.

ad test

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, September 17, 2017

Well, This is Great

Did you know that Equifax runs the My Social Security and is responsible for verifying data for Obamacare exchanges for the US government?

You know, that whole, "Reinventing Government", thing that Bill Clinton put forward in the 1990s, when critical government functions were outsourced to private for-profit operators, is looking to be an even worse deal than when it was first implemented in the mid-1990s.

Of course, efficiency and savings were never really the goals: It was a depressingly successful attempt to subvert the civil service laws and to return to the spoils system.

Just ask President Garfield how well that worked out.

Friday, September 8, 2017

How to Check the Equifax Hack Without Signing Away Your Rights

Equifax just got hacked, with perhaps as many as 143 million Americans had their data compromised.

In response, Equifax put a link on their site to see if your link had been compromised.

There was one problem though, they make you jump through hoops, and try to get you into their credit monitoring service, which involves signing away your rights to sue.

There's also related insider trading by senior executives between when the breach was discovered and when it became public, but that's another post.

I am now going to walk you through how to check if your data was compromised while not signing up for their bogus credit monitoring service and entering binding arbitration hell. (Facebook users, click through for all the pictures)

The joys of American business: They f%$#ed up, and f%$# millions of people, and Equifax's response is to try to f%$# these people another time.

Well, here are the instructions:

  • Go to equifax.com and click the marked link:


  • On the next page DON'T click on the link at the top:


  • Scroll down and click here:


  • On the next page click the "check potential impact" button:


  • And you are FINALLY taken to a page where you can check if your record was compromised:
Equifax should be put out of business.

Thursday, July 27, 2017

This is F%$#ed Up and Sh%$

Yesterday I wrote about a Pakistani crime ring operating out of the of a number of Democratic Congressional offices.  (As if that wasn't weird enough).

It turns out that they got fired once the investigations of equipment and data theft became known by every office at which they worked, except for Debbie Wasserman Schultz's office.

She did not fire her larcenous staffer until after his arrest for fraud:

When a computer expert who worked for congressional Democrats was accused of stealing computers and data systems in February, members of Congress cut him loose within days, leaving Imran Awan with no supporters five months later.

Except for Rep. Debbie Wasserman Schultz.

The Weston Democrat has not explained in detail why she continued to employ Awan until Tuesday when she fired him — after he was arrested on bank-fraud charges at Dulles International Airport in Virginia attempting to board a flight to Pakistan.

And she has not elaborated on what work Awan did for her after he lost access to the House computer network.

She declined to answer questions about Awan in Washington on Wednesday, and her spokesman, David Damron, accompanied her to the House floor while instructing a reporter that Wasserman Schultz would not take questions about her former employee.

………

But months after Awan was fired by everyone else, Wasserman Schultz grilled Capitol Police Chief Matthew Verderosa in May over why computer equipment was confiscated from her office as part of the investigation into Awan even though she was not under investigation.

“Under my understanding, the Capitol police are not able to confiscate a member’s equipment when the member is not under investigation,” Wasserman Schultz said. “It is their equipment and it is supposed to be returned.”

Verderosa told Wasserman Schultz that he couldn’t return the equipment without the permission of the investigation.
Am I the only one who thinks that this is hinky beyond words?

There are only two reasons I can see behind this, either Awan has something truly damming on DWS, or DWS hired Awan to spy on her colleagues in Congress.

Something here is crookeder than ……… sh%$ ……… I've run out of analogies.

Wednesday, July 26, 2017

OK, This is Very Weird

It appears that a group of Congressional aides, most of them working for Debbie Wasserman Schultz in some capacity, and all of them originally from Pakistan, have been under criminal investigation, and one of Wasserman Schultz's aides was arrested trying to catch a flight to Pakistan: (Background stories going back to February here and here)
Imran Awan, a House staffer at the center of a criminal investigation potentially affecting dozens of Democratic lawmakers, has been arrested on a bank fraud charge and is prevented from leaving the country while the charge is pending.

