their use of U.S.-supplied components. They’ve done this because dealing with U.S. vendors increases costs (due to regulatory compliance costs) and causes unpredictable delays in the supply of parts. Nevada’s Bigelow Aerospace delivered an aluminum satellite stand to Russia in 2006, which Robert Bigelow described as “indistinguishable from a common coffee table.” But because it’s associated with a satellite and officially part of a satellite assembly, it is covered by ITAR and had to be guarded by two security guards at all times. Even commodity items like screws and wiring, when part of a satellite, are covered by ITAR regulations. The purpose of ITAR is to prevent key U.S. technologies with military applications from being leaked out to other countries that might be hostile to the U.S. But the effect of its overly broad application has been to shift the development of that technology to other countries and reduce the ability of U.S. companies to compete in the commercial satellite business. Congress should look to reform ITAR–when export controls are so badly broken as to have nearly the opposite of the intended effect, they clearly need to be relaxed. (Satellite and ITAR info via “Earthbound,” The Economist, August 23, 2008, pp. 66-67.) ...

August 30, 2008 · 4 min
Mastodon Verification