Showing posts with label Yahoo. Show all posts
Showing posts with label Yahoo. Show all posts

Thursday, June 02, 2011

An interesting analog in the age of digital hacking


Ed.--A recent spate of cyberattacks on Google's Gmail system (originating in China) reminded me of a some similar techniques employed against Deborah Jeane Palfrey (the DC Madam), perhaps by the United States Government or non-governmental actors--contractors of one variety or another. The Chinese attacks ensnared several hundred individuals, some of them high level American government officials, presumably some working for the State Department.

Some whose Gmail accounts were breached were American military personnel as well as a few Chinese dissidents, perhaps included as a diversion or as overlap from other hacking operations originating from the same actors. Whoever they were, they were looking for specific types of people doing specific types of work for the U.S. Government; specific individuals were targeted for hacking.

Do no evil?

Google routinely cooperates with the America national security state, so it's no surprise that they've been targeted by other nations using third party actors to provide a kind of plausible deniability. In the case of the recent attack on Google, it's safe to assume that the encouragement of non-governmental actors was formulated to prevent accountability being directed at the regime in Beijing, a fair assumption. Does the U.S. do this? Certainly--one could argue that we pioneered its use--and some of this echoes the very real world attacks on American soil on September 11, 2001, ushering in a newer form of mercenary where attacks by one state against another are done indirectly by proxy, "non-governmental" agents.

21st Century Brigands?

This is perhaps going to be the Golden Age of the mercenary, with further tech-enhancements.

Mercenary hackers aren't new, but the scale of their activities is growing rapidly. Information warfare itself is an old tactic of political entities, and nation states like the United States or even Turkey are engaged in it all of the time.


...Google said Wednesday that personal Gmail accounts of several hundred people, including senior U.S. government officials, military personnel and political activists, had been exposed. Google traced the origin of the attacks to Jinan, China, the home city of a military vocational school whose computers were linked to a more sophisticated assault 17 months ago on Google's systems." ... ("US says no... ," AP, June 2, 2011)

Most modern nation states are engaging in it at some stage, but like the use of drones in recent conflicts, it remains unofficial policy, often mislabeled as "conspiracy." Cyberwarfare isn't new, but the widening scope of its use by state and "rogue" (using the term without any value judgment) actors is.

The Palfrey defense was under surveillance, period, it's inarguable and I bore witness to it directly. Some will say that it was for legitimate purposes of the enforcement of the law, but how then would any defendant get a fair trial under such scrutiny? What's arguable is who it might have been which one could speculate on endlessly with such a muddied trail. That's how it goes with hacking and cyberattacks, but with enough persistence and even some luck the origins of a hit can sometimes be uncovered. The key is to erase as much of a trail leading to the originator of the attack as possible and it's not rocket science, but not so prevalent or as easy in the
stone age days of the Internent back in the fall of 1998 when the madam's account was hacked.

Even at the time what they did wasn't especially sophisticated, but the average Internet user wouldn't have known how to do the breach and what followed from it.

Just shy of ten years later I had a productive exchange with a former attorney of the DC Madam's about the breaching of the her email account:

Jeane and I searched and searched and finally traced the insertion of a email forwarding address in her earthlink account to a Yahoo.uk email address. When I took it up with yahoo.uk, they had no answer how anyone had hacked into Jeane's account and could not identify the owner of the yahoo.uk email account as it was to a string of fictious email accounts. (Correspondence with the Editor, August 2008)

This was to be expected whether it was a state actor or not. It's a very good possibility that this was a former client of Pamela Martin & Associates, but that could just as well mean the arrow points to the state as well as contractors.

What raised a few flags this week for me came from this passage in an AP article on the recent breaches in Google's Gmail infrastructure that compromised some of the personal email accounts of a few high level American officials.

The modus operandi is similar if not identical to the breaches in the DC Madam's Sprynet email account back in 1998:

...While Google said last year's attack was aimed at its corporate infrastructure, the latest incident appears to have relied on tricking email users into revealing passwords, based on Google's description in its blog post.

It said the perpetrators changed the victims' email forwarding settings, presumably secretly sending the victims' personal emails to other recipients. ... ("Google reveals... ," Reuters, June 2, 2011 )

The final sentence is exactly what happened to the DC Madam's email account sometime in October 1998.

It's almost become a cliche that intelligence agencies (and similar institutions and groups) can and have used primitive forms of hacking as a cover for the activities against various actionable targets. Perhaps one day we'll find through declassifications that a government contractor created all of those phony email accounts when Palfrey began to become a "person of interest" to whoever hacked her account and changed her forwarding settings, intercepting all of her emails going in and out (I know from experience as I was receiving bouncebacks once the phony account had been closed). Most likely, she was beginning to become a liability to a privileged former client...but the truth of the case is elusive as ever.


"US says no official email hacked; FBI on case," AP, June 2, 2011): http://enews.earthlink.net/article/top?guid=20110602/39b5ae26-4471-4ea8-b6c5-afbde96ef979

"Google reveals Gmail hacking, says likely from China," Reuters, June 2, 2011: http://news.yahoo.com/s/nm/us_google


Friday, September 14, 2007

Kenton Clark, Fictional 'Attorney'


WWW
-At this writing, Ms. Palfrey, myself, and her civil attorney are still receiving return error e-mails every single time we correspond and send to each other. In the beginning (there was God), virtually everyone I would send to would return this way, but it narrowed to just Ms. Palfrey and Montogmery Blair Sibley.

This is extremely telling, because with the narrowing, one gets the possible indication that parameters were being set--initially, all of my e-mail, then just between the aforementioned. It wouldn't surprise me if it was some 'vigilante' action by some goober with people-clothing and some tech know-how (and a stunted, reactionary personality).


There are--of course--other possibilities, such as that what we're experiencing is a very desperate prosecution team abusing antiterror laws at the Justice Department. Remember that last week, federal district Judge Victor Marrero ruled against NSLs to internet and telecommunications providers with broad discretion, including gag orders to the recipients of the NSLs (like say, Google or Verizon, and even AT&T or Yahoo). At present, there are a little over 80-days left for the government to appeal Judge Marrero's decision. In the mean time, they can still keep ISPs under the gag, and continue their fun-and-games, even with boss Alberto leaving today.

Again, it could just be some aspiring Tim McVeigh(s) out there, reactionary vigilante-types who think that some dumb games with someone's e-mail is going to intimidate. What's interesting is the intended-effect on the new round of hacker foreplay: not obstructing our First amendment guarantee of free and open communication with each other, but to temporarily create the impression that we're receiving send errors and that the messages aren't reaching Ms. Palfrey, Mr. Sibley, or myself.

This would suggest that fear of being caught violating our ability to correspond--since it's illegal and protected speech--is in the puny fore brain(s) of whomever is expediting the action(s). It's not paranoia, it's happening, see the post below for a sample of the error mails, they're all the same.


Who is it? We don't know yet, but we're looking into it. Luckily, the individuals doing this aren't very bright, they've made a few mistakes that give away parts of their identities: we know for a fact that whomever is doing it is American. Why? In every e-mail return message, the same phony lawyer's name occurs--Kenton Clark, which is found most often in '419' spams, usually from Nigeria. So? Ms. Palfrey found the significance this time: the error messages all contain this address, 'attorneykentonclark_office@yahoo.co.uk' (it's dead). In the UK, a lawyer is commonly referred to as a 'barrister,' not an attorney.

And today, Ms. Palfrey and I received some e-mails from an anonymous individual via http://www.hush.com/. [Ed., 08.28.2008--This turned-out to be a friendly contact!] Curiouser and curiouser. Sam Eardth: kiss my ass.