-Caveat Lector-

from alt.conspiracy
-----
As always, Caveat Lector.
Om
K
-----
<A HREF="aol://5863:126/alt.conspiracy:482328">REPORT - HOW THE INTERNET IS
BEING CONTROLLED</A>
--[1]--
REPORT - HOW THE INTERNET IS BEING CONTROLLED

"But there is another, perhaps more disturbing aspect
of the PCCIP report. Almost every solution proposed by
the commission represents some new expansion of government
authority and some new encroachment into personal liberty.
These recommendations follow from the description of a
potential problem with barely a moment to consider the
consequences for our form of open government.
  - moshe


CRITICAL INFRASTRUCTURE PROTECTION
AND THE ENDANGERMENT OF CIVIL LIBERTIES

An Assessment of the President's Commission on Critical
Infrastructure Protection (PCCIP)

By Wayne Madsen
Electronic Privacy Information Center
Washington, DC

About the Electronic Privacy Information Center

The Electronic Privacy Information Center (EPIC) is a public
interest research center in Washington, D.C. It was established in
1994 to focus public attention on emerging civil liberties issues
and to protect privacy, the First Amendment, and constitutional
values. EPIC is a project of the Fund for Constitutional
Government. EPIC works in association with Privacy International,
an international human rights group based in London, UK and is also
a member of the Global Internet Liberty Campaign, the Internet Free
Expression Alliance and the Internet Privacy Coalition.

The EPIC Bookstore provides a comprehensive selection of books and
reports on computer security, cryptography, the First Amendment and
free speech, open government, and privacy. Visit the EPIC Bookstore
at  http://www.epic.org/bookstore/

Not for commercial use. Solely to be fairly used for the
educational purposes of research and open discussion.

Copyright (C) 1998 by the Electronic Privacy Information Center

First edition 1998

Printed in the United States of America

All Rights Reserved

ISBN: 1-893044-01-7

EPIC Staff

Marc Rotenberg, Executive Director
David L. Sobel, General Counsel
David Banisar, Policy Director
Shauna Van Dongen, Publications Director
Kathleen Ellis, Administrative Director
Wayne Madsen, Senior Fellow, Principal author of this report

ACKNOWLEDGEMENTS

The Electronic Privacy Information Center gratefully acknowledges
the support of the Fund for Constitutional Government, the C.S.
Fund, the Scherman Foundation, the Rockefeller Family Fund, and the
Stern Family Fund as well as the assistance of members of the EPIC
Advisory Board.

Preface

More than ten years have passed since adoption of the Computer
Security Act. That law, which was intended to ensure that issues of
computer security not be held hostage by government secrecy, has
remained more a goal than a result. For more than a decade,
administrations of both parties have sought to limit government
accountability and to extend government secrecy.

The cost of these efforts to expand government control over
computer security have been enormous: a failed encryption proposal,
expanded wire surveillance, short-sighted technical standards to
facilitate monitoring, and lack of trust and confidence in
government's ability to defend proposals in open forums among
technical experts.

The most recent dangers to civil liberties comes from the new-found
threat to our nation's infrastructure. An elaborate report
identified a whole series of attacks that terrorists could wage
against our communication lines, power grids, and transportation
networks. Not surprisingly, perhaps, the report recommended a
dramatic expansion of government authority, new funding to combat
the threat, and greater secrecy to conceal potential
vulnerabilities as well as the work of the government agencies now
tasked with defending us.

Taken on its face, there is a real question of whether the PCCIP
report adequately evaluated the dangers to our Nation's security.
The PCCIP report largely ignored the Y2K problem, now seen as the
greatest threat to our nation's infrastructure by experts,
industry, and the general public. The PCCIP also ignored the
extraordinary damage that could be caused by natural disasters such
as the ice storm that crippled large parts of southern Canada
during the winter of 1998.

Natural disasters, computer errors, and network vulnerabilities are
very real threats that we must consider in a society that is ever
more dependent on advanced technologies. To view all dangers
through the lens of terrorist attack, invariably hides from view
many of the practical problems we should consider.

But there is another, perhaps more disturbing aspect of the PCCIP
report. Almost every solution proposed by the commission represents
some new expansion of government authority and some new
encroachment into personal liberty. These recommendations follow
from the description of a potential problem with barely a moment to
consider the consequences for our form of open government.

In each of the areas touched on by the PCCIP Report - privacy,
freedom of information, open government, censorship, security
classification, Internet monitoring and surveillance, encryption,
and the authority of the FBI - it is necessary to examine carefully
the proposals of the PCCIP and consider the potential harm to open
government, personal liberty, and agency accountability.

Regarding privacy, our view is that there is no need to expand
workplace surveillance or weaken the protections established by the
Employee Polygraphy Protection Act. We would further oppose any
efforts to limit the application of the Freedom of Information Act
or the Federal Advisory Committee Act. Not only do we object to the
proposals to expand classification authority as envisaged by the
PCCIP report, we believe that there is more than ample evidence to
support further declassification of information held in federal
agencies.