A senior House Democratic aide confirmed Awan was still employed by Rep. Debbie Wasserman Schultz (D-Fla.) as of Tuesday morning. But David Damron, a spokesman for Wasserman Schultz, later said that Awan was fired on Tuesday.


Awan pleaded not guilty on Tuesday to one count of bank fraud during his arraignment in the U.S. District Court for the District of Columbia.

Awan is accused of attempting to defraud the Congressional Federal Credit Union by obtaining a $165,000 home equity loan for a rental property, which is against the credit union’s policies since it is not the owner’s primary residence. Those funds were then included as part of a wire transfer to two individuals in Faisalabad, Pakistan.

Awan was arrested Monday evening at Dulles International Airport in Virginia before boarding a flight to Lahore, Pakistan. His wife, Hina Alvi, had earlier left the country for Pakistan, along with their children. Federal agents do not believe Alvi has any intention of returning to the U.S., according to a court document.

………

Awan, a longtime IT staffer who worked for more than two dozen House Democrats, has been at the center of a criminal investigation on Capitol Hill for months related to procurement theft. Several of his family members, also IT staffers at the time, were implicated in the ongoing investigation.

………

Alvi, another House staff member involved in the Capitol Hill investigation, left the country with their three daughters, headed for Pakistan, in March, according to an affidavit filed in the Awan case. Alvi had “numerous pieces of luggage” and more than $12,000 in cash, FBI agent Brandon Merriman wrote in the affidavit.
(emphasis mine)

The stories of he investigation at Politico go back to early February, which means that, unlike the claims made by Mr. Awan's lawyer, any investigation almost certainly began under the Obama administration.

There are also allegations of equipment and data theft, and these people worked for Democratic members of Congress for years.

This is f%$#ing weird, and I'm wondering if this is organized crime or some sort of ISI operation gone pear shaped.

Monday, July 24, 2017

United Strikes Again

United notified passengers that they could not check check comic books in as luggage if they were flying to Comic Con in San Diego, because ……… Transportation Security Administration (TSA).

The TSA released a statement that United Airlines had f%$#ed up: (Also here)

Don’t worry Comic-Con fans, you don’t have to remove your comic books from your checked luggage, despite what a Sunday photo circulated on Twitter suggests.

The dust-up began after a person named Adi Chappo tweeted the above, tagging United Airlines, which responded on Twitter:





But by Monday, the Transportation Security Administration was saying that no such restriction existed.



Lorie Dankers, a TSA spokeswoman, told Ars on Monday morning that she was mystified as to how United could get this policy wrong. “I don’t know how United went ahead and stated a TSA policy incorrectly,” she said. “I can say that TSA has advised in the past that if people bring several of the same type of item, it can alarm the checked baggage screening, but there is no prohibition on bringing things that are not a security threat. In this case, comic books are not a security threat and we encourage travelers to bring them if they so choose.”
Seriously, they make big bank on checked bags, so it takes a special type of incompetence to do this.

They are both inconveniencing the customer and losing money on the deal.

Friday, May 19, 2017

Reality is Weird

Have you heard of the The U.S. Cyber Consequences Unit?

Here is their description of themselves:

The U.S. Cyber Consequences Unit (US-CCU) is an independent, non-profit (501c3) research institute. It provides assessments of the strategic and economic consequences of possible cyber-attacks and cyber-assisted physical attacks. It also investigates the likelihood of such attacks and examines the cost-effectiveness of possible counter-measures.

Although the US-CCU aims to provide credible estimates of the costs of ordinary hacker mischief and white collar crime, its primary concern is the sort of larger scale attacks that could be mounted by criminal organizations, terrorist groups, rogue corporations, and nation states.

The mission of the US-CCU is to provide America and its allies with the concepts and information necessary for making sound security decisions in a world where our physical well-being increasingly depends on cyber-security. The reports and briefings the US-CCU produces are supplied without charge to the government, to entire critical infrastructure industries, and to the public.
Do you know what the name of their director is?

It's Scott Borg.

