George Soros gave Ivanka's husband's business a $250 million credit line in 2015 per WSJ. Soros is also an investor in Jared's business.

Friday, April 27, 2018

Mr. Pompeo: It's the US--not Russia or N. Korea--that has given every hacker in the world access to lethal cyber weapons. NSA's EternalBlue was centerpiece of May 2017 WannaCry global cyber attacks. Due to NSA negligence, its elite hacking tool EternalBlue is now "in every hacker's toolbox" and will be "go-to tool for attackers for years to come"-Wired, 3/18/18

NSA’s EternalBlue is “in every hacker’s toolbox." EternalBlue...a sophisticated, top-secret US cyber espionage tool, is now the people’s crowbar. It is also frequently used by an array of nation state hackers 







networks. It will be years before enough computers are patched against EternalBlue.”...EternalBlue can hide or give false clues about geographic location of the hacker. 

3/7/18, The Leaked NSA Spy Tool That Hacked the World,Wired, Lily Hay Herman 

Leaked to the public not quite a year ago, EternalBlue has joined a long line of reliable hacker favorites. The Conficker Windows worm infected millions of computers in 2008, and the Welchia remote code execution worm wreaked havoc 2003.

EternalBlue is certainly continuing that tradition—and by all indications it’s not going anywhere. If anything, security analysts only see use of the exploit diversifying as attackers develop new, clever applications, or simply discover how easy it is to deploy…. 

EternalBlue is the name of both a software vulnerability in Microsoft’s Windows operating system and an exploit the National Security Agency developed to weaponize the bug. In April 2017, the exploit leaked to the public, part of the fifth release of alleged NSA tools by the still mysterious group known as the Shadow Brokers. 

Unsurprisingly, the agency has never confirmed that it created EternalBlue, or anything else in the Shadow Brokers releases, but numerous reports corroborate its origin—and even Microsoft has publicly attributed its existence to the NSA. 

The tool exploits a vulnerability in the Windows Server Message Block, a transport protocol that allows Windows machines to communicate with each other and other devices for things like remote services and file and printer sharing. Attackers manipulate flaws in how SMB handles certain packets to remotely execute any code they want. Once they have that foothold into that initial target device, they can then fan out across a network.

Microsoft released its EternalBlue patches on March 14 of last year [2017]. But security update adoption is spotty, especially on corporate and institutional networks. Within two months, EternalBlue was the centerpiece of the worldwide WannaCry ransomware attacks….As WannaCry hit, Microsoft even took the “highly unusual step” of issuing patches for the still popular, but long-unsupported Windows XP and Windows Server 2003 operating systems. 

In the aftermath of WannaCry, Microsoft and others criticized the NSA for keeping the EternalBlue vulnerability a secret for years instead of proactively disclosing it for patching. Some reports estimate that the NSA used and continued to refine the EternalBlue exploit for at least five years, and only warned Microsoft when the agency discovered that the exploit had been stolen. EternalBlue can also be used in concert with other NSA exploits released by the Shadow Brokers, like the kernel backdoor known as DarkPulsar, which burrows deep into the trusted core of a computer where it can often lurk undetected. 

The versatility of the tool has made it an appealing workhorse for hackers. And though WannaCry raised EternalBlue’s profile, many attackers had already realized the exploit’s potential by then.
 
Within days of the Shadow Brokers release, security analysts say that they began to see bad actors using EternalBlue to extract passwords from browsers, and to install malicious cryptocurrency miners on target devices. “WannaCry was a big splash and made all the news because it was ransomware, but before that attackers had actually used the same EternalBlue exploit to infect machines and run miners on them,” says Jérôme Segura, lead malware intelligence analyst at the security firm Malwarebytes. “There are definitely a lot of machines that are exposed in some capacity.”

Even a year after Microsoft issued a patch, attackers can still rely on the EternalBlue exploit to target victims, because so many machines remain defenseless to this day. “EternalBlue will be a go-to tool for attackers for years to come,” says Jake Williams, founder of the security firm Rendition Infosec, who formerly worked at the NSA. “Particularly in air-gapped and industrial networks, patching takes a lot of time and machines get missed.

There are many XP and Server 2003 machines that were taken off of patching programs before the patch for EternalBlue was backported to these now-unsupported platforms.” 

At this point, EternalBlue has fully transitioned into one of the ubiquitous, name-brand instruments in every hacker’s toolboxmuch like the password extraction tool Mimikatz. But EternalBlue’s widespread use is tinged with the added irony that a sophisticated, top-secret US cyber espionage tool is now the people’s crowbar. It is also frequently used by an array of nation state hackers including those in Russia’s Fancy Bear group, who started deploying EternalBlue last year as part of targeted attacks to gather passwords and other sensitive data on hotel Wi-Fi networks. 

New examples of EternalBlue’s use in the wild still crop up frequently. In February, more attackers leveraged EternalBlue to install cryptocurrency-mining software on victim computers and servers, refining the techniques to make the attacks more reliable and effective. “EternalBlue is ideal for many attackers because it leaves very few event logs,” or digital traces, Rendition Infosec’s Williams notes. “Third-party software is required to see the exploitation attempts.”

And just last week, security researchers at Symantec published findings on the Iran-based hacking group Chafer, which has used EternalBlue as part of its expanded operations. In the past year, Chafer has attacked targets around the Middle East, focusing on transportation groups like airlines, aircraft services, industry technology firms, and telecoms. 

“It’s incredible that a tool which was used by intelligence services is now publicly available and so widely used amongst malicious actors, says Vikram Thakur, technical director of Symantec’s security response. “To [a hacker] it’s just a tool to make their lives easier in spreading across a network. Plus they use these tools in trying to evade attribution. It makes it harder for us to determine whether the attacker was sitting in country one or two or three. 

