Showing posts with label Mother Jones. Show all posts
Showing posts with label Mother Jones. Show all posts

Friday, February 22, 2013

Chinese Cyberwarfare, Explained

On Monday, an American cybersecurity firm called Mandiant released a report accusing the Chinese government of systematically hacking into American computer networks and targeting state secrets, weapons programs, businesses, and even the nation’s gas pipelines. The New York Times vetted the story and concluded that a growing body of evidence “leaves little doubt” that these attacks are originating from a secret Chinese army base. Adam Segal, senior fellow for China studies at the Council on Foreign Relations (an organization that, in the past, has also been targeted by hackers that appeared to be China-based), tells Mother Jones that this “raises the pressure on the increasing drum beat on the US to do something.” 

So just how freaked out do you need to be? Here’s everything you need to know: 

How do cyberattacks and cyberwarfare work? A cyberattack is what happens when a hacker penetrates computers or networks for the purpose of maliciously exploiting systems and information. This can lead to identity theft, viruses, theft of intellectual property, or full-on system infiltration (i.e., the hacker can watch your every move). Cyberwarfare is what happens when countries are the ones employing those hackers, often with the goal of stealing state secrets and/or causing damage. 

The scheme that Chinese hackers employ to gain footholds on victims’ computers is known in computer-speak as spear phishing, according to Mandiant, and it’s a scam that’s been around for years. The sabotage begins when a victim receives an innocuous work-related email about a meeting or a project from what appears to be a colleague’s email address. If the target takes the bait, he or she will click on a hyperlink or download an attachment from the message. In some cases, suspicious recipients have responded to phishing emails with questions about the file’s authenticity. The Chinese hackers have responded: “It’s legit.” When the target downloads the files, they’ll be unwittingly installing remote-access software (sometimes referred to as a “backdoor”) that allows the hacker to assume control of the victim’s computer.

With a few lines of code, the hacker can install other backdoors and programs, upload and download files, capture screenshots of the user’s desktop, record keystrokes and passwords, and shut down the system. The sleuthing can last months or even years, and confidential and top-secret files can be easily transported from the network into the hacker’s hands.  Here’s a video showing an attack in progress: 

So what is this mysterious Unit 61398? Unit 61398 (or “61398部队”​ for the Mandarin speakers among you) is believed to be a top-secret unit of the Chinese government that “engages in harmful ‘Computer Network Operations,’” according to the Mandiant report. It’s located in a 12-story facility in Shanghai, and could have up to thousands of employees, most of whom are required to speak English, demonstrate computer security skills, and exhibit “team spirit.” Richard Bejtlich, the chief security officer at Mandiant, tells Mother Jones that the unit built new headquarters in 2007. Mandiant claims to have known about the unit for seven years, but it’s unclear exactly how long it has been around. D.B. Grady, a national security journalist and author, makes the case that “concerns over Unit 61398—a perfectly unnerving name—are no more worrisome than Chinese spies recruiting American agents to steal folders from locked filing cabinets.” He adds, “If the US government were really alarmed, we would be threatening to go to war. Instead, we’re threatening to give a lot of money to government contractors.”

Nevertheless, here are some infographics showing just how effective Unit 61398 is at getting on your computer, and staying there: 

​Who is the Chinese government hacking? The short answer: Your business, your water supply, your defense, your newspapers, and probably more. The longer answer: Since 2006, China’s espionage division has stolen data from at least 115 American businesses—and that’s only the hacking that Mandiant directly observed. The company believes that number represents only a small fraction of the China’s overall hacking activity. Not surprisingly, Chinese spies were most interested in hacking national-security-related industries such as aerospace, energy, scientific research and information technology. Here’s a chart showing the most-targeted industries (it only includes attacks Mandiant witnessed, and includes some that occurred outside the United States):

Mandiant

But even if you work for an alfalfa farm in Wyoming, hacking could still affect you: According to the New York Times, the hackers are interested in US critical infrastructure—electric grids, oil pipelines and water systems—and are attempting to unlock US military secrets by targeting defense contractors and weapons program (more on that later). Chinese hackers are also taking on media giants that produce journalism critical of China: the Times‘ computers were compromised recently after a high-profile investigation revealed that members of Chinese Prime Minister Wen Jiabao’s family had accumulated massive wealth from state contracts, and the Washington Post, Bloomberg News and the Wall Street Journal have also all been targeted. (Mother Jones liability note: China is great! 我们爱中国!)