Sunday, May 14, 2017

1000 Words on the Internet of Things


Link

We……… Got ……… Lucky

Here is a very good account of how a techie more or less accidentally found the off switch for this weeks ransomware attack.

It's not really an accident, though the techie, one "MalwareTech", describes it as such.

Basically, he has a procedure, and a check list of sorts for evaluating this sort of thing.

Because he followed this procedure, he found that the software phoned home to an unregistered domain, and he registered that domain, and its existence functioned as a kill switch.

As I've said before, this is not an accident: this is a byproduct of proper procedures.

Much like a pilot's preflight checklist, success is a byproduct of a deliberate process, and not some random stroke of luck.

As Baseballer Branch Ricky pithily noted, "Luck is a residue of Design."

Thursday, April 13, 2017

Pull All of His Security Detail, and Let Market Forces Rule

Scott Pruit, environment hating wingnut and current head of the Environmental Protection Agency, is requesting a round the clock security detail in his next budget.

It appears that in addition to being a corrupt stooge of the energy industry, he's also an abject coward:

The administrator of the US Environmental Protection Agency, historically, has had some measure of government-funded personal security detail. Agents routinely picked Gina McCarthy from the airport, for example, or accompanied her on site visits during her time as EPA administrator from July 2013 to Jan 2017. But Scott Pruitt, the new EPA chief, wishes to be guarded 24/7.

………

The Times calls it a first for an EPA chief, and notes that the 10 additional agents would more than double the agency’s current security staff, which has hovered between six and eight agents in recent years. Similarly, security detail for education secretary Betsy DeVos has reached unprecedented levels: Typically, the secretary of education is guarded by about six agents from within the Department of Education. Since her contentious confirmation, DeVos has been under the protection of the US Marshals Service, costing $8 million over eight months.

What security menace is Pruitt guarding against? According to Myron Ebell, who led Trump’s EPA transition team but is no longer employed by the administration, Pruitt is at risk from his own employees—and “the left.”
Seriously, the wingnuts spend their days soiling their pants in abject terror.

Wednesday, March 29, 2017

More News from the Internet of Things

In another episode of how manufacturers are f%$#ing things making ordinary objects around your house internet enabled, now hackers can take over your dishwasher:
Don't say you weren't warned: Miele went full Internet-of-Things with a network-connected dishwasher, gave it a web server, and now finds itself on the wrong end of a security bug report – and it's accused of ignoring the warning.

The utterly predictable vulnerability advisory on the Full Disclosure mailing list details CVE-2017-7240 – aka "Miele Professional PG 8528 - Web Server Directory Traversal.” This is the builtin web server that's used to remotely control the glassware-cleaning machine from a browser.

“The corresponding embedded Web server 'PST10 WebServer' typically listens to port 80 and is prone to a directory traversal attack, therefore an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks,” reads the notice, dated Friday.

………

And because Miele is an appliance company and not a pure-play IT company, it doesn't have a process for reporting or fixing security bugs. The researcher who noticed the dishwasher's web server vuln – Jens Regel of German company Schneider-Wulf – complains that Miele never responded when he contacted the biz with his findings; he says his first contact was made in November 2016.

Appliance makers: stop trying to connect stuff to networks, you're no good at it.
I would also add, regulators need to police this stuff, and civil liability law needs to be rewritten to ensure that the manufacturers, and perhaps senior management are explicitly liable for this crap, including punitively harsh mandatory penalties.

If copyright trolls can threaten 6 figure judgements against people's kids who Bit Torrent a Nickelback song,* then these manufacturers need to face at least that much jeopardy.

*I will note, if your kids are downloading Nickelback, I do think that a visit from Child Protective Services (CPS) might be in order, because, well, it's f%$#ing Nickelback.

Thursday, March 9, 2017

I am Surprised and Impressed

It appears that Wikileaks is exercising a bit more due diligence in its releases, as it is making the CIA hacks leaked to it available to the tech firms that were targeted before making them available to the general public:

Technology firms will get "exclusive access" to details of the CIA's cyber-warfare programme, Wikileaks has said.