It will be years before enough computers are patched against EternalBlue that hackers retire it from their arsenals. At least by now security experts know to watch for it—and to appreciate the clever innovations hackers come up with to use the exploit in more and more types of attacks.”
……………………
.............................

Added: Re: US city of Atlanta, Georgia is a US location that was attacked by US elite hacking weapons in May 2017 global WannaCry disaster, per cyber security firm Rendition Infosec. WannaCry was made possible by NSA tools which appeared on the internet in 2016 and 2017: 

3/28/18, Atlanta, hit by ransomware attack, also fell victim to leaked NSA exploits, ZDNet, Zack Whittaker

“According to one security firm, last week’s cyberattack was not a surprise because the city had fallen victim to leaked government exploits used in the [2017] WannaCry outbreak [which used leaked hacking tools developed by the National Security Agency.]

New data provided by Augusta, Ga.-based cybersecurity firm Rendition Infosec, seen by ZDNet, shows that the city’s network was silently infected last year [2017] with leaked exploits developed by the National Security Agency. 

The cybersecurity firm’s founder Jake Williams said at least five internet-facing city servers were infected with the NSA-developed DoublePulsar backdoor in late April to early May 2017.

That was more than a month after Microsoft released critical patches for the exploits and urged users to install. 

The NSA exploits were stolen in 2016 in one of the biggest breaches of classified files since the Edward Snowden disclosures.

The [alleged] hackers [described as “leakers” in headline and elsewhere in this article] who stole the exploits, known as the
Shadow Brokers, attempted to auction off the files but failed. 

Microsoft learned of the theft of these tools and, fearing that they would be used or publicly released, the company quietly released security patches for the exploit in March. Weeks later, the tools were dumped online for anyone to use. 

According to Williams, the city’s networks were left unpatched for weeks making them vulnerable to ransomware attacks.

“Based on our data, we can say for an organization of its size, the city of Atlanta had a substandard security posture in April 2017, making the scope of the ransomware attack far from surprising,” Williams told ZDNet.

Williams also wrote up his findings Tuesday in a detailed blog post. 

Just two weeks later, the WannaCry ransomware attack hit.

The attack was the biggest of its kind — spreading throughout several countries, infecting hundreds of thousands of computers. The ransomware used the leaked NSA exploit dubbed EternalBlue, which attacks a flaw in Windows SMB, and drops the DoublePulsar backdoor and waits. It’s that DoublePulsar backdoor that allows an attacker to remotely execute a malicious payload — such as ransomware.

Williams said his firm detected 148,000 infected machines at its peak — machines that were directly connected to the internet.

But that doesn’t account for the vast number of machines connected to those infected servers — likely putting the final number of machines at risk significantly higher. 

Williams stopped scanning for infected servers only by chance before the WannaCry attack, because as security patches were applied, the number of vulnerable systems was going down. 

It’s not known if Atlanta patched its network during that two week period before the WannaCry attack.

When reached, a spokesperson for the City of Atlanta was unable to comment on specific questions we had. 

Williams confirmed that as of Monday, none of Atlanta’s systems are still infected by the NSA exploits –– though, he said, it’s not known if the clean-up is a response to Thursday’s cyberattack or not.

Atlanta’s recovery efforts continue “around the clock,” said Bottoms.

CSO security reporter Steve Ragan reported earlier Tuesday that the portal used to pay the ransom — if the city decides to do so — has been pulled offline by the ransomware attacker. A screenshot of a city employee’s computer, which included the dark-web address used to access the payment portal, was publicized by local media. 

Although some of the city’s machines are slowly coming back online, many systems remain locked. For now, it’s not known when — or even if — the city will get fully back up and running.

==========

Comment: Mr. Pompeo, regarding US "security" partnerships with the UK, the US has no basis for "partnering" with a country that's part monarchy and part slave camp for unelected EU parasites. As you know, UK "security" agencies are lawless entities, free to engage in massive criminal activities, never held to account, and have no fear of consequence. That may sound great to you, but it doesn't to us. As you also know, UK GCHQ operates under the protection of its Daddy--you--the US government. This "special" relationship is therefore either parent-child, or pimp and hooker.

Two citations for above comment:

9/20/2013, "Britain's GCHQ Hacked Belgian Telco: Report," Security Week

"In UK's attack on Belgium telecom, "Initially, the NSA was suspected, but the presentation shows that it was a British operation using surveillance technology developed by the NSA."... 

..................

2/17/18, "How U.K. Spies Hacked a European Ally and Got Away With It," The Intercept, Ryan Gallagher

UK GCHQ's brutal hacks on the Belgium telecom network caused millions of dollars in damages, were ongoing since at least 2010, but to this day, the UK hasn't admitted what it did. Belgium chose not to pursue the matter with required aggressiveness fearing political repercussions. Meaning, they knew UK had Daddy US behind them:

"But we [Belgium telecom giant of which Belgian gov. is majority owner] were fighting against two big cyber armies from the UK and the US. We knew we could never win this."
 
 

...................

Two thirds of California Likely Voters want to send National Guard to the US-Mexican border per Survey USA poll of Likely Primary Voters-San Francisco Chronicle, 4/25/18

4/25/18, "Poll: California governor race heats up, two-thirds of voters want to send National Guard to border," San Francisco Chronicle, Eric Ting

"With six weeks to go until the June 5 primary, a new poll suggests that it's a three-man race to be the next governor of California. A poll of 520 likely primary voters released by SurveyUSA and sponsored by KABC-TV Los Angeles, KFSN-TV Fresno, KGTV-TV San Diego, KPIX-TV San Francisco and the San Diego Union-Tribune found that Gavin Newsom, Antonio Villaraigosa and John Cox are all within 6 percentage points of one another.