Why is China hacking the United States?Segal, the Council on Foreign Relations expert, explains:

The Chinese want to move up the value chain. They want to move from “made in” to “innovated in China.” So part of it is stealing industrial secrets and helping Chinese companies. There’s [also] political and military espionage—having a better sense of what the US government and US opinion leaders and other people think about China and try to influence that, and wanting to steal US military secrets. It’s also a kind of deterrent. [It] sends a message to the US that the US homeland is vulnerable and if there was going to be a regional conflict that escalated, the US should know that the Chinese have a way of reaching out and touching us.

Another explanation? Chinese hackers just really wanted to access their social-media accounts, many of which are blocked on the mainland. Mandiant was able to trace some of the hackers’ identities because the “easiest way for them to log into Facebook and Twitter [was] directly from their attack infrastructure.” And as our colleague Josh Harkinson noted, at least one hacker appears to be “a fan of American and British pop culture”—he used Harry Potter references for his passwords. 

So…just how screwed are we? Both private US companies and government infrastructure are pretty bad at stopping hackers from beating down the door. Most private companies “aren’t in a position to defend themselves, and if you devote any length of time to break into one of these guys, you’re going to find a way in,” says Mandiant’s Bejtlich.

When it comes to government, the forecast isn’t much better: President Obama says that the “cyberthreat is one of the most serious economic and national security challenges we face as a nation.” Between 2007 and 2009, the head of the Pentagon’s Cyber Crime Center confirmed 102 instances in which hackers had infiltrated the networks of government agencies, military contractors, or other entities connected to the Department of Defense, according to a 2010 Forbes report. In 2007, the 10 largest defense contractors, including Lockheed Martin, Northrop Grumman, Raytheon, and Boeing, all suffered security breaches that traced back to China. CFR’s Segal says that even though cyber attacks aren’t new, “on the defense side, we haven’t had too much success” defending against them. 

But experts don’t necessarily say that means the United States is screwed. Segal says that US-China relations would have to “already be very, very bad or very, very close to military conflict anyway for the Chinese to consider a cyberattack.” He adds that “there is some vulnerability to the power grid and industrial sector, but it’s not a major threat right now. The major threat is espionage and stealing secrets.”

“The way cybersecurity works is the way security works in the real world,” Bejtlich says. “It’s based on fast detection and response. It’s hard to stop someone from breaking into your house, but you can call the police and kick them out.” He adds that “defense contractors also learn from their experiences, and the ones who are making the news more tend to do the best job of protecting information that I’ve seen.” 

Grady makes the case that many of the cybersecurity concerns are overblown, and are instead, simply a good way for the defense industry to squeeze more money out of taxpayers. “This isn’t some kind of new horror. Cyberattacks will become worrisome when someone figures out how to use a copy of Linux to blow up something,” he tells Mother Jones. “The motives of defense contractors are pretty obvious, aren’t they?” he adds. “The war on terror is all but over, but cybersecurity could mean anything and everything. Where there’s fear, there’s a lot of money to be made.” 

What is the Obama administration doing? Last week, Obama issued an executive order on cybersecurity with the aim of protecting US critical infrastructure from hackers, despite pushback from conservatives and big business. The order requests that companies participate in a voluntary information-sharing program so the government can help them stop attacks. “It’s not clear that the executive order is going to make it better,” Segal says. According to Bejtlich, the administration “is doing as much as it can with the order, but now the focus needs to shift to the House and the Senate.”

Who else is China attacking? Wait, are we attacking anyone? Check out this amazing chart by Foreign Affairs, showing the number of cyber attacks, and by whom, from 2001 to 2011 (click link for the full chart): 

Foreign Affairs (Sam Pepple / Sample Cartography)

 


Politics | Mother Jones


Chinese Cyberwarfare, Explained

Thursday, February 21, 2013

Obama"s Immigration Plan Is Far Harsher Than Reagan"s

Draft immigration legislation being hammered out by the White House was leaked to USA Today over the weekend, and the paper had no trouble finding Republicans who balked at the president’s plan. Sen. Marco Rubio (R-Fla.), one of the members of the bipartisan “Gang of Eight” who recently cooperated on a proposal for comprehensive immigration reform, called the White House draft “dead on arrival.”

Opponents of immigration reform however, see the exchange as theater—”the point of leaking the bill is to enable Rubio to say that his amnesty plan is waaay different from the dastardly Obama plan,” wrote the Center for Immigration Studies’ Mark Krikorian at National Review. As a policy matter, Krikorian isn’t entirely wrong: Rubio’s hometown paper, the Miami Herald, also got ahold of the White House’s drafts and concluded that they “closely resemble many of the reforms advanced in 2011 by Obama and, more recently, by Republican Florida Sen. Marco Rubio.” (If you’ve been reading Mother Jones, that’s hardly surprising.)