The anti-secrecy website has published thousands of the US spy agency's secret documents, including what it says are the CIA's hacking tools.

Founder Julian Assange said that, after some thought, he had decided to give the tech community further leaks first.

"Once the material is effectively disarmed, we will publish additional details," Mr Assange said.

………

Mr Assange said that his organisation had "a lot more information on the cyber-weapons programme".

He added that while Wikileaks maintained a neutral position on most of its leaks, in this case it did take a strong stance.

"We want to secure communications technology because, without it, journalists aren't able to hold the state to account," he said.

Mr Assange also claimed that the intelligence service had known for weeks that Wikileaks had access to the material and done nothing about it.

He also spoke more about the Umbrage programme, revealed in the first leaked documents.

He said that a whole section of the CIA is working on Umbrage, a system that attempts to trick people into thinking that they had been hacked by other groups or countries by collecting malware from other nation states, such as Russia.

"The technology is designed to be unaccountable," he said.

He claimed that an anti-virus expert, who was not named, had come forward to say that he believed sophisticated malware that he had previously attributed to Iran, Russia and China, now looked like something that the CIA had developed.
This is why cyber security needs to be completely separate from any intelligence agency.

Otherwise, there is too much pressure to cover up the bugs so that the folks on the other side of the office spy on the rest of us.

Any hole which the CIA, NSA, DIA, or other TLA* can exploit can also be exploited by criminals, the Chinese, the Russians, terrorists, or the New England Patriots.

*Three letter acronym.

Wednesday, February 8, 2017

Scary Tweet of the Day

Of course, who cares about a lightweight relatively cheap drone.

Then again, what if this was a self driving car, or even the car that you are driving now? While you are driving it?

Tesla has already done over the air (OTA) updates on their cars, and while you may trust them, (I don't) would you trust the creators of the Chevy Vega?

H/t Naked Capitalism

Tuesday, November 29, 2016

I Didn't Think That It Was Possible, but Donald Trump Just Disappointed Me


Maddow has some more on this sorry excuse for a human being
OK, not just disappointed. I am also horrified, but I kind of expect to be horrified by him.

I did not expect to be disappointed, because my expectations are so f%$#ing low, but the inverted traffic cone has outdone himself.

Specifically, Trump's appointee as deputy national security adviser, Kathleen Troia "KT" McFarland, who is infamous for outing her brother as gay to her family while he was dying of AIDS:
In between Twitter claims that he lost the popular vote due to voter fraud instead of due to alienating over half the nation by being the dictionary definition of "The Worst," President-elect Donald Trump somehow finds time to fill out his staff with people you wouldn't trust to pick up dog sh%$.

As the Washington Blade reports, Trump's pick for deputy national security adviser is basically a monster. Kathleen Troia "KT" McFarland, FOX News contributor and former Pentagon official during the Reagan administration, outed her gay brother, who was dying of AIDS, to their family.

The Blade is referring to a 2006 New York Magazine article, when McFarland was gearing up to challenge Hillary Clinton for her Senate seat, which unearthed a 1992 letter to her then-estranged parents:

“Have you ever wondered why I have never had anything to do with Mike and have never let my daughters see him although we live only fifteen minutes away from each other?” she wrote. “He has been a lifelong homosexual, most of his relationships brief, fleeting one-night stands.”
McFarland tried to downplay the letter at the time, claiming it was a form of therapy to deal with abuse she and her siblings had suffered at the hands of their parents—abuse both her parents and at least one of her siblings denied.

“It’s a complete fabrication,” Tom Troia told the New York Post back in 2006 regarding his sister’s allegations. “If I had one word to describe my sister, it would be ‘evil.’”

………

Former Geroge W. Bush National Security Council member Peter D. Feaver told The Times McFarland's job is supposed to be "the place where bad ideas die," but as Donald Trump's other appointees make glaringly clear, there is no longer such a place.

(%$ mine)

There is also the long history of resume padding, as Maddow discusses above, but that doesn't disappoint me:  I expect sh%$ like that from a Trump administration.