It is worth emphasizing that it was the Freedom of Information Act
that helped identify many of the problems with the government's
proposed Clipper encryption scheme - errors in design, management
and adoption - that might have remained classified if not for the
presumption of government accountability firmly established by the
FOIA.

The PCCIP proposes the development of a large-scale monitoring
strategy for communications networks. Borrowing techniques that
have been applied to hostile governments and foreign agents, the
PCCIP brings the Cold War home with an open-ended proposal to
conduct ongoing surveillance on the communications of American
citizens. We believe that the Electronic Communications Privacy Act
of 1986 should be strengthened to prohibit such surveillance.

The PCCIP also continues the failed policies of the past, urging
the adoption of key escrow encryption scheme even after technical
experts have demonstrated its flaws and foreign governments have
rejected this approach. But in the key escrow recommendation, one
is given an important insight into the nature of the PCCIP effort.
For even proponents of key escrow have acknowledged that it poses a
significant risk to network security and creates new sources of
vulnerability that could otherwise be avoided.

The PCCIP, which was established to identify measures to protect
the Nation's critical infrastructure against attack, seems quite
prepared to sacrifice this critical goal when the return is greater
surveillance capability.

Here finally we reach the critical thrust of the PCCIP effort - a
proposal to extend the reach of law enforcement, to limit the means
of government accountability, and to transfer more authority to the
world of classification and secrecy. These proposals are more of a
threat to our system of ordered liberty than any single attack on
our infrastructure could ever be.

Openness, not secrecy, remains the key to a nation's security and
its future prosperity.

Marc Rotenberg
Executive Director
EPIC
Washington, DC
October, 1998


Table of Contents

EXECUTIVE SUMMARY *
The Pentagon/NSA Angle *

The Backdrop of NSDD-145 *

Industry's Refusal to Cooperate *

The Computer Security Act *

The Clipper Conundrum *

>From Clipper to Information Warfare *

War on Information *

The March of the Info-Warriors *

CRITICAL INFRASTRUCTURE PROTECTION IMPACT AREAS & COUNTER-RECOMMENDATIONS *
Privacy *

Freedom of Information, Open Government, and Censorship *

New Security Classification Category *

Internet Monitoring and Surveillance *

Encryption *

The Posse Comitatus Act *

Expanded Role for the FBI *

Antitrust *

Liability *

State Government Liability and Disclosure *

Government Certification and Deputizing of Information Security
Personnel *

Bibliography *

Appendix A: White Paper on PDD-63 *

APPENDIX B: White House Statement on PDD-62 and PDD-63 *

APPENDIX C: Members of PCCIP *


EXECUTIVE SUMMARY

On July 15, 1997, President Clinton signed Executive Order 13010,
which established the President's Commission on Critical
Infrastructure Protection (PPCIP). The Executive Order listed eight
sectors that the PCCIP was to examine for security vulnerabilities.
They are: telecommunications, electrical power systems, gas and oil
storage and transportation, banking and finance, transportation,
water supply systems, emergency services, and continuity of
government.

President Clinton appointed retired Air Force General Robert T.
Marsh to chair the PCCIP. Although the commission, its Steering
Committee, and its Advisory Committee were composed of members of
government and industry, the membership of the three bodies
consisted of a majority of military and intelligence
representatives. Appendix B lists the military and intelligence
affiliated members.

PCCIP's report, issued in October 1997, contained many
recommendations that have the potential to curtail a number of
important civil liberties, including freedom of speech and freedom
of information. Although the report concluded there was no evidence
of an "impending cyber attack which could have a debilitating
effect on the nation's critical infrastructure," it did recommend a
new bureaucratic security establishment with expansive authority.
If not properly monitored and controlled, these new national
security structures and intelligence-sharing networks, in addition
to those that already exist, may, instead of protecting the
national infrastructure, be used by the government and private
corporations to further erode the privacy of U.S. and foreign
citizens.

Duane Andrews, a former top Pentagon official who is an executive
Vice President at Science Applications International Corporation
(SAIC), a large intelligence and military contractor, sees no
practical difference. He stated, "A large international bank has
exactly the same problems and challenges as the Defense
Department." However, columnist Bill Frezza writes, "Maybe I'm
overreacting, but the intentional blurring of civilian and military
computer security concerns -- each legitimate in its own right --
smells fishy . . . both United Airlines and the U.S. Air Force
employ skilled mechanics to keep their planes in the air. So what?
I don't recall the Air Force telling United Airlines that it is
insufficiently informed to make rational decisions about flying.
And if our government is so worried about commercial security, why
has the Clinton administration become the single biggest impediment
to the adoption of strong encryption?" Not coincidentally, Andrews
served as the chairman of the Pentagon's Defense Science Board Task
Force on Information Warfare.