Newsom led the field with 21 percent of the vote, but was followed closely by fellow Democrat Antonio Villaraigosa with 18 percent. Republican John Cox came in third with 15 percent, and was followed by fellow Republican Travis Allen at 10 percent and Democrat John Chiang at 9 percent....

RELATED: Gavin Newsom says alcohol isn't a problem anymore: 'A little wine' is fine

The poll also found that 66 percent of Californians support sending troops from the California National Guard to the Mexican border. 30 percent of participants said they support sending troops to "patrol for people attempting to cross the border illegally," and an additional 36 percent said they support sending troops to the border as long as they "only focus on gang and drug activity."

Just 27 percent of the poll's participants said that National Guard troops shouldn't be sent to the border, while 7 percent were undecided....

In the Senate race, the poll found that Dianne Feinstein maintains a large lead over her many primary challengers.

Feinstein leads the way with 39 percent, and the next closest contender is Republican Patrick Little, with 18 percent. State Senate leader Kevin de León garnered just 8 percent support."



............

.........

Thursday, April 26, 2018

Caravan people won't be saved by legal aid. Caravan people should fear coming to US because they can be given to human and sex traffickers, forced to work as slaves. US gov. has no ability to prevent this, doesn't keep track of kids, has no way of dealing with so-called sponsors who prevent kids from receiving services-Washington Post, NY Times, Jan. 28, 2016

Jan. 28, 2016 articles, Washington Post and NY  Times:

1/28/2016, "Obama administration placed children with human traffickers, report says," Washington Post, Abbie Van Sickle  

"The Obama administration failed to protect thousands of Central American children who have flooded across the U.S. border since 2011, leaving them vulnerable to traffickers and to abuses at the hands of government-approved caretakers, a Senate investigation has found.

The Office of Refugee Resettlement, an agency of the Department of Health and Human Services, failed to do proper background checks of adults who claimed the children, allowed sponsors to take custody of multiple unrelated children, and regularly placed children in homes without visiting the locations, according to a 56-page investigative report released Thursday.

And once the children left federally funded shelters, the report said, the agency permitted their adult sponsors to prevent caseworkers from providing them post-release services.
Sen. Rob Portman (R-Ohio) initiated the six-month investigation after several Guatemalan teens were found in a dilapidated trailer park near Marion, Ohio, where they were being held captive by traffickers and forced to work at a local egg farm.

The boys were among more than 125,000 unaccompanied minors who have surged into the United States since 2011, fleeing violence and unrest in Guatemala, Honduras and El Salvador....

The report concluded that administration “policies and procedures were inadequate to protect the children in the agency’s care.” HHS spokesman Mark Weber said in a statement that the agency would “review the committee’s findings carefully and continue to work to ensure the best care for the children we serve.”

The report was released ahead of a hearing Thursday before the Senate Permanent Subcommittee on Investigations, which Portman co-chairs with Sen. Claire McCaskill (D-Mo.). It detailed nearly 30 cases where unaccompanied children had been trafficked after federal officials released them to sponsors or where there were “serious trafficking indicators.”

“HHS places children with individuals about whom it knows relatively little and without verifying the limited information provided by sponsors about their alleged relationship with the child,” the report said.

For example, one Guatemalan boy planned to live with his uncle in Virginia. But when the uncle refused to take the boy, he ended up with another sponsor, who forced him to work nearly 12 hours a day to repay a $6,500 smuggling debt, which the sponsor later increased to $10,900, the report said. A boy from El Salvador was released to his father even though he told a caseworker that his father had a history of beating him, including hitting him with an electrical cord. In September, the boy alerted authorities that his father was forcing him to work for little or no pay, the report said; a post-release service worker later found the boy was being kept in a basement and given little food.

The Senate investigation began in July after federal prosecutors indicted six people in connection with the Marion labor-trafficking scheme, which involved at least eight minors and two adults from the Huehuetenango region of Guatemala.

One defendant, Aroldo Castillo-Serrano, 33, used associates to file false applications with the government agency tasked with caring for the children, and bring them to Ohio, where he kept them in squalid conditions in a trailer park and forced them to work 12-hour days, at least six days a week, for little pay.

Castillo-Serrano has pleaded guilty to labor-trafficking charges and awaits sentencing in the Northern District of Ohio in Toledo. 

The FBI raided the trailer park in December 2014, rescuing the boys, but the Senate investigation says federal officials could have discovered the scheme far sooner. 

In August 2014, a child-welfare caseworker attempted to visit one of the children, who had been approved for post-release services because of reported mental-health problems, according to the report. 

The caseworker went to the address listed for the child, but the person who answered the door said the child didn’t live there, the report added. When the caseworker finally found the child’s sponsor, the sponsor blocked the caseworker from talking to the child. 

Instead of investigating further, the caseworker closed the child’s case file, the report said, citing “ORR policy which states that the Post Release Services are voluntary and sponsor refused services.” 

That child was found months later, living 50 miles away from the sponsor’s home and working at the egg farm, according to the report. The child’s sponsor was later indicted."

"VanSickle is a reporter for the Investigative Reporting Program, a nonprofit news organization at the University of California at Berkeley."
.........

==============
.............  
Jan. 28, 2016 NY Times article: 
 
"The report also said that it was unclear how many of the approximately 90,000 children the agency had placed in the past two years fell prey to traffickers, including sex traffickers, because it does not keep track of such cases."...