What may be surprising however, is that Obama’s bill sets out a very long road to citizenship for undocumented immigrants. As Suzy Khimm writes at the Washington Post, under Obama’s proposal, those undocumented immigrants who are eligible for legalization would likely have to wait around 13 years for full citizenship—eight years of temporary legal status before acquiring a green card, then, as is standard under US law, about another five for citizenship. (If a backlog of existing visa applications is cleared before that initial eight years, the total wait could be shorter.) Lynn Tramonte, deputy director of the pro-reform group America’s Voice, tells Khimm that Obama’s proposal would “delay citizenship another generation.”

Compare that with the Immigration Control and Reform Act of 1986 that was signed by President Ronald Reagan, which allowedundocumented immigrants to apply for green cards after a temporary legal status of just 18 months. Add in the standard five years green-card holders have to wait before seeking citizenship, and under the bill Reagan signed the path to citizenship was half as long as Obama’s would be.

So if you‘re looking for an indication of where America’s immigration debate stands in 2013, note that Obama’s liberal proposal would be significantly harsher than the law put in place by the patron saint of American conservatism more than 25 years ago. 


Politics | Mother Jones


Obama"s Immigration Plan Is Far Harsher Than Reagan"s

Wednesday, February 20, 2013

Watch Out, GOP: Obama Super-PAC Is Coming for You in 2014

Priorities USA Action, the powerful pro-Obama super-PAC, unloaded $ 65 million in the 2012 presidential race, battering Republican Mitt Romney with attack ads that depicted him as a profit-chasing, cold-hearted plutocrat with a history of screwing over the middle class. Priorities was the counterexample to the Republican outside groups that spent hundreds of millions with little impact: Its ads were deemed hugely effective, and Priorities played a decisive part in Obama’s narrow victory in Ohio last November.

But Priorities isn’t shutting down now that Obama is safely ensconced for a second term. Instead, it will raise and spend big money to help the Democrats in the 2014 midterm elections and the 2016 presidential election, a Priorities fundraiser tells Mother Jones. The fundraiser says it is too early to comment on the group’s strategy for next year’s midterms or the upcoming presidential race, but he confirms that Priorities will remain a fixture in Democratic politics. The super-PAC currently has $ 3.4 million in the bank.

Continue Reading »

Politics | Mother Jones


Watch Out, GOP: Obama Super-PAC Is Coming for You in 2014

Sunday, February 17, 2013

"We"re Not Going to Be Pushed Around by the Antis"

Wichita, Kansas, has been without a local abortion provider since an anti-abortion extremist murdered Dr. George Tiller in his church in May 2009. Now, one of Tiller’s former employees has bought his clinic and intends to reopen it this spring.

The Trust Women Foundation, led by former Tiller spokeswoman Julie Burkhart, purchased Tiller’s old office last September. The group has raised most of the $ 1 million it will take to reopen the clinic, and Burkhart, 46, and her staff have been busy renovating the office and recruiting doctors. Burkhart is originally from northern Oklahoma. She worked with Tiller at the clinic for seven years, and had moved away from Wichita shortly before his murder. She has since moved back to reopen the clinic, which she and her colleagues plan to call South Wind Women’s Center.

When it opens, the clinic will provide abortions only up to the 14th week, and will provide referrals for pregnancies that are farther along. It will also offer full gynecological services, like pap smears, breast exams, birth control prescriptions, and prenatal care. “We want to make it a place that’s open for all women,” Burkhart told Mother Jones. Without a clinic in town, women have been traveling more than three hours away to seek abortions at clinics in Kansas City and Oklahoma.

Of course, it’s not the pap smears that draw the anti-abortion protesters. And Wichita has had more than its share of protests. Tiller, one of the nation’s only late-term abortion providers, was a main focus of their actions. Operation Rescue moved its headquarters to Wichita to focus on the clinic. And protesters have blocked other would-be providers from opening clinics in the town in their quest to keep Wichita “abortion free.” Since Burkhart signaled her intention to reopen the clinic, anti-abortion groups have lodged complaints that the clinic didn’t have proper building permits (it did) and have started a petition drive to get the city council to rezone that part of town as residential so that the clinic can’t reopen.

I talked to Burkhart last week about her plans for South Wind Women’s Center.