In response to the PCCIP's report, on May 22, 1998, President
Clinton signed two Presidential Decision Directives - PDD 62
(Combating Terrorism) and PDD 63 (Critical Infrastructure
Protection) - designed to defend the nation's critical
infrastructures from various threats, including "cyber attacks" by
computer hackers and terrorists. The White House summary of these
two PDDs is contained in Appendix A. PDD 63 carried out most of the
recommendations contained in the Report of the President's
Commission. These include the establishment of several new boards
and agencies, some with Internet surveillance authority. One of the
new offices is the National Coordinator for Security,
Infrastructure Protection, and Counter-terrorism within the
National Security Council. This office is headed by Richard Clarke,
a person who has spent a number of years in intelligence-related
functions. Clarke reports to the President through the Assistant to
the President for National Security Affairs.

PDD-63 also authorized the creation of a National Infrastructure
Assurance Council (consisting of private sector and state and local
government representatives), a National Plan Coordination (NPC)
staff, the Critical Infrastructure Assurance Office (CIAO) (headed
by Jeffrey Hunker), the Critical Infrastructure Coordination Group
(CICG), and the National Infrastructure Protection Center (NIPC)
under the FBI. Of most alarm is the fact that the NIPC may be
assisted in its Internet surveillance activities by the Department
of Defense and the U.S. Intelligence Community. The NIPC is headed
by Associate Deputy Attorney General Michael Vatis.

In addition, PDD-63 encourages private industry to establish an
Information Sharing and Analysis Center (ISAC). However, the
Federal government is authorized to facilitate the start-up of the
ISAC. Many observers believe that the NSA's Information Warfare
Technical Center in Fort Meade, Maryland, has the right embryonic
structure for the proposed ISAC. Such a facility, located within
the structure of one of the world's most intrusive intelligence
agencies, would constitute a grave threat to the privacy of not
only law-abiding American citizens but citizens of other countries
as well.


The Pentagon/NSA Angle

Congress has a "particular obligation to examine the NSA,
in light of its tremendous potential for abuse. ... The
danger lies in the ability of NSA to turn its awesome
technology against domestic communications."
 - Sen. Frank Church

The Department of Defense and its secretive component, the NSA,
were the driving forces behind critical infrastructure protection.
They convinced the administration that it was necessary to defend
the infrastructures of the United States in order to further
offensive and defensive information warfare contingencies --
notions partly drawn up by think tanks like the RAND Corporation
and hyped by Hollywood screen writers. In fact, some computer
experts interviewed by Reuters claimed the "threat is more
Hollywood than hard fact." They added that some information
security companies are using information warfare as a catalyst for
more security software and gadgetry by exploiting the fear
associated with a cyber-attack.  The same phenomenon exists with
the feared Year 2000 calamity.

For the Pentagon and the intelligence community, information
warfare offered a new vista in an era of post-Cold War diminishing
military budgets, paucity of conventional threats, base closures,
and reductions in force of both military and civilian employees.


The Backdrop of NSDD-145

The information security component of critical infrastructure
protection - namely the withholding of what the government deems is
"sensitive" information in the private sector - has roots in the
Reagan administration. It is important to examine the policy
decisions then in order to understand what is driving the current
critical infrastructure and information warfare initiatives.

Responsibility for computer security standards within the civilian
government had, until 1984, been assigned to the National Bureau of
Standards (NBS). During the 1970s, NBS became a pivotal player in
the development of computer security standards, particularly the
widely accepted Data Encryption Standard (DES). The result of these
developments was that NSA faced unprecedented competition from a
civilian agency within the Department of Commerce in the area of
encryption technology.

On September 17, 1984, NSA prevailed upon President Reagan to sign
National Security Decision Directive 145 (NSDD-145). The directive
authorized NSA to develop means to protect "unclassified sensitive"
information. For the first time in its thirty-two year history, the
NSA was assigned responsibilities outside its traditional foreign
eavesdropping and military and diplomatic communications security
roles. The agency was granted new powers to curb the use of public
cryptography and to develop standards and techniques for automated
systems security. In addition, NSDD-145 permitted NSA to control
the dissemination of government, government-derived, and even non-
government information that might adversely affect the national
security. Some argued that such a broad definition included all
information. NSA quickly began to exercise its new-found authority.

The directive also stated that NSA was to act as the government's
focal point for information security and as such was to:. . .
review and approve all standards, techniques, systems and equipment
for telecommunications and automated equipment security.