1/28/2016, "U.S. Placed Immigrant Children With Traffickers, Report Says," NY Times,

The Department of Health and Human Services placed more than a dozen immigrant children in the custody of human traffickers after it failed to conduct background checks of caregivers, according to a Senate report released on Thursday.

Examining how the federal agency processes minors who arrive at the border without a guardian, lawmakers said they found that it had not followed basic practices of child welfare agencies, like making home visits.

The Senate’s Permanent Subcommittee on Investigations opened its inquiry after law enforcement officials uncovered a human trafficking ring in Marion, Ohio, last year (2015). At least six children were lured to the United States from Guatemala with the promise of a better life, then were made to work on egg farms. The children, as young as 14, had been in federal custody before being entrusted to the traffickers....

 In addition to the Marion cases, the investigation found evidence that 13 other children had been trafficked after officials handed them over to adults who were supposed to care for them during their immigration proceedings. An additional 15 cases exhibited some signs of trafficking.

The report also said that it was unclear how many of the approximately 90,000 children the agency had placed in the past two years fell prey to traffickers, including sex traffickers, because it does not keep track of such cases....

In the fall of 2013, thousands of unaccompanied children began showing up at the southern border. Most risked abuse by traffickers and detention by law enforcement to escape dire problems like gang violence and poverty in Central America.

As detention centers struggled to keep up with the influx, the Department of Health and Human Services began placing children in the custody of sponsors who could help them while their immigration cases were reviewed. Many children who did not have relatives in the United States were placed in a system resembling foster care.

But officials at times did not examine whether an adult who claimed to be a relative actually was, relying on the word of parents, who, in some cases, went along with the traffickers to pay off smuggling debts.

 Responding to the report, the Department of Health and Human Services said it had taken measures to strengthen its system, collecting information to subject potential sponsors and additional caregivers in a household to criminal background checks.

 Mark Greenberg, the agency’s acting assistant secretary of the Administration for Children and Families, said it had bolstered other screening procedures and increased resources for minors.

“We are mindful of our responsibilities to these children and are continually looking for ways to strengthen our safeguards,” he said."    

................
   
Translation/comment: This is called "overwhelming the system" and gets predictable results for both invaders and invaded, ie misery, poverty, and disease. It's a thrill for the entire US political class who, as open borders globalists, have converted American citizens into global slaves for the purpose of forcing continuous low wages globally. It's also a wink to the world's tyrants and dictators to continue their brutal ways, to include forcing out all the people they don't want because US taxpayers will be forced to pay their expenses. US elections are meaningless. Convicted felon George Soros runs the US.
.........




..............

South Koreans send food to North Koreans in plastic bottles they toss in the sea to be carried North by tide-BBC

4/26/18, "South Koreans send aid to the North in floating plastic bottles," BBC

BBC video
"Activists in South Korea say they are providing "a lifeline" to their neighbours in the North in the form of plastic bottles filled with food, medicine and USB sticks carrying entertainment.

They gather fortnightly on Ganghwa island near the border to throw the bottles containing aid into the sea, which are then carried across to the North by the tide.

It is not clear how many of the bottles reach their intended recipients."



.............

Senate easily confirms Mike Pompeo as US Secretary of State. Seven Democrats-five facing re-election in states Trump won in 2016-joined united Republican conference in 57-42 vote-NY Times

4/26/18, "Senate Confirms C.I.A. Chief Mike Pompeo to Be Secretary of State," NY Times, Gardiner Harris, Thomas Kaplan

Pompeo and Kim Jong-un


In the end, the 57-to-42 tally lacked the drama of other nail-biting confirmation votes in the Trump era. Earlier this week, Senator Rand Paul of Kentucky, the nominee’s main Republican antagonist, bowed to pressure from President Trump to drop his objections. Ultimately, seven members of the Senate Democratic caucus — five of whom face re-election this year in states that Mr. Trump won in 2016 — joined a united Republican conference to support Mr. Pompeo’s confirmation.

Mr. Pompeo was expected to be sworn in almost immediately after the vote, after which he planned to dash to Joint Base Andrews, where a plane was waiting to fly him to Brussels on his first trip abroad as secretary of state for a meeting of NATO allies. His agenda is already packed, with crucial deadlines in the coming weeks involving Russia, North Korea, Syria and Venezuela.... 

Senators were mindful of the need to get Mr. Pompeo in place, given the crush of work facing him. His confirmation seemed all but assured after Senator Heidi Heitkamp of North Dakota, a Democrat who is running for re-election in a state that Mr. Trump won by a wide margin, said last week that she would support him. 

Four other Democrats who are also running for re-election in states won by Mr. Trump — Senators Joe Donnelly of Indiana, Joe Manchin III of West Virginia, Claire McCaskill of Missouri and Bill Nelson of Florida — also voted to confirm Mr. Pompeo....

As secretary of state, Mr. Pompeo will also have to navigate the rivalries within the Trump administration. At the White House, John R. Bolton, the administration’s third national security adviser in a little over a year, is presiding over another purge of top assistants. Mr. Pompeo must forge a working relationship with Mr. Bolton as he creates alliances with the White House chief of staff, John F. Kelly, Defense Secretary Jim Mattis, and the president’s son-in-law and top adviser Jared Kushner.

Mr. Pompeo’s early military career — he attended West Point and became a tank commander before leaving for Harvard Law School — could endear him to Mr. Kelly and Mr. Mattis, both former four-star generals.

But handling Mr. Kushner will be a delicate matter. Mr. Kushner’s diplomatic portfolio includes forging a Middle East peace deal and safeguarding the relationship with Mexico even as Mr. Trump pursues his hard-line immigration policies and wall on the southern border.