Thursday, October 27, 2016

We Are Doomed

It now appears that the recent hack against DYN was the work of script kiddies.

Heaven help us if the pros decide to do something like this:
Business risk intelligence firm FlashPoint has put out a preliminary analysis of last week’s massive denial of service attack against Dyn DNS, and its conclusion is it was likely the work of amateur hackers — rather than, as some had posited, state-sponsored actors perhaps funded by the Russian government.

The DDoS attack against Dyn’s domain name system impacted access to a range of sites in parts of the U.S. last Friday, including PayPal, Twitter, Reddit, GitHub, Amazon, Netflix, Spotify and RuneScape.

Aside from suspicion falling on Russia, various entities have also claimed or implied responsibility for the attack, including a hacking group called the New World Hackers and — bizarrely — WikiLeaks, which put out a (perhaps joke) tweet suggesting some of its supporters might be involved.

FlashPoint dubs these claims “dubious” and “likely to be false”, and instead comes down on the side of the script kiddies theory.

Its reasoning is based on a few factors, including a detail it unearthed during its investigation of the attack: namely that the infrastructure used in the attack also targeted a well-known video game company.

“While there does not appear to have been any disruption of service, the targeting of a video game company is less indicative of hacktivists, state-actors, or social justice communities, and aligns more with the hackers that frequent online hacking forums,” writes FlashPoint’s Allison Nixon, John Costello and Zach Wikholm in their analysis.
This is going to get very ugly very fast.

I might suggest that making sure that equipment manufacturers can be held liable for these sort of bone-headed vulnerabilities.

Yes, Ask the Worst Administration on Privacy Ever to Help Us

The Mozilla Foundation is asking for the White House to coordinate efforts to prevent cyber attacks.

The Obama administration has been at the forefront of efforts to make computers less secure by requiring back doors in the software.

You don't want Barack Obama Evil Minions anywhere near commercial cyber security policy.

Hen house, meet fox.

Sunday, September 25, 2016

Krebs on Security is Back Online

The security blogger's highly regarded site was taken down by a massive DDOS attack, which forced Akamai to drop him from their protection system:

………

However, events of the past week have convinced me that one of the fastest-growing censorship threats on the Internet today comes not from nation-states, but from super-empowered individuals who have been quietly building extremely potent cyber weapons with transnational reach.

More than 20 years after Gilmore first coined that turn of phrase, his most notable quotable has effectively been inverted — “Censorship can in fact route around the Internet.” The Internet can’t route around censorship when the censorship is all-pervasive and armed with, for all practical purposes, near-infinite reach and capacity. I call this rather unwelcome and hostile development the “The Democratization of Censorship.”

Allow me to explain how I arrived at this unsettling conclusion. As many of you know, my site was taken offline for the better part of this week. The outage came in the wake of a historically large distributed denial-of-service (DDoS) attack which hurled so much junk traffic at Krebsonsecurity.com that my DDoS protection provider Akamai chose to unmoor my site from its protective harbor.

Let me be clear: I do not fault Akamai for their decision. I was a pro bono customer from the start, and Akamai and its sister company Prolexic have stood by me through countless attacks over the past four years. It just so happened that this last siege was nearly twice the size of the next-largest attack they had ever seen before. Once it became evident that the assault was beginning to cause problems for the company’s paying customers, they explained that the choice to let my site go was a business decision, pure and simple.

………

Today, I am happy to report that the site is back up — this time under Project Shield, a free program run by Google to help protect journalists from online censorship. And make no mistake, DDoS attacks — particularly those the size of the assault that hit my site this week — are uniquely effective weapons for stomping on free speech, for reasons I’ll explore in this post.

Why do I speak of DDoS attacks as a form of censorship? Quite simply because the economics of mitigating large-scale DDoS attacks do not bode well for protecting the individual user, to say nothing of independent journalists.

In an interview with The Boston Globe, Akamai executives said the attack — if sustained — likely would have cost the company millions of dollars. In the hours and days following my site going offline, I spoke with multiple DDoS mitigation firms. One offered to host KrebsOnSecurity for two weeks at no charge, but after that they said the same kind of protection I had under Akamai would cost between $150,000 and $200,000 per year.