NSA also put pressure on the continued viability of DES when it
announced that it would no longer certify DES products used by the
government after 1988. Ignoring NBS's role within the civilian
government agencies, NSA mandated the use of its own secretly-
developed encryption algorithms - as part of a program called the
Commercial COMSEC Endorsement Program or CCEP -by all government
agencies. On November 5, 1986, National Security Adviser John
Poindexter, who was embroiled in controversy stemming from the
Iran-Contra scandal, further expanded NSA's information security
role when he signed National Telecommunications and Information
Systems Security Policy (NTISSP) No. 2. Officially titled
"Protection of Sensitive, But Unclassified Information in Federal
Government Telecommunications and Automated Information Systems",
Poindexter's directive extended NSA's mandate to the protection of
unclassified sensitive information in the commercial data bases of
private corporations. NSA found itself in charge of a program that
was at variance with the Constitution and its Bill of Rights.

At about the same time, NSA began lobbying against two bills in
Congress that were aimed at curtailing NSA's influence in the
civilian government and commercial sectors. House Resolutions 2889
and 145 reinforced NBS's authority over the security civil
government computer systems and networks by enshrining it in public
law. National Computer Security Center director Patrick R.
Gallagher, Jr., in a December 22, 1986 letter to Donald C. Latham,
the Pentagon's Assistant Secretary of Defense for Command, Control,
Communications, and Intelligence and the Chairman of the National
Telecommunications and Information Systems Security Committee
(NTISSC), reported that his staff "provided support for [the]
lobbying effort that successfully blocked HR 2889 from passage by
the 99th Congress." NBS and certain members of Congress were eyeing
NSA's computer security center, hoping to move it from NSA to NBS
along with a budget approaching $1 billion. HR 145, also known as
the Computer Security Act of 1987, ultimately fared better than HR
2889, but, it too, faced the same antagonistic NSA lobbying effort.

In testimony before the Chairman of the House Government Operations
Committee in February 1987, the NSA director, General William Odom,
was questioned on NSA congressional lobbying by the committee
chairman Jack Brooks of Texas. Brooks asked Odom, "Did NSA
officials contact private companies to gather support for NSA's
opposition to HR 2889 or HR 145? If so, did you authorize these
efforts?" Odom answered in writing that "NSA has no knowledge that
any of its employees initiated contact with private companies for
the purpose of gathering opposition support against HR 2889 or HR
145." Brooks' line of questioning was prompted by reported
Congressional lobbying on NSA's behalf by officials and agents of
one of its main computer security evaluation contractors, the MITRE
Corporation, and by one of its major computer vendors, Digital
Equipment Corporation (DEC). In replying to a question from
Representative Gerald Kleczka of Wisconsin on whether NSA staff
members lobbied against the bill, Odom was a bit more forthcoming.
He responded, "The answer is yes, sir. It's not the sense of the
word that you used, �lobby.' It's a sense of talking to Members of
the Congress as we do on all sorts of legislation . . ."

Brooks made it quite clear to General Odom what he thought of NSA's
computer security lobbying efforts on the Hill when he asked the
NSA chief, "Are you aware that it is illegal, against the law, for
Government officials to use appropriated funds to lobby Congress on
a piece of legislation? Odom replied, "Yes, sir."

Most irksome for Brooks were official visits made by NSA, FBI, and
CIA agents to U.S. companies that provided on-line access to
computer databases. NSDD-145, in creating a new information
category called "unclassified but sensitive," made commercial
providers of such information subject to government security
controls. One of the largest database providers visited by the
government intelligence agents was Dialog, at the time the largest
on-line vendor of data in the world. Dialog controlled around 270
databases that contained both commercial and government
information.
Brooks then called Latham to testify. The chairman made known his
feelings about NSDD 145:

 . . . one of the most ill-advised and potentially troublesome
directives ever issued by a President. First, it was drafted in a
manner, which usurps Congress's role in setting national policy.

Second, the directive is in conflict with existing statutes which
assign to the Office of Management and Budget, the Department of
Commerce, and the General Services Administration the sole
responsibility for establishing government-wide standards,
guidelines and policies for computer and telecommunications
security.

Finally, I seriously question the wisdom of the President's
decision to give DOD the power to classify, hence control,
information located in civilian agencies and even the private
sector which, in DOD's opinion, may affect national security.

Latham, in his testimony, denied that he or anyone else in the
NTISSC group had any plans to impose controls on unclassified
information in the private sector. However, on November 11, 1986,
six days after Admiral Poindexter issued his directive establishing
the "unclassified but sensitive category," Diane Fountaine,
Latham's Pentagon assistant, shocked a meeting of the Information
Industry Association by confirming that the Reagan administration
wanted to restrict access to public databases.

