Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/30/2013
06:10 PM
Gunter Ollmann
Gunter Ollmann
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

NSA's TAO

NSA's Q-branch upgrades Omega laser watch with Huawei backdoors

This week the Internet's all aflutter with the latest NSA disclosures about the uber-hacking group -- the Office of Tailored Access Operations, or "TAO" for short. Der Spiegel's latest NSA articlesreveal some of the inner workings of the TAO team and their tools. It's pretty interesting stuff, and I'm sure the legacy conspiracy nuts are trading in their tinfoil hats for "I told you so" t-shirts today.

As more details leak about the 50-page catalog of hacking goodiesthat the NSA, CIA, FBI, DHS, etc., government entities could purchase for "lawful intercept" work, I get the feeling that a lot of product managers at the vendors for which these tools exploit vulnerabilities or frailties in their products will be a little wobbly in the knees department right about now. I suspect that there will be plenty of additional discussion in the coming months about the "lawful" part of the lawful intercept concept, too.

In many ways, TAO reminds me of a digital "Q" branch from the Ian Fleming's James Bondseries. I can just imagine a grey-mustached Q handing out USB dongles with embedded wireless transmitters to go with the Omega watch with the laser, or the exploding pen.

In light of the recent revelations, it would seem that the NSA TAO team has been very successful in completing their objectives. I suppose it's quite refreshing to know that at least one part of the U.S. government is capable and functioning as it's supposed to?

While this glimpse in to the shadowy world of modern spying and espionage is as exciting as cut scenes from an upcoming James Bond movie, I don't believe that it changes the paradigm that much. These are simply the tools of the trade for the cyberdomain. In fact, the tools that have been disclosed thus far are already close to a decade old -- and clearly have been in service for some time. Anyone who has attended a Black Hat conference in the past 10 years would be familiar with all of the concepts and attack vectors. What makes it different is how the NSA has successfully made the leap from theory to reality; clearly, having a sufficiently sized budget makes that leap much easier.

Of the documents produced thus far, the most surprising revelations to me have been about how small the TAO team is, and the proportion of which are civilian contractors. Given the size and budget of the DoD (and NSA, in particular), how advanced their adversaries are, and how successful they appear to have been in their missions, I'd have expected the team to be five to 10 times the size. Perhaps the absolute numbers get a bit fuzzy when it comes to the civilian contractors ... and the contracting firms they belong to.

It is inevitable that many people are going to be upset with the NSA's newly disclosed capabilities. Those previously mentioned vulnerable vendor product managers are probably working with their marketing and PR teams right now, crafting indignant responses to the U.S. government, while seeking to calm customer fears that their companies hadn't been negligent in dealing with the vulnerabilities they knew about, and have never knowingly placed backdoors into their products (all of which could get a bit hand-wavy in the case of RSA and the $10 million they supposedly received for weakening random number generators).

While many likely also fear that the NSA is out of control and needs to be reeled in through new legislative restrictions or the honing of existing laws -- and I'm sure that much of the software industry is allocating additional funds to lobby against the hacking of their products -- I think it is critical that folks take a step back and look around. The past six months of NSA leaks have certainly dumped a lot of the agency's dirty linen on the pavement, but let's be clear: The NSA (and, by default, the U.S. government) isn't the only the only countries to have invested in these kinds of cyberspying and espionage tools. I think you'd be hard-pressed to find a country that isn't already doing it. If you're thinking that Pakistan's ISI isn't spying on India and exploiting its computer vulnerable systems, or that France's DGSE isn't doing the same to Chinese systems in Central Africa, then let me tell you about a bridge I'd like to sell you.

My fear is that the reaction to all of these NSA disclosures will have legislators and committees curtailing many vital parts of the NSA's capabilities, leaving the U.S. high and mighty on the ethical front, but shackled and third-rate in areas of statecraft and cybersecurity.

In the meantime, if Q has a few of those Omega laser watches spare, I wouldn't mind one as a late Christmas present. He can keep the Huawei backdoor; I have one of those already.

-- Gunter Ollmann, CTO IOActive Inc.

 

Gunter Ollmann serves as CTO for security and helps drive the cross-pillar strategy for the cloud and AI security groups at Microsoft. He has over three decades of information security experience in an array of cyber security consulting and research roles. Before to joining ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/30/2014 | 4:10:31 PM
re: NSA's TAO
Of course countries spy on their adversaries. What troubles me is how much the NSA has invested in surveilling U.S. citizens. That's dangerous.
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18214
PUBLISHED: 2019-10-19
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVE-2019-18197
PUBLISHED: 2019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo...