Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint //

Privacy

4/4/2014
07:00 AM
Ira Winkler
Ira Winkler
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

NSA’s Big Surprise: Gov’t Agency Is Actually Doing Its Job

When people claimed after 9/11 that the NSA was ill equipped to deal with a changing world, I wonder what they expected to happen.

As I read all of the stories about the NSA, they come across as if this is somehow surprising. You can search back to the early 2000s and find stories that state how the NSA was behind the technology curve, and was woefully unprepared to deal with the ever-growing Internet and new technologies.

The Sept. 11 attacks seemed to further highlight how the NSA was unable to do its job, because it was focused on Cold War enemies and ill equipped to handle the new terrorist threat.

Well, it now appears that the NSA has made up for lost time.

People want to portray it as an ominous entity that operates independently from all control, but the fact is that the NSA only does what it has been asked to do. It takes direction from the executive branch of the government. Requirements for NSA operations come through the director of national intelligence. All programs are funded through Congress, despite the selective amnesia of many prominent senators and congressmen. Despite any disdain people may have for the FISA court, programs go through that court when required. The NSA is not a rogue agency that operates without oversight.

The leaks resulting from Edward Snowden's treason demonstrate that the NSA is making inroads where everyone previously doubted its capability and said it was failing at its mission. When people claimed that it was ill equipped to deal with a changing world, I wonder what they expected to happen. Did they expect Congress to just dissolve the NSA? Did they expect it just to accept its current technology capability? No, the NSA found a smart group of people and started using its money to work on its supposed shortcomings.

If you don't like what it is doing, you can't really protest the NSA itself. It just found a way to do what people said it couldn't do but was supposed to do. It is only doing exactly what it has been tasked to do.

Easy target? Talk to Congress
Yes, people like to have something to embody their frustration (and the NSA makes an easy target). But if you have a complaint, talk to your representatives in Congress. The NSA director, and actually the incredibly small number of staff members who work on the programs in question, are doing what they believe to be in the best interests of the country, as well as what is morally and legally right. If you think otherwise, then find the people who allocate the funding for the NSA, and deal with them.

As for the protesters who focus their attention on the NSA, they ignore the people who are actively harming hundreds of millions of people. When they criticize the NSA, they ignore the fact that Snowden first ran to China, which has hundreds of political dissidents in jail. China is monitoring its citizens on a scale well beyond anything the NSA is accused of doing -- and that isn't even up for debate. Likewise, they ignore China's supposed wide-scale hacking of the accounts of US citizens and companies.

I actually don't begrudge China for doing what it is doing in theory. The people doing the work are only doing what they believe is in the best interests of their country. The only difference that people should consider is that, at least in the US, there is a public conversation about it. Nor does there seem to be any public outrage toward the criminals who stole the credit cards from Target or who committed similar thefts of personal information or caused financial loss to hundreds of millions of people.

I guess that people just like to go after an entity that appears to actually care about what they think, despite the actual damage caused.

Ira Winkler is president of Secure Mentem and author of Advanced Persistent Security.
View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
tjensen846
50%
50%
tjensen846,
User Rank: Apprentice
4/4/2014 | 11:14:27 AM
George III
No doubt there were colonists who believed that King George III was "doing what [he] believed to be in the best interests of the country, as well as what is morally and legally right." 

But they were wrong too.
DOUG01
0%
100%
DOUG01,
User Rank: Apprentice
4/4/2014 | 10:23:09 AM
Missing the obvious
In addition to the excellent points already posted, you've overlooked the obvious.  People who are upset with Target have protested by not buying from Target.  Target revenue is down some 40% since the credit card theft.  When people vote with their money, the effect is immediate.  People cannot quit buying from NSA, so there is no alternative but to protest and contact their government representatives as the author suggests.  When people vote at the polling place, or contact their senator/representative, they do not get immediate action, partly because they don't have enough money individually to influence congress. Their influence is very small unless the congressman is flooded with millions of phone calls and emails.  This requires massive organization, which most individuals do not have time for.  Even with a massive campaign that influenced members of congress, change would take months or years.  The only group who could have an immediate effect on congress is the large corporations who donate huge sums of money to finance congressional election campaigns.  If  big business was really upset, they could easlily and rapidly initiate change in NSA policy by threatening to withhold election campaign funds or threaten to suppport another candidate.
GeoffreyL842
100%
0%
GeoffreyL842,
User Rank: Apprentice
4/4/2014 | 10:03:38 AM
False dichotomy
>Nor does there seem to be any public outrage toward the criminals

>who stole the credit cards from Target or who committed similar thefts...

This is an example of several logical fallacies.  The first is FALSE DICHOTOMY-- what you are presenting is not an either/or choice.  The worse one, though, "ARGUMENT BY IRRELEVANCY" (commonly known as "Red Herring").  Basically, you're trying to distract people from their quite reasonable objections to the NSA by bringing up a completely different subject.  Your argument boils down to "look, here's something else!  Squirrel!"

A third, somewhat more subtle logic flaw here is categorization error (commonly called "apples and oranges.")  The Target Hackers don't claim to be working for the government that (in principle) I elected, nor do they claim to be doing their bad things with a claim that they are benefitting me, nor are they subject to public pressure.  They are criminals. Are you are putting forth the premise the NSA are criminals, and thus the NSA and the Target Hackers are in a common category, but the Target Hackers are WORSE criminals? 
geriatric
100%
0%
geriatric,
User Rank: Moderator
4/4/2014 | 8:26:14 AM
Not Doing the Job You Think
Your argument falls flat when one looks at the Boston Marathon bombing. There was an abundance of evidence to raise enough red flags on the perps. The NSA didn't see them for one simple reason - that's not who they're looking for.
<<   <   Page 2 / 2
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
Out-of-Date and Unsupported Cloud Workloads Continue as a Common Weakness
Robert Lemos, Contributing Writer,  7/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internet—and What Your Organization Can Do About It
The Threat from the Internet—and What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-16271
PUBLISHED: 2020-08-03
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
CVE-2020-16272
PUBLISHED: 2020-08-03
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database via an A=0 WebSocket connection.
CVE-2020-8574
PUBLISHED: 2020-08-03
Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service enabled allowing unauthorized code execution to local users.
CVE-2020-8575
PUBLISHED: 2020-08-03
Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which allows administrative users to cause Denial of Service (DoS).
CVE-2020-12739
PUBLISHED: 2020-08-03
A vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices. The vulnerability is due to improper design or implementation of the Ethernet communication modules of the CNC. An attack...