In fact, Latham was enforcing both NSDD-145 and the Poindexter
Directive to the letter. In September 1986, this resulted in a
visit by an NSA official to the headquarters of Mead Data Central
in Columbus, Ohio. Mead operated two well-known repositories of
data -NEXIS, a well-spring of news from the U.S. and foreign press,
and LEXIS, a source data for court cites and other legal data.
Describing computer data bases as threats to national security,
Latham said, "I'm very concerned about what people are doing -- and
not just the Soviets. If that means putting a monitor on NEXIS type
systems, I'm for it. The question is, how do you do that
technically without interference?" NSA soon began investigating
ways to eavesdrop on computer communications without being
detected. The perfect method would be to use a computer program to
surreptitiously monitor data base requests for particular
categories of information. A user who would conduct a data base
search using such keywords as "nuclear weapons", "stealth
technology", or "National Security Agency" could activate such
monitors, alerting the NSA about the database requests. For the
NSA, the agency that had pioneered the development of text and
voice keyword recognition systems, the monitoring of data base
queries would not be an insurmountable task.
Marc Rotenberg, the former counsel for Senator Patrick Leahy's
Subcommittee on Technology and Law Senate (and present director of
EPIC), later testified before the House Subcommittee on Legislation
and National Security that NSA's visits to private companies
"leaves open the possibility that any Federal agency could request
that the NSA undertake an assessment of any information system
maintained by a Federal contractor." He urged the Congress to limit
the authority of the NSA in computer security and to establish
adequate means for public accountability. He also recommended in
1989 that Congress begin public hearings on the role of encryption
technology in computer security. "Discussions about cryptography
must become public discussions, regardless of the agencies
involved."

Industry's Refusal to Cooperate

The NSA and Pentagon visitors to Mead Data Central were not only
interested in stemming the flow of technical data to the Soviets
and others, but also in trying to co-opt Mead to provide
information on their Soviet bloc clients. Mead would have nothing
to do with such a deal. Company president Jack W. Simpson refused
to become a snitch for the intelligence community, declaring, "They
would control GI Joe dolls as militarily significant if they could
get away with it." Gerald Yung, Mead's general counsel, affirmed
that "our clients are confidential."

Lockheed Dialog's General Counsel Robert A. Simons broke with the
Pentagon and NSA and questioned the government's activities: "Will
we all need a passport to enter a public library?" Simons' boss,
Dialog President Roger Summit, said "I don't know under what
authority it [control of private data bases] would be implemented."
Likewise, Kenneth B. Allen, the vice president for government
relations of the Information Industry Association, the trade group
of commercial data base companies, criticized the administration's
stance: "We think it is dangerous for the government to censor or
restrict the flow of information," adding, "We're just looking at
the opening salvos here." In light of the recent critical
infrastructure and information warfare initiatives, Allen's words
could not have been more prophetic.

The Computer Security Act

Despite the opposition of NSA and the Pentagon, Congress passed the
Computer Security Act of 1987. The House Report on the legislation
notes that NSDD 145 "raised considerable concern within the private
sector and the Congress." One of the principal objections to the
directive was that it gave NSA the authority to use its
considerable foreign intelligence expertise within this country.
This is particularly troubling since NSA was not created by
Congress, but by a secret presidential directive and it has, on
occasion, improperly targeted American citizens for surveillance.

Spurred to passage by Senators Patrick Leahy and Lawton Chiles and
by Representatives Jack Brooks and Dan Glickman, Public Law 100-235
firmly established the role of the NBS (later renamed the National
Institute of Standards and Technology or NIST) in establishing
security standards for computer systems and networks processing
unclassified information. But NSA still maintained a hook into the
unclassified sector -- one that it would begin to exploit to the
maximum extent possible. The Computer Security Act called for NIST
to draw on NSA for "technical assistance" in particular areas,
especially cryptography.

In 1989, NSA and NIST signed a Memorandum of Understanding (MOU).
The memorandum effectively returned to NSA many of the powers
rejected by the Computer Security Act. The MOU contained several
key goals that were to NSA's benefit, including: NSA providing NIST
with "technical security guidelines in trusted technology,
telecommunications security, and personal identification that may
be used in cost-effective systems for protecting sensitive computer
data;" NSA "initiating research and development programs in trusted
technology, telecommunications security, cryptographic techniques
and personal identification methods"; and NSA being responsive to
NIST "in all matters related to cryptographic algorithms and
cryptographic techniques including but not limited to research,
development, evaluation, or endorsement." The MOU was signed in
March 1989 by Vice Admiral William O. Studeman, Odom's successor as
NSA director, and Raymond G. Kammer, NIST's acting director and a
disciple of NSA principles. NSA, once again, re-established its
cryptographic hegemony within the government. Cynically, Studeman
wrote a letter to Congressman John Conyers in June 1989 stating
that it was NSA's "fondest desire . . . to work with NIST to start
the momentum toward increased fielding of technology, standards,
and guidelines in pursuit of PL 100-235 objectives."