Mother Jones: How did you come to the decision to reopen Dr. Tiller’s Clinic?

Julie Burkhart: This was something that a lot of us thought about almost immediately after Dr. Tiller’s murder in ’09. It was on our minds, but a lot of us just didn’t feel that we were emotionally able to go down that path and pass through those hoops in order to make this happen. I kept coming back to it, and other people I worked with kept coming back to it, that this was just the right thing to do. A year and a half after we lost Dr. Tiller, we were really able to say, “Okay, this is going to be hard, this is going to be challenging—probably the biggest challenge of our lives—but we’re going to get this done.”

MJ: How did you overcome that apprehension and decide you needed to do it, even if it was going to be hard?

JB: I kept thinking that somebody else was going to do this. There were some other very well intentioned people who wanted to do this, and it just didn’t seem to work out for one reason or another. Here we live in a pretty good-sized city, Wichita, with a metropolitan area of around 650,000 people. It’s like really, come on. We’re a town that used to have three abortion clinics. Shouldn’t we be able to have at least one ob-gyn practice that offers abortion care? We realized we just needed to pick up the torch and do it.

MJ: Wichita has been the subject of so much attention from both anti- and pro-choice activists. What is the significance of reopening the clinic?

JB: First and foremost, we want to make sure that women who need to see us, want to come see us, are able to access care. We’re looking at a few thousand women who now have to travel outside the area each year. Secondly, what it says is that no matter where you live in the United States of America, women will have access to reproductive health care. This community has just been so embroiled in the abortion…I hate to say the abortion “debate,” but just the turmoil. Some people would say, “Just leave it alone and let it go.” However, we can’t really have true freedom in this country until everyone can access that right.

Why, just because we live in Kansas, in the middle of the country, should women be faced with more hardship? Why should it just be women on the coast where the laws are typically more liberal that have access to abortion care? I hope that’s what people get out of this—that no matter where you are as a woman, you’re entitled to that right.

MJ: Given the atmosphere in Wichita, were there any concerns about coming back there?

JB: Our concerns are about security, and making sure it’s peaceful at our clinic and things are peaceful at our homes. I feel that there’s a bit of a different attitude here now. The community in general really gets and understands that a medical facility like ours is needed in this community. Frankly, the only people we get the pushback from by and large are the antis. They’re good bullies. But people in this community are speaking out maybe a little bit more. There’s a little bit more understanding. We want people to understand that this is a new day; this is a new clinic. We’re working on a different model of health care for women. And we’re not going to be pushed around by the antis.

MJ: We just marked the 40th anniversary of Roe v. Wade a few weeks ago. Where do you think we are as a country on abortion access, and where are we heading?

JB: Well, I’m hoping that we’re coming to a turning point in our society where we can address this issue and this need instead of trying to hide from it, and can have a more honest dialogue. Frankly, I’m guilty of the same thing, because I went through a period of time where it was commonplace to not say the A-word, to try to dance around the issue. Looking back, I’m not sure that was the best strategy for us.

I’m hoping that we’re coming to a point where we can just be more honest, where we can lay things on the table and have those discussions. Because this is what I feel about abortion care: I think abortion is about motherhood. Abortion is about motherhood because by and large women coming in to have abortions are concerned about the kind of life and the future for their children. Women are thinking in a very responsible manner when choosing that. The anti-choice groups often portray women as irresponsible and making these whimsical decisions. But in truth these are very well thought out decisions women are making. They’re taking responsibility for their lives and the lives of their future families.


Politics | Mother Jones


"We"re Not Going to Be Pushed Around by the Antis"

Friday, February 15, 2013

Here"s Why Obama Won"t Say Whether He Can Kill You With a Drone: Because He Probably Can

During a Google+ “Fireside Hangout” Thursday evening, President Barack Obama was asked if he believed he has the authority to authorize a drone strike against an American citizen on US soil.

He didn’t exactly answer the question.

The Council on Foreign Relations’ Micah Zenko transcribed the whole exchange. Lee Doren, a conservative activist, asked the question; here’s Obama’s answer:

First of all, I think, there’s never been a drone used on an American citizen on American soil. And, you know, we respect and have a whole bunch of safeguards in terms of how we conduct counterterrorism operations outside the United States. The rules outside the United States are going to be different then the rules inside the United States. In part because our capacity to, for example, to capture a terrorist inside the United States are very different then in the foothills or mountains of Afghanistan or Pakistan.