Mr. Pompeo will also have to mend fences with the American ambassador to the United Nations, Nikki R. Haley, whose relationship with Mr. Tillerson was so strained that she ordered his portrait removed from her New York offices. She was absent from this week’s state dinner with French President Emmanuel Macron.

Mr. Pompeo’s year of service as the director of the C.I.A. has given him a running start. He forged an unlikely bond with Mr. Trump while giving the president daily intelligence briefings. The trust between them is so strong that Mr. Trump sent Mr. Pompeo to Pyongyang last month on a secret trip to pave the way for a high-stakes summit with the North Korean leader, Kim Jong-un, now expected to take place in June....

Within hours of his landing in Europe, he will preside over a breakfast meeting at NATO headquarters....

In two weeks, Mr. Trump is also set to announce whether he will exit the Iran nuclear deal, struck by President Barack Obama.... Failing to scrap the deal would violate a core campaign pledge.

Mr. Pompeo was once a voluble member of the Republican chorus opposing the pact. But in his confirmation hearing, Mr. Pompeo promised to try to preserve the accord, one of several pledges he made that were at odds with his record as a four-term Tea Party congressman from Kansas. This week, Mr. Trump also signaled he may preserve the deal.

In addition, Mr. Pompeo will have to help forge a strategy to deal with a splintering Syria, something administration officials have openly acknowledged they lack, decide whether to launch a trade war with China, and choose whether to impose new sanctions against Venezuela following the expected re-election of President Nicolas Maduro on May 20 in a campaign widely seen as undemocratic.

Although a decided hawk and more socially conservative than much of his staff, Mr. Pompeo’s expected arrival has been greeted with quiet relief in Foggy Bottom, which has yet to recover from the tenure of Mr. Tillerson."... 

Above image caption: ". The White House released photographs from the meeting on Thursday. Credit via The White House"


..........



UK attack on Belgian telecom used Daddy NSA technology. UK spy agency GCHQ frequently hacks governments and businesses from countries including Russia, North Korea, UAE, Iran, Turkey, and Belgium. UK never admits hacking and 'gets away with it' because of its sick relationship with the deeply corrupt US political class-The Intercept, 2/17/18

In UK's attack on Belgium telecom, "Initially, the NSA was suspected, but the presentation shows that it was a British operation using surveillance technology developed by the NSA."... 9/20/2013, "Britain's GCHQ Hacked Belgian Telco: Report," securityweek.com, Rochford

UK "got away with" the Belgium telecom attack because their corrupt US Daddy protected them. UK opted to become subservient to the US when for example it secretly accepted $139 million in new spy equipment from the Obama administration from 2009-2012. UK is said to be desperate to maintain approval of its US cronies believing the relationship is all that stands between the UK and global irrelevance.

UK GCHQ's brutal hacks on the Belgium telecom network caused millions of dollars in damages, were ongoing since at least 2010, but to this day, the UK hasn't admitted what it did. Belgium chose not to pursue the matter with required aggressiveness fearing political repercussions. Meaning, they knew UK had Daddy US behind them: 

"But we [Belgium telecom giant of which Belgian gov. is majority owner] were fighting against two big cyber armies from the UK and the US. We knew we could never win this."

2/17/18, "How U.K. Spies Hacked a European Ally and Got Away With It," The Intercept, Ryan Gallagher

"It was the summer of 2013, and European investigators were looking into an unprecedented breach of Belgium's telecommunications infrastructure. They believed they were on the trail of the people responsible. But it would soon become clear that they were chasing ghosts – fake names that had been invented by British spies. 

The hack targeted Belgacom, Belgium's largest telecommunications provider, which serves millions of people across Europe. The company’s employees had noticed their email accounts were not receiving messages. On closer inspection, they made a startling discovery: Belgacom’s internal computer systems had been infected with one of the most advanced pieces of malware security experts had ever seen. 

As The Intercept reported in 2014, the hack turned out to have been perpetrated by UK surveillance agency  Government Communications Headquarters, better known as GCHQ. The British spies hacked into Belgacom employees’ computers and then penetrated the company’s internal systems. In an eavesdropping mission called “Operation Socialist,” GCHQ planted bugs inside the most sensitive parts of Belgacom’s networks and tapped into communications processed by the company. 

The covert operation was the first documented example of a European Union member state hacking the critical infrastructure of another. The malware infection triggered a massive cleanup operation within Belgacom, which has since renamed itself Proximus. The company of which the Belgian government is the majority owner was forced to replace thousands of its computers at a cost of several million euros. Elio di Rupo, Belgium’s then-prime minister, was furious, calling the hack a “violation.” Meanwhile, one of the country’s top federal prosecutors opened a criminal investigation into the intrusion.
 

 


but no details about its activities have been made public. Now, following interviews with five sources close to the case, The Intercept – in collaboration with Dutch newspaper de Volkskrant – has gained insight into the probe and uncovered new information about the scope of the hack. The sources, who are subject to confidentiality agreements and not authorized to talk to the media, spoke on the condition of anonymity. Their accounts reveal an extraordinary investigation that was hindered from the outset by political, diplomatic, technical, and legal difficulties.

The Belgacom breach sparked outrage in Europe’s political institutions and made global headlines. But Belgium’s effort to identify the spies responsible and hold them accountable faced roadblocks at almost every turn. Europol, the European Union’s law enforcement agency, refused to assist. Prosecutors overseeing the case feared triggering a major diplomatic dispute and were reluctant to pursue it aggressively. Meanwhile, 



“We wanted to show that as a small country, we would not be bullied,” said a source close to the investigation. “But we were fighting against two big cyberarmies from the U.K. and the U.S. We knew we could never win this.”