The Clipper Conundrum

By early 1993, NSA was, once more, clearly in the driver's seat in
protecting computerized information in the civil government sector.
It, along with its allies in the Justice Department and FBI, sold
the incoming Clinton administration on the technology of escrowed
encryption. Most notable was the "Clipper Chip", a backdoor in
digitized telephone scrambling programs that permitted law
enforcement and intelligence agencies to listen in. The national
firestorm that erupted forced many traditional NSA hidden agendas
into public view, a situation which NSA found increasingly
uncomfortable.

NSA's escrowed encryption proposals, the FBI's "Digital Telephony"
proposals to give it virtual real-time access to the nation's
digital telecommunications network, and the Clinton
administration's continuation of arcane "munitions" export controls
on acceptable strength cryptography, continued into the critical
infrastructure protection debate. Within the business community,
there is an underlying suspicion of government intentions,
particularly in the computer and telecommunications industries. The
privacy and civil liberties communities are inherently suspicious
of administration intentions after witnessing a panoply of
intrusive and anti-privacy measures being introduced in proposed
legislation or by administrative fiat.

>From Clipper to Information Warfare

Control of cryptography is important to NSA but there is another
area in which the agency has always wanted to stake a claim --
computer intelligence. Throughout the late 1980s, a group of
computer intruders operating out of Hannover, West Germany were
discovered to be breaking into the computer systems of U.S. and
foreign government agencies and corporations. Furthermore, the
hackers were found to be acting on behalf of the Soviet KGB. This
incident gave NSA and other intelligence agencies the opportunity
to expand their charters. In the spring of 1991, during Desert
Storm operations in the Gulf, computer hackers from The Netherlands
accessed U.S. military computers connected to the Internet. In all,
some thirty-four DOD sites were penetrated according to the General
Accounting Office (GAO). In testimony before the Senate
Subcommittee on Government Information and Regulation, GAO official
Jack L. Brock, Jr. revealed that "at many of the sites, the hackers
had access to unclassified, sensitive information." The use of the
term "unclassified, sensitive information" was a windfall for NSA.
It could confidently resurrect the tenets of NSDD-145 by arguing
that it was necessary to protect such information, even though it
was available via the publicly-accessible Internet.

NSA, however, still faced some wary members of Congress who were
reluctant to expand NSA's powers in contravention of the Computer
Security Act. In November 1991, Senator Herb Kohl, the chairman of
the Senate subcommittee on Government Information and Regulation,
sent a letter to Commerce Secretary Robert Mosbacher, in which he
wrote that he held the Commerce Department, not NSA, responsible
for the break-in by Dutch teenage hackers into the DOD computers
containing "sensitive" information. Kohl also stated that "if the
provisions of the Computer Security Act were followed these break-
ins would be much less likely to happen." The senator urged
Mosbacher to "make computer security a higher priority at the
Department of Commerce."

Regardless of Kohl's stance, NSA was determined to take control of
the protection of unclassified but sensitive information. In July
1994, NSA's new director, Vice Admiral Mike McConnell, wrote a
letter to Senator Ernest Hollings, a key member of the Senate
Appropriations Committee, declaring that "the threat to these
[computer] systems is real . . . network/computer protection within
DOD is a fundamental readiness issue and the need for security
products is immediate."

But NSA was clearly looking for new reasons for existence. With the
collapse of the Soviet Union, the Warsaw Pact, and a shrinking U.S.
military budget, NSA's huge infrastructure and budget were being
eyed by anxious budget-cutters. After the closure of NSA
eavesdropping stations from Iceland to Alaska, NSA was clearly in
search of an expanded mission that would supplement its signals
intelligence and communications security responsibilities. Computer
intelligence-gathering and computerized digital countermeasures
were the answer. The term "information warfare" was coined and the
NSA saw it as a natural area in which to assume responsibility.

By 1994, NSA positioned itself to become the top government
information warfare-fighting agency. Because many government
officials were not exactly sure what "information warfare" was,
since no one had ever actually fought one, the Defense Department
decided to come up with a definition. According to DOD, information
warfare involves "actions taken to achieve information superiority
in support of national military strategy by affecting adversary
information and information systems while leveraging and protecting
our own information and information systems."

NSA set about to influence the information warfare proposals that
were being drawn up by a Defense Science Board information warfare
panel that met during the summer of 1994. The panel's findings
would have a great deal of influence on President Clinton's
emerging information warfare policy doctrine. Fortunately for NSA,
the information warfare panel of the study group was chaired by a
former Reagan administration official, Donald Latham, who was then
working for Loral Federal Systems, a large intelligence community
contractor.