………

What exactly was it that generated the record-smashing DDoS of 620 Gbps against my site this week? Was it a space-based weapon of mass disruption built and tested by a rogue nation-state, or an arch villain like SPECTRE from the James Bond series of novels and films? If only the enemy here was that black-and-white.

No, as I reported in the last blog post before my site was unplugged, the enemy in this case was far less sexy. There is every indication that this attack was launched with the help of a botnet that has enslaved a large number of hacked so-called “Internet of Things,” (IoT) devices — mainly routers, IP cameras and digital video recorders (DVRs) that are exposed to the Internet and protected with weak or hard-coded passwords. Most of these devices are available for sale on retail store shelves for less than $100, or — in the case of routers — are shipped by ISPs to their customers.

Some readers on Twitter have asked why the attackers would have “burned” so many compromised systems with such an overwhelming force against my little site. After all, they reasoned, the attackers showed their hand in this assault, exposing the Internet addresses of a huge number of compromised devices that might otherwise be used for actual money-making cybercriminal activities, such as hosting malware or relaying spam. Surely, network providers would take that list of hacked devices and begin blocking them from launching attacks going forward, the thinking goes.
The sheer disproportionality of the attack made one of his Krebs readers notes that this is odd, it's like the Death Star being tested out on the Millennium Falcon, rather than Alderran, but Krebs notes that with connectivity providers ignoring a very basic 12 year old protocol, (BCP38) it's more like there are an infinite supply of cloned warriors.  (Mostly, I prefer not to use Star Wars analogies myself.)

My thought is that this was a test. Krebs on Security was a well protected target, but taking it off line for a few days is not a huge deal in the scheme of things.

I think that it was a dress rehearsal, and so the question is what is going to be the main event.

Tuesday, August 16, 2016

Sauce for the Gander

After decades of merrily hacking into other people's computers and snooping on people's emails, it appears that the NSA has been hacked.

A group of hackers are trying to auction off malware that the spy organization has been using to spy on the rest of us:

A mysterious online group calling itself “The Shadow Brokers” is claiming to have penetrated the National Security Agency, stolen some of its malware, and is auctioning off the files to the highest bidder.

The authenticity of the files cannot be confirmed but appear to be legitimate, according to security researchers who have studied their content. Their release comes on the heels of a series of disclosures of emails and documents belonging mostly to Democratic officials, but also to Republicans. Security researchers believe those breaches were perpetrated by agents thought to be acting on behalf of Moscow.

The NSA did not answer Foreign Policy’s questions about the alleged breach on Monday. But if someone has managed to penetrate the American signals intelligence agency and post its code online for the world to see — and purchase — it would constitute a historic black eye for the agency.

………

The files posted over the weekend include two sets of files. The hackers have made one set available for free. The other remains encrypted and is the subject of an online auction, payable in bitcoin, the cryptocurrency. That set includes, according to the so-called Shadow Brokers, “the best files.” If they receive at least 1 million bitcoin — the equivalent of at least $550 million — they will post more documents and make them available for free.

The set of files available for free contains a series of tools for penetrating network gear made by Cisco, Juniper, and other major firms. Targeting such gear, which includes things like routers and firewalls, is a known tactic of Western intelligence agencies like the NSA, and was documented in the Edward Snowden files. Some code words referenced in the material Monday — BANANAGLEE and JETPLOW — match those that have appeared in documents leaked by Snowden. Security researchers analyzing the code posted Monday say it is functional and includes computer codes for carrying out espionage.
If this hack is real, my guess is that they got in through backdoors that the NSA itself insisted on.



Friday, August 12, 2016

I Don't Believe Them

Tor promises not to build back-doors into its services.

Considering the fact that much of their funding comes from the US State security apparatus, and that their statement leaves a lot of wiggle room for things like securing the various supporting infrastructure from 3rd parties, I'd go back to using carrier pigeons, only attach an encrypted microSD card to their ankle.