At first, it was not clear how severely Belgacom’s systems were compromised or who was responsible for the breach. Inside a grayish, four-story office building on Lebeau Street in Brussels, one of the company’s email servers kept malfunctioning. The problem, first identified in the summer of 2012, was assumed then to be a routine technical fault. But about a year later – in June 2013 – the issue flared up again, and Belgacom’s security experts realized there was a more sinister explanation: The company’s systems had been hacked.

Belgacom notified the authorities that it had been targeted, and in July 2013, filed a formal complaint with a federal prosecutor. The complaint triggered a major investigation that was code-named “Trinity,” led by a group that included members of Belgium’s federal police, domestic secret service, military intelligence, and a specialist unit known as a Computer Emergency Response Team. Belgacom also recruited help in the form of Netherlands-based cybersecurity firm Fox-IT; it called in the U.S. technology company Cisco to assess the damage, as well.

Once they had the chance to analyze Belgacom's infected computers, the Belgian authorities realized  that they were not dealing with a routine cyberattack. Instead, they assessed that it was an “advanced persistent threat” – a deep-reaching hack perpetrated by a well-funded, highly skilled actor. They had never encountered anything like it before.

The malware that had infected Belgacom’s systems was disguised as legitimate Microsoft software, the investigators found. It was secretly collecting data from the company’s networks before storing it in compressed containers with several layers of encryption. Assessing the extent of the damage was no easy task.

The Belgians could not completely decrypt the files and were therefore unable to identify exactly what had been taken from Belgacom’s computers.

The hackers were retrieving the stolen information from Belgacom’s systems during business hours, masking their activity within the normal flows of data passing to and from the company’s networks. But in late August 2013, the malware suddenly began deleting itself, vanishing in minutes from Belgacom’s infected computers. “The attackers knew they’d been discovered,” said a security expert who worked on the case. “They pushed a button to destroy the malware.”

Luckily, the investigators had already made copies of the bug. They followed the digital evidence, forensically analyzing it for clues. They found that the stolen data had been sent out of Belgacom’s systems to a network of servers seemingly operated by the hackers.

They identified the servers by tracing IP addresses – a series of numbers assigned to computers when they connect to the internet – to countries including India, the Netherlands, Indonesia, and Romania.

The hackers had rented the servers from private companies operating in each of these countries. Belgian police contacted the companies and asked them to turn over any information they had about the customers who had purchased the servers. The companies complied, providing the police with names, addresses, and payment records. The police now had a list of people they believed could be responsible for the hack. But that’s where the trail began to go cold.

The addresses were for people who appeared to live in Germany and Denmark. Belgian federal police officers reached out to their counterparts in these countries, sharing the details about their suspects. But there were no records of anyone with the suspects’ names having lived at the addresses. In Germany, the address the hackers had used turned out to be a theater. It quickly became obvious to the investigators that the information was fraudulent. 

Their prime suspects were people who did not exist.

“There was nothing there – just ghosts,” said a source close to the investigation. “They are spies. They put up smokescreens.”

One detail would later take on significance, however. The servers had in some cases been purchased with payment cards that appeared to have been issued to people based in the U.K.

In June 2013, shortly before the discovery of the intrusion at Belgacom, journalists began publishing documents leaked by National Security Agency whistleblower Edward Snowden. The documents exposed controversial mass surveillance programs operated by the NSA [ie US taxpayers] and its British counterpart, GCHQ.

Some of the Belgacom investigators initially suspected that the NSA was involved in the hack, partly due to the complexity of the malware. It bore similarities to Stuxnet and Flame, U.S.-created digital viruses designed to sabotage and collect intelligence about Iran’s uranium enrichment program. “This was by far the most sophisticated malware I’ve ever seen,” recalled Frank Groenewegen, a researcher who analyzed Belgacom’s infected systems for the cybersecurity firm Fox-IT.

It was not until September 2013 that the Belgians would learn the truth: The Belgacom intrusion had in fact been carried out by another of their close allies, the British. Documents from Snowden, published that month by Der Spiegel, showed that a GCHQ unit called the Network Analysis Centre had hacked into the computers of three Belgacom engineers who had access to sensitive parts of the company’s systems.

When the details about the hack went public, Belgacom tried to play down the extent of the breach.

The company circulated a press release insisting there was “no indication of any impact” for its customers and their data. But the reassurance turned out to be false. As The Intercept revealed in December 2014, the most sensitive parts of Belgacom’s networks were compromised in stages between January and December 2011.

After installing malware on the engineers’ computers by luring them to a fake version of the LinkedIn website, GCHQ was able to steal their keys to the secure parts of Belgacom’s networks and begin monitoring the data flowing across them. The agency [GCHQ] boasted in classified reports that the operation was “hugely successful.” It gained access to Belgacom “both deep into the network and at the edge of the network” and hacked into data links carrying information over a protocol known as GPRS, which handles cellphone internet browsing sessions and multimedia messages.

The British spies appear to have targeted Belgacom due to its role as one of Europe’s most important telecommunications hubs. Through a subsidiary company called Belgacom International Carrier Services, it maintains data links across the continent and also processes phone calls and emails passing to and from the Middle East, North Africa, and South America. But tapping into a broad range of global communications is only one possible motive. GCHQ may also have sought access to Belgacom’s networks to snoop on NATO and key European institutions, such as the European Commission, the European Parliament, and the European Council. All of those organizations have large offices and thousands of employees in Belgium. And all were Belgacom customers at the time of the intrusion.