To consolidate its position, NSA approved the creation of the
Defensive Information Warfare Program within the Defense
Information Systems Agency (DISA) - a component of the Pentagon. By
doing so, NSA was staking the same claim to "Infowar" that it had
already established for "Infosec" within the DOD infrastructure.
Information warfare also extended DOD's responsibilities in
disseminating disinformation, a technique mastered by the KGB
during the Cold War. The significant impact of an information war
on the international media is clear. Thomas Czerwinski, a professor
at the School of Information Warfare and Strategy at the National
Defense University in Washington, prophesied about an information
war when he asked, "What would happen if you took Sadaam Hussein's
image, altered it, and projected it back to Iraq showing him
voicing doubts about his own Baath Party?" But the same technology
could also be used to discredit democratically-elected leaders with
whom the United States disagreed. DOD's move into the area of
disinformation, morphing software, perception management, and
censorship potentially pits its "cyber warriors" against the
nation's "cyber libertarians."

War on Information

Charles Swett, a Pentagon official in the Office of the Assistant
Secretary of Defense for Special Operations and Low Intensity
Conflict, warned in 1995 that "the political process is moving on
to the Internet." Swett charged that the Zapatista National
Liberation Front was lying in their Internet communiqu�s in
claiming the Mexican army had raped and killed children in Chiapas.
Swett also argued that the Pentagon should begin scanning "left-
wing" news on Internet sites in order to keep track of political
activists operating domestically and abroad. However, the Pentagon
has a vested interest in trying to eliminate the Zapatista presence
on the Internet. The U.S. Army's Special Forces have been involved
in training Mexico's army in counter-insurgency operations against
the Zapatistas, a group which has only been deemed terrorist by the
Mexican oligarchy, New York banks and securities firms, and U.S.
military and intelligence officials. In June 1995, then-CIA
director John Deutch accused "terrorists" of using the Internet for
their own communications. In addition, the Defense Intelligence
Agency (DIA) maintains a list of 70 "rebel" Web sites.

Unfortunately, the DIA is involved in psychological warfare
operations with several unsavory governments in helping them quell
"rebel" movements. Many of these movements are considered
"terrorist" only in the eyes of dictatorial regimes supported by
the U.S. military. Freedom movements around the world, like the
Zapatistas in Chiapas, the Tibetans, East Turkestanis,
Bougainvilleans, Chechnians, West Papuans, Iranian Mojaheddin,
Kurdistanis, Chinese democrats, and East Timorese, are using the
Internet to communicate information about the horrific situation in
their lands. The Pentagon's information warriors have made a habit
of confusing Internet activism by such groups with "cyber-attacks."
For example, in May 1998, the U.S. information warfare structure
announced that the Liberation Tigers of Tamil Eelam, a group
fighting for independence from Sri Lanka, had successfully launched
a cyber-terrorist assault on Sri Lankan computer systems. In
reality, the attack was nothing more than a counter-propaganda e-
mail flooding of Sri Lankan embassy web sites. In an annual survey
of terrorist incidents, the State Department charged a Tamil group
called the Internet Black Tigers with "suicide e-mail bombings" of
Sri Lankan web sites. The Tamil group, far from engaging in
anything so dramatic, was merely trying to counter Sri Lankan
propaganda directed against the Tamils. Using the Pentagon's and
State Department's lexicology, one could equate the posting of
anti-government banners and posters on a government building as a
form of terrorism.

Many experts scoff at the notion that the Internet is vulnerable to
terrorist attack. According to Neil Barrett, a principal consultant
of Europe's Groupe Bull, "terrorist groups are not using the
Internet for anything more than propaganda and internal
communications." Barrett also stated that there is a lot of
exaggeration over what constitutes a cyber terrorist attack. He
cited one case in which an Internet chess club web site was
attacked by hackers -- the intrusion was later described as a
terrorist attack. Similarly, when the Pentagon alleged that its
computer systems were subjected to 250,000 hacker intrusions, it
failed to mention that all but 500 of these were mere Internet
"pings", a sort of inquiry that can be generated by a search engine
looking for information on "nuclear weapons", "missiles", or
"chemical warfare", all subjects that would be contained in the
Pentagon's Internet-connected systems. However, such search engine
"pings" hardly constitute cyber-terrorist attacks.

The Congress should consider measures aimed at preventing the U.S.
military and intelligence community, particularly the CIA, DIA,
FBI, and NSA from engaging in activities aimed at disrupting the
free flow of human rights information on the Internet.
Specifically, Internet intelligence-sharing between the United
States and nations that violate human rights should be strictly
restricted.