But what I think is absolutely true is that it is not sufficient for citizens to just take my word for it that we are doing the right thing. I am the head of the executive branch. And what we’ve done so far is to try to work with Congress on oversight issues. But part of what I am going to have to work with congress on is to make sure that whatever it is we’re providing congress, that we have mechanisms to also make sure that the public understands what’s going on, what the constraints are, what the legal parameters are. And that is something that I take very seriously. I am not someone who believes that the president has the authority to do whatever he wants, or whatever she wants, whenever they want, just under the guise of counterterrorism. There have to be legal checks and balances on it.

Doren isn’t the only one who wants an answer to this question. Senator Rand Paul (R-Ky.) has placed a hold on John Brennan, Obama’s nominee for CIA director, “until [Brennan] answers the question of whether or not the President can kill American citizens through the drone strike program on U.S. soil.” Senator Dianne Feinstein (D-Calif.) posed that exact question to Brennan in a written questionnaire, but his answer was as opaque as Obama’s. “This Administration has not carried out drone strikes inside the United States and has no intention of doing so,” Brennan wrote. 

So why didn’t Obama just say, “no, the president cannot deploy drone strikes against US citizens on American soil”? Because the answer is probably “yes.” That may not be as apocalyptically sinister as it sounds.

“Certainly, we routinely ‘targeted’ U.S. citizens during the Civil War,” says Steve Vladeck, a law professor at American University’s Washington College of Law. “Even if the targeting was with imprecise 19th-century artillery as opposed to 21st-century [unmanned arial vehicles].” If he had the technology, President Abraham Lincoln would most likely have been within his authority to send a drone to vaporize Confederate General Robert E. Lee.

Drone strikes in the modern context, however, aren’t being used against uniformed commanders of a traditional military force. Instead, we’re talking about strikes that target individuals suspected of being part of terrorist organizations where “membership” is an inherently more nebulous concept. 

There are two government agencies known to conduct drone strikes, the CIA and the Department of Defense. CIA involvement in a domestic drone strike is probably off-limits, says Paul Pillar, a former CIA official who is now a professor at Georgetown University. The idea is really far-fetched anyway, Pillar argues. “I expect that if the CIA were to do anything like that within the U.S. it probably would violate some of the legal restrictions that are placed on all of the agency’s activities as far as inside-U.S. operations are concerned,” Pillar wrote in an email to Mother Jones. “Nothing like this is ever going to arise as far as drone strikes are concerned, so I don’t see it as a live issue.”

Since the CIA is probably out, that leaves the military. Congress has long held that the president has the authority to use the military domestically in some circumstances. The Posse Comitatus Act, passed after Reconstruction to limit the use of military force on US soil, states that the military can be used to enforce the law “in cases and under circumstances expressly authorized by the Constitution or Act of Congress.” The last time this happened was 1992 when, citing the Insurrection Act, President George H.W. Bush called out the National Guard to suppress the Los Angeles riots in the aftermath of the Rodney King verdict.

According to US law, Congress can authorize the use of the military inside the US. The question is whether the Authorization for Use of Military Force, which Congress passed in the aftermath of the 9/11 attacks, counts as “express authorization” to carry out a targeted killing on US soil. The Obama administration stated in its white paper explaining its legal authority to kill US citizens abroadthat capturing a suspected terrorist should be “infeasible” before a strike is authorized. But “the government’s going to have a devil of a time proving that capture is infeasible for any individual found within the territorial United States,” Vladeck says. And there’s no reason to believe that local or state authorities, or if necessary the FBI, wouldn’t be left to handle a situation involving suspected terrorists. (Local police dropped a bomb during an armed standoff with the radical group MOVE in Philadelphia in 1985, proving that civilian authorities can be just as lethal as the military.)

The law says military force can sometimes be used against people on American soil, such as if it were needed to fight an armed domestic insurgency. But we still don’t know how broad the Obama administration thinks that authority is. Less than a week before President George W. Bush left office, the Justice Department withdrew a series of memos written by torture memo author John Yoo that envisioned near-dictatorial authority for the president, including the authority to deploy military force against terrorism suspects inside the US. Yoo had basically given Bush the executive branch equivalent of the Konami Code

The Bush Justice Department argued that Yoo’s theories should no longer “be treated as authoritative for any purpose.” The question is whether the Obama administration has envisioned similar authority for itself. The answer to that question lies in the classified documents explaining the Obama administration’s legal rationale for the targeted killing program—documents that the Obama administration has so far refused to fully disclose to Congress, let alone release to the public.


Politics | Mother Jones


Here"s Why Obama Won"t Say Whether He Can Kill You With a Drone: Because He Probably Can