Over the last decade [2008-2018], as the internet and smartphone use have boomed, GCHQ has increasingly turned to hacking to collect intelligence on matters related to economics, geopolitics, and security. Aside from Belgacom, the agency has broken into the computer systems of the oil production organization OPEC; the Netherlands-based security company Gemalto; and organizations that process international cellphone billing records, including Switzerland’s Comfone. The agency [GCHQ] has also hacked several governments and companies from countries including

Ireland, South Africa, Pakistan, India, Turkey, Iran, Argentina, Russia, North Korea, the United Arab Emirates, and Zimbabwe,

according to previously undisclosed lists of some of its targets, contained in the archive of classified documents that The Intercept obtained from Snowden.

The hacking attacks are among GCHQ’s most sensitive and risky operations, mainly because the method is not as discreet as more traditional forms of electronic surveillance, like monitoring a phone line. Challenges the agency faces during its computer intrusions include “avoiding detection by [the] target or another agency” and “remaining within the law,” according to a previously undisclosed top-secret GCHQ document from the Snowden archive. All of GCHQ’s hacking activities “must be U.K. deniable,” the document says, meaning it should be impossible for those targeted by the hacks to trace them back to GCHQ’s computers. The agency’s hackers use what they call “intermediary machines” and “covert infrastructure” to disguise themselves before they steal information from hacked computers or phones.

In the Belgacom case, these protections failed and GCHQ’s biggest fear was realized. Its operation was discovered and its identity as the perpetrator was publicly exposed. For the authorities in Belgium, however, seeking justice for the damage that the agency caused still proved a remarkable challenge.

As news organizations began publishing the Snowden documents in 2013, the Belgians studied them with interest. The classified files revealed details about the planning and execution of the hack [by GCHQ]. But because the documents appeared in the press, were partly redacted, and had not been handed straight to the police, the law enforcement officials overseeing the criminal investigation did not consider them direct evidence, though they did enter the documents into their case file.

According to a source close to the investigation, there were informal discussions over whether it would be possible to ask Snowden to testify as a witness in the case, so he could verify the documents and potentially provide his own statement about the hack of Belgacom. However, senior prosecutor Frederic Van Leeuw poured cold water on the idea, on the grounds that it would be too damaging diplomatically. Snowden was in Russia, where he had sought asylum, and interviewing him could upset the U.S., a powerful ally of the Belgian government. At the time, there were rising concerns about the movement of potential Islamist terrorists in Europe. The Belgians needed U.S. assistance in tracking that threat and feared any move that could jeopardize the cooperation. (A spokesperson for Van Leeuw declined to comment for this story.)"...

[Ed. note: It's the exact opposite! Belgium has allowed itself to become a haven for Islamic terrorists: "Belgium has a central location in Europe; few border controls; a common language with prime jihadi target France; and a political divide between French and Dutch speakers that has long created bureaucratic disarray in justice and security." 11/25/2015, "Why terrorists find Belgium a haven," AP] 

(continuing); "The investigators knew the U.K. was responsible for the hack. But they wanted to build their own case, based on their own sources, that nailed GCHQ as the perpetrator. Some of the forensic evidence they had obtained from Belgacom’s systems pointed toward the U.K., but it was not conclusive and could still be denied.

There were the payments they had been able to trace to the U.K., but those turned out to have been made using pre-paid credit cards that were obtained anonymously – in the Kent area of England and elsewhere – and not linked directly to GCHQ. The investigators also found the names “Daredevil” and “Warriorpride” embedded within the code of the malware that had infected Belgacom’s systems.

These are the names of a hacking tool used by GCHQ and NSA, according to the Snowden documents, and their discovery within Belgacom was as close as the investigators got to a smoking gun. But the Belgians felt these details were still too circumstantial. They needed more.

In late 2013, Belgian police decided to approach the European Union’s law enforcement agency, Europol, for assistance. Europol helps E.U. member states fight terrorism and serious crime. It has a specialist unit called the European Cybercrime Centre, whose mandate is to “strengthen the law enforcement response to cybercrime in the E.U.” The Belgians hoped the unit would help them gather more evidence about the hack.

However, Europol wanted nothing to do with the investigation and refused to assist, according to two sources familiar with the interaction. Europol asserted that it would not carry out investigations into other European Union member states – in this case, the U.K. The Belgians were frustrated and believed Europol had stonewalled them for political reasons; they noted with suspicion that the organization was led by Rob Wainwright, who is British.

Jan Op Gen Oorth, a spokesperson for Europol, told The Intercept in an email that regulations restricted the organization to “investigating acts affecting two or more EU Member States, involving serious and organized crime and terrorist actors only.” Questioned on which regulations he meant, Op Gen Oorth pointed to a policy that did not exist at the time the Belgians asked for assistance with the hack of Belgacom. (The policy was in fact brought into force in May 2017; it states that Europol is empowered to investigate hacks “of suspected criminal origin,” but says nothing about hacks perpetrated by governments.)

At every turn in the case, the Belgian investigators encountered a dead end. They knew that even if they identified specific GCHQ personnel responsible for the hack, they would likely never be able to arrest or extradite them from the U.K. It might have been possible to place the names of particular GCHQ employees on a watch list, and if they ever traveled to Belgium, police could detain and interrogate them. But that would pose its own set of problems. Arresting a British spy would trigger a massive public dispute with the U.K. and there was insufficient political appetite for such a showdown. As such, the Belgian Trinity investigation came to be viewed as little more than symbolic in value.

“We could see GCHQ was behind it, but we knew it was never going to go to court,” said a source close to the case. “But still, we wanted to gather information and make it known to the world that in Belgium if you try to hack our national telecoms we won’t look away, we will investigate.”

