Risk
2/22/2011
02:56 PM
Connect Directly
RSS
E-Mail
50%
50%

Air Force Seeks Fake Online Social Media Identities

The military has issued a request for bids on software to let it spread messages and make online friends using non-existent identities on social media sites.

The United States Air Force is taking an unusual approach to cyber-security with a request for bids for "Persona Management Software," which would let someone command an online unit of non-existent identities on social media sites. The move became a major topic last week following the release of emails from private security firm HBGary, which were disclosed after an attack by Wikileaks competitor and collaborator Cryptome.org.

According to Solicitation Number: RTB220610 , the armed services division sought a software program that could manage 10 personas per user, including background; history; supporting details, and cyber presences that are " technically, culturally and geographacilly [sic] consistent. Individual applications will enable an operator to exercise a number of different online persons from the same workstation and without fear of being discovered by sophisticated adversaries. Personas must be able to appear to originate in nearly any part of the world and can interact through conventional online services and social media platforms. The service includes a user friendly application environment to maximize the user's situational awareness by displaying real-time local information."

The request, made in June 2010, was for 50 licenses, for a total of 500 fake Internet identities, which the Air Force planned to deploy in Iraq and Afghanistan. The software would protect government agencies' identities by using several false signals to convince other users that the poster was a real person, according to the contract. For example, each persona could receive its own IP address, making it appear to post from a different location around the world.

At least one individual was surprised that the proposal was published openly.

"This is posted on open source. Are you ****ing serious?" wrote Greg Hoglund, owner of HBGary, in an email leaked by a group of hackers that broke into the security firm's network earlier this month. "Just curious, this particular one is pretty sensitive and I'm wondering why it was in the public domain," he added, in a separate email.

Details about the contract were disclosed when hacker Cryptome.org broke into the email account of HBGary, which develops computer forensics and malware analysis tools. Its sister company, HBGary Federal, provides security services -- such as installing intrusion detection systems, secure networking, penetration testing, and vulnerability assessment -- to public and private sector organizations.

The fake-personal social media contract would allow the government to "friend" real people on Facebook as a way to show support for pro-government messages, according to information revealed during the hack.

The software could cross-reference all available social media such as Facebook, Twitter, MySpace, and other services to collect data on real individuals, and then use this to gain access to users' social circles, according to the emails.

"Using the assigned social media accounts we can automate the posting of content that is relevant to the persona. In this case there are specific social media strategy Web site RSS feeds we can subscribe to and then repost content on twitter with the appropriate hashtags. In fact using hashtags and gaming some location-based check-in services we can make it appear as if a persona was actually at a conference and introduce himself/herself to key individuals as part of the exercise, as one example. There are a variety of social media tricks we can use to add a level of realness to all fictitious personas," said Aaron Barr, HBGary CEO, in the hacked emails.

By using information -- such as their high schools, colleges, and home towns -- that users freely share on social networking sites, the Air Force could gain access to individual's social circles, creating a Classmates.com account at the same school and within the same graduating class, and then creating a Facebook account in the name of a real person who does not have a Facebook account, the email exchanges said. By friending someone with 300 to 500 friends, a fake persona easily can develop mutual friends before sending a friend request to the targeted individual, the emails said.

"When choosing to participate in social media, an individual is only as protected as his/her weakest friend," according to the documents.

In 2009, the Pentagon spent at least $4.7 billion and employed 27,000 people solely for recruitment, advertising, and public relations, according to a 2009 report by the Associated Press.

The Armed Forces increasingly has integrated social media considerations into operations. In November, the Air Force warned members about the dangers of location services such as Facebook Places and Foursquare. A year ago, the Department of Defense released a policy memorandum regarding the safe and effective use of Internet-based capabilities, including social media.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7052
Published: 2014-10-19
The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7056
Published: 2014-10-19
The Yeast Infection (aka com.wyeastinfectionapp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7070
Published: 2014-10-19
The Air War Hero (aka com.dev.airwar) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7075
Published: 2014-10-19
The HAPPY (aka com.tw.knowhowdesign.sinfonghuei) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-7079
Published: 2014-10-19
The Romeo and Juliet (aka jp.co.cybird.appli.android.rjs) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.