The information warfare proponents also seek to spread
disinformation via the Internet. The Pentagon and intelligence
community have traditionally used such tactics as "spoofing" the
airwaves with false messages and distributing propaganda through
television and radio broadcasts, air dropping of leaflets, and
planting of false stories in foreign newspapers and magazines. For
example, the U.S. Air Force Special Operations Command maintains
six EC-130 aircraft (code-named Commando Solo) that are designed to
broadcast propaganda to civilians over AM, FM, shortwave, and
television frequencies. These aircraft have been used in military
operations in Saudi Arabia, Turkey, Bosnia, Haiti, Panama, and
Grenada. In addition, U.S. Army psychological operations propaganda
specialists publish the weekly Herald of Peace newspaper in both
Serbian and Croatian, which is distributed throughout Bosnia. The
Pentagon planners feel that if another country or group resists
U.S. policy they are fair game for a propaganda assault. In a paper
written for the U.S. Air University, U.S. Air Force Colonel Richard
Szafranski maintains that "Information warfare is hostile activity
directed against any part of the knowledge and belief systems of an
adversary." The use of the Internet for similar disinformation and
propagandizing during peacetime could potentially violate laws and
U.S. Information Agency regulations intended to shield American
citizens from such manipulation and deception. These laws and
regulations should be revisited by Congress in consideration of
future critical infrastructure protection appropriations.
The March of the Info-Warriors

NSA has put its service cryptologic elements to work on information
warfare. The Army got a head start in 1990 when its Signal Warfare
Center at Vint Hill Farms, Virginia began soliciting companies to
propose the development of destructive computer viruses, self-
reproducing malicious computer instructions contained in computer
memory that can, if properly programmed, destroy information stored
in a computer. The Army, a pioneer in the development of deadly
biological viruses at its Fort Detrick, Maryland germ warfare
facility, was interested in developing surreptitious programs to
launch at an enemy's computer systems and networks, perhaps
transmitting destructive computer codes by radio. Computer security
specialists warned that such research could potentially backfire
against a computer aggressor. Many reasoned that the United States
was more vulnerable to the potential "bounce back" effect of such
viruses. Nevertheless, NSA's military components began to ready
their computer terminals for information warfare.

For example, the Army created its information warfare center at
Fort Belvoir, Virginia. Known as the Land Information Warfare
Activity (LIWA), it is co-located with the Army Intelligence and
Security Command, the Army component of NSA's Central Security
Service (CSS). According to a LIWA spokesperson, the Army is
"looking beyond the land battle with information warfare
initiatives and new technology."

In 1996, the Air Force established its Information Warfare Center
at Kelly Air Force Base, Texas. This activity is co-located with
the Air Intelligence Agency, the Air Force component of NSA's CSS,
and the NSA's Medina Annex Regional Signals Intelligence (SIGINT)
Operations Center (RSOC).

The Naval Information Warfare Activity at Fort Meade, Maryland, is
located with the Naval Security Group Command, the Navy component
of the NSA's CSS. In addition, the Navy's Fleet Information Warfare
at the Navy's Atlantic Fleet headquarters in Norfolk, Virginia, is
developing new methods for information warfare.

Armed with a new mission of defending against a cyber-attack, NSA
further eroded the provisions of the Computer Security Act by
offering its services to numerous federal agencies, including the
Department of Interior, National Aeronautics and Space
Administration, and the Department of the Treasury. For example,
NSA penetration teams tried to access unclassified computer
networks at NASA to probe the vulnerabilities of satellite control,
launch control and other operations. Even more alarming was the
fact that the General Accounting Office (GAO), the congressional
watchdog agency that is tasked with ensuring federal agencies are
complying with laws like the Computer Security Act, asked NSA to
conduct the penetration testing of NASA, an agency which clearly
falls under the purview of NIST.

The intelligence community and Pentagon also ensured a body of
congressional champions of information warfare advocates and
supporters. Chief among them are Senator Jon Kyl, whose
Subcommittee on Technology, Terrorism, and Government Information
has held numerous hearings featuring "gloom and doom" witnesses
complaining that the nation is one the verge of an "electronic
Pearl Harbor" and even more distastefully, an "electronic Oklahoma
City."
--[cont]--
Aloha, He'Ping,
Om, Shalom, Salaam.
Em Hotep, Peace Be,
Omnia Bona Bonis,
All My Relations.
Adieu, Adios, Aloha.
Amen.
Roads End
Kris

DECLARATION & DISCLAIMER
==========
CTRL is a discussion and informational exchange list. Proselyzting propagandic
screeds are not allowed. Substance�not soapboxing!  These are sordid matters
and 'conspiracy theory', with its many half-truths, misdirections and outright
frauds is used politically  by different groups with major and minor effects
spread throughout the spectrum of time and thought. That being said, CTRL
gives no endorsement to the validity of posts, and always suggests to readers;
be wary of what you read. CTRL gives no credeence to Holocaust denial and
nazi's need not apply.

Let us please be civil and as always, Caveat Lector.
========================================================================
Archives Available at:
http://home.ease.lsoft.com/archives/CTRL.html

http:[EMAIL PROTECTED]/
========================================================================
To subscribe to Conspiracy Theory Research List[CTRL] send email:
SUBSCRIBE CTRL [to:] [EMAIL PROTECTED]

To UNsubscribe to Conspiracy Theory Research List[CTRL] send email:
SIGNOFF CTRL [to:] [EMAIL PROTECTED]

Om

Reply via email to