Wednesday, August 3, 2016

It's Called Paper

The Department of Homeland Security is looking at ways to safeguard electronic voting machines from hackers.

It's really pretty simple, you eliminate the purely electronic machines, and go with optically scanned machines, which will give you a count in roughly the same time, and then you do a manual recount of a small portion of the precincts.

If you want to retain purely electronic machines, I'd suggest that you require that the software be open source, so that it can be audited.

Instead, they will probably shovel money at Diebold and their ilk:

The Obama administration is weighing new steps to bolster the security of the United States’ voting process against cyberthreats, including whether to designate the electronic ballot-casting system for November’s elections as “critical infrastructure,” Jeh Johnson, the secretary of Homeland Security, said on Wednesday.

In the wake of hacks that infiltrated Democratic campaign computer systems, Mr. Johnson said he was conducting high-level discussions about “election cybersecurity,” a vastly complex effort given that there are 9,000 jurisdictions in the United States that have a hand in carrying out the balloting, many of them with different ways of collecting, tallying and reporting votes.

………

Mr. Johnson said he was considering communicating with state and local election officials across the country to inform them about “best practices” to guard against cyberintrusions, and that longer-term investments would probably have to be made to secure the voting process.

“There are various different points in the process that we have to be concerned about, so this is something that we are very focused on right at the moment,” Mr. Johnson said.

His comments were the latest evidence that recent cyberintrusions have caused alarm in the administration about the potential for hacking to disrupt the election, and how to respond.
Seriously, this sh%$ ain't rocket science.

Use paper ballots, and make selected public hand recounts of a small randomly selected group of sites.

It's really that simple.

Tuesday, June 9, 2015

Obama's Lawless Behavior in Support of the Security State

You may recall that the NSA bulk data collection of phone records were ruled by an Federal appellate court.

It not turns out that the Obama administration tried to get a ruling from the FISA court saying that they could ignore this ruling.

The interesting bit here is that the FISA court is technically a district court, and so is subordinate to an appellate court.

This shows a complete contempt for the rule of law:
The Obama administration has asked a secret surveillance court to ignore a federal court that found bulk surveillance illegal and to once again grant the National Security Agency the power to collect the phone records of millions of Americans for six months.

The legal request, filed nearly four hours after Barack Obama vowed to sign a new law banning precisely the bulk collection he asks the secret court to approve, also suggests that the administration may not necessarily comply with any potential court order demanding that the collection stop.

US officials confirmed last week that they would ask the Foreign Intelligence Surveillance court – better known as the Fisa court, a panel that meets in secret as a step in the surveillance process and thus far has only ever had the government argue before it – to turn the domestic bulk collection spigot back on.

Justice Department national security chief John A Carlin cited a six-month transition period provided in the USA Freedom Act – passed by the Senate last week to ban the bulk collection – as a reason to permit an “orderly transition” of the NSA’s domestic dragnet. Carlin did not address whether the transition clause of the Freedom Act still applies now that a congressional deadlock meant the program shut down on 31 May.

But Carlin asked the Fisa court to set aside a landmark declaration by the second circuit court of appeals. Decided on 7 May, the appeals court ruled that the government had erroneously interpreted the Patriot Act’s authorization of data collection as “relevant” to an ongoing investigation to permit bulk collection.

Carlin, in his filing, wrote that the Patriot Act provision remained “in effect” during the transition period.

“This court may certainly consider ACLU v Clapper as part of its evaluation of the government’s application, but second circuit rulings do not constitute controlling precedent for this court,” Carlin wrote in the 2 June application. Instead, the government asked the court to rely on its own body of once-secret precedent stretching back to 2006, which Carlin called “the better interpretation of the statute”.
While it is true that  the FISA court is not technically under the 2nd court of appeals, which ruled the program illegal, because they are not in the 2nd district, (technically, they are not in any district) but blithely asking the court to overrule an appeals court shows a complete contempt for due process and the rule of law.

Worst Constitutional Law Professor Ever!