The British government has never publicly acknowledged any role in the Belgacom hack. GCHQ declined to answer questions for this story and instead issued a statement asserting that its work is carried out “in accordance with a strict legal and policy framework, which ensures that our activities are authorised, necessary and proportionate.” Any GCHQ hack that targets foreign organizations must be approved at a senior level within the agency, and particularly sensitive operations sometimes require the sign-off of the government’s foreign secretary, who at the time of the Belgacom intrusion was William Hague. A spokesperson for Hague refused to discuss the case, saying he would not comment on “national intelligence matters.”

In the aftermath of the incident, it is likely that the Belgian government lodged diplomatic protests with its British counterparts. According to U.K. government records obtained by The Intercept through the Freedom of Information Act, British officials held a series of meetings with Belgian government representatives after the Belgacom intrusion was publicly exposed. In October 2013, for instance, foreign secretaries of each country and senior diplomats attended a two day “Belgian-British conference” at Lancaster House in London’s West End. Two weeks later, the British ambassador to Belgium met in Brussels with Johan Delmulle, a top Belgian federal prosecutor, who was overseeing the Belgacom investigation at the time.

Even within the Belgian government and law enforcement community, however, there was a lack of clarity about how the case was being handled. The country’s law enforcement personnel were not informed about whether a diplomatic dialogue was underway with the British. Meanwhile, Alexander De Croo, the Belgian government minister responsible for telecoms services, appears to have been kept in the dark about the incident. During a January 2016 talk at the World Economic Forum in Davos, Switzerland, De Croo made the extraordinary suggestion that his own [Belgian] government might even have secretly allowed the British to go ahead with the hack.

“The whole question is: Did we agree or not,” De Croo said. “I am not the Minister of Justice so I don’t get access to everything .… It might very well be that the Belgian intelligence services said, ‘Yes please go ahead, why not?’”

De Croo declined to be interviewed for this story. Belgium’s Ministry of Justice and intelligence services refused to discuss De Croo’s comments, citing an ongoing investigation.

The police file on the Belgacom hack numbers thousands of pages and is expected to be handed over soon to the prosecutor now overseeing the case. That prosecutor, Geert Schoorens, will decide what to do next, including whether to charge anyone over the breach.

Despite the political uproar the incident triggered in 2013, it is unlikely that any action will be taken. 

That GCHQ was responsible is beyond doubt, but the agency will face no consequences, say sources with knowledge of the case.

There will be no sanctions for the U.K., no compensation to cover the damage caused, no arrests, no interrogations, no apology, and no admission of guilt. Rather, Schoorens will turn over a report to the Belgian parliament and the investigation will be quietly closed.

Despite this, the hack has had a palpable impact in Belgium. Belgacom – or Proximus, as it is now known – committed to spend more than $55 million to reform its internal security procedures. The company created a cyberdefense unit and recruited “ethical hackers” who routinely try to break into its networks, which helps identify and fix any potential vulnerabilities. It has also trained its employees in how to spot potential hacking attempts, introduced new systems that constantly monitor activity within its internal networks, and reduced the number of its computers that have access to sensitive parts of its systems.

The Belgian authorities, too, were forced to embrace changes after the breach. The criminal investigation brought the country’s law enforcement and secret services closer together, and now the agencies are more cooperative on cybersecurity issues. For them, GCHQ's actions were a rude awakening – and the sign of a looming new threat, for which they are now preparing. “In the next few years, this malware is going to be in the hands of criminals and terrorists, said a source close to the investigation. “Belgacom was a learning curve. We learned how to respond to a crisis before the next crisis.”"
———
Documents published with this article:

 https://theintercept.com/document/2018/02/17/computer-network-exploitation-presentation/




....................

Wednesday, April 25, 2018

Mob rule may be fine for you, but not for me: 'LET ME BE,' 1965 by the Turtles: 'Don't try to change me or rearrange me to satisfy the selfishness in you. I'm not a piece of clay to mold to your moves each day. I'm sorry, I'm not the fool you thought would play by your rules'



 
The Turtles: Let Me Be (Lyrics), You Tube
..................  
"Let me be," lyrics
.................. 
"Please don't mistake me or try to make me
The shadow of anybody else

I ain't the him or her you think I am
I'm just trying hard to be myself
Though society's goal is to be part of the whole
That may sound good to you, not to me

....................
Let me be, let me be
To think like I want to
Let me be, let me be
That's all I ask of you
I am what I am and that's all I ever can be
.................
Don't try to plan me or understand me
I can't stand to be understood
I could never give in to or ever live up to
Being like you think I should

I've got some inner need that I'm tryin' to heed
I can't take hand-me-down destiny
.......................
Let me be, let me be
To think like I want to
Let me be, let me be
That's all I ask of you
I am what I am and that's all I ever can be
...............
Don't try to change me or rearrange me
To satisfy the selfishness in you

I'm not a piece of clay to mold to your moves each day
And I'm not a pawn to be told how to move
I'm sorry I'm not the fool you thought would play by your rules

'To each his own' philosophy

Let me be, let me be
To think like I want to
................
Let me be, let me be
That's all I ask of you

I am what I am and that's all I ever can be
...............
I said that's all I ever can be
I said that's all I ever can be
I said that's all I ever can be"
...
About The Turtles


-----------------------

Added: Mobs need to get a life of their own. The US isn't Europe. We don't accept rule by monarchies:

"The American people made it quite clear that they do not want to follow in Western Europe’s footsteps. They do not want to give their country away. They want to preserve their nation, their freedoms, their prosperity....Against the media, against the establishment, against the elites, against all the odds, Donald Trump won the American elections. And what a victory!"...11/9/2016, Geert Wilders  






...............

Followers

Blog Archive

About Me

My photo
I'm the daughter of an Eagle Scout and World War II Air Force pilot born in Brooklyn, finally settling in New Jersey.