Tuesday, August 21, 2012

Password Security

Ars Technica has an excellent article on the state of password security. It used to be that if you had a password with a mix of lower and upper case letters that was at least eight or nine characters long you were pretty secure. However over the past several years, the art and science of password cracking has changed considerably. The bottom line is you and your organization may be more at risk than you think. If your passwords aren't at least 13 characters long, you're not using randomly generated passwords for sensitive accounts and information, and you don't know what KeePass or Password Safe are, be sure to read the article.

Labels:

Saturday, August 11, 2012

Online Security for Human Rights Workers

Wired has a nice, non-technical piece on the challenges of providing effective online security for those involved in human rights work.

Labels:

Wednesday, July 25, 2012

Hacked Hotel Doors

The Black Hat security conference in Las Vegas always exposes interesting security vulnerabilities. This year is no different, with news that the Onity card lock used on millions of hotel rooms is vulnerable to a hack attack. With about $50 worth of hardware parts and a bit of programming, an unauthorized person can open a locked door from the outside. See the Forbes article here and the presentation and paper here.

A couple of points to consider. Not all hotels use Onity locks (VingCard, CISA, and Safelok are a few other popular brands). There's a higher probability of a corrupt hotel employee accessing your room without your permission than a hacker. Most doors feature some type of mechanical lock in the form of a chain or swing lock that secure the room from the inside when occupied (it's worth noting that these locks do not offer 100% security, and can be readily defeated by a knowledgable person).

A cheap and simple solution to securing a hotel room while you're inside (or a room with any door that opens inward) is to use rubber door stopper. Jam the stopper between the door and floor. There is usually enough friction to prevent the door from opening. Give it a try.

International Security/Espionage Trivia: Some security practitioners may recall the 2010 assassination of Hamas member Mahmoud Al-Mabhouh in Dubai. The Mossad was alleged to have hacked the card lock on Mabhouh's hotel room and waited for his return. The Al Bustan Rotana hotel, where Mabhouh stayed, uses VingCard locks. Dubai authorities reported there was evidence that someone reprogrammed the lock at the door to gain access to the room before Mabhouh was killed.

Labels:

Thursday, May 03, 2012

Turning security documents into ebooks

If iPads and iPhones are popular in your organization, you might want to consider distributing organizational security documents in a format that's iOS compatible (policies and procedures, security manuals, and checklists are all good candidates).

While Apple tablets and smart phones can display PDF files, the format isn't very usable on smaller screens. Text doesn't flow correctly due to the device's screen size and the constant scrolling and zooming in and out really detracts from reading.

Instead of PDFs you should be thinking ebook files. Apple and Android tablets and phones have ebook readers (either built-in or freely downloadable) that are designed to make reading and searching certain file types a snap. The most widely used ebook file format is called ePub. And converting Word documents into ePub (and other ebook formats) is surprisingly simple.

The tool of choice is a free (donations appreciated) program called Calibre. Calibre is designed to manage your collection of ebooks but it can also convert ebooks from one format to another; for example you can take an Apple compatible ePub file and convert it to an Amazon Kindle readable Mobi format file. Turning security documents created with Word into ePub files is pretty easy. Here are the basic steps:
  1. Save the Word document as RTF
  2. Run Calibre and add the file to your ebook library
  3. Select the RTF document and convert to ePub
Calibre will crunch away and convert the file, retaining the formatting. When it's finished, the file is ready to distribute as an ebook, and be happily read by staff members on a tablet or phone.

Calibre has been around since 2006 and is widely used and well documented. There are versions for Windows, OS X, and Linux operating systems. It's the defacto tool for ebook geeks, but you don't need to be a techie to successfully use it.

The other tool I have at the ready when creating ebook security documents is called Sigil. It's a free ePub editor. At times Calibre isn't perfect, and the formatting of a converted file can get messed up a bit. In those cases I'll open the file up in Sigil, pretty things up (it's just like using a word processor), then save the changes. Sigil isn't quite as mature as Calibre in terms of usability and reliability (it's still a work in progress), but it's still very useful and usable.

Note: If you're an open-source fan and use OpenOffice or LibreOffice there also are extensions available that allow you to create ePub files from within the word processor (such as Writer2ePub). I haven't had any experience with these add-ons, but they may be worth checking out.

Labels:

Wednesday, February 29, 2012

Big Brother Is Watching

The Electronic Privacy Information Center recently released a document obtained through a Freedom of Information Act (FOIA) request that details US Department of Homeland Security (DHS) monitoring of social networks/media on the Internet (download the PDF file here). The document has a lengthy list of Items of Interest keywords that DHS searches for in Twitter tweets, Facebook pages, and forum and blog posts. Automated programs troll the Net vacuuming up information and if a keyword (or certain sequence of keywords) occurs, the source is flagged, and a human analyst reviews the content.

Government monitoring of the Net is nothing new (obligatory ECHELON reference). I remember back in the pre-Internet 1980s, conspiracy-minded programmers would often include a signature line in their email messages and USENET posts that contained words such as CIA, KGB, Cuba, Bomb, and Mossad. Dubbed NSA bait, the thought was the words would set off alarm bells somewhere and an analyst would be forced to view the message contents; which had nothing to do with national security. Salting messages with suspicious keywords was probably more about making a personal, anti-establishment statement than actually hindering monitoring operations.

There are at least three, non-government IP addresses (two in the Washington DC area and one in Paris) that frequently visit the NGO Security Blog at random hours of the day. These aren't search engine bots and I've long thought this blog has been on someone's monitor list. If the DHS keyword list is any indication, it's pretty clear why. Considering the variety of state and non-state actors, locations, and topics that have been discussed in this blog over the years (Al Qaeda, UN, drug cartels, Afghanistan, Somalia, flu, and tsunami, to name a few), whistles and bells must have been going off in one or more monitoring centers.

So here's a shout-out to any government or contractor analyst who may reading this post. Nothing to see here, move along...

Labels: ,

Sunday, February 26, 2012

Stratfor emails

It appears the WikiLeaks folks have access to more than five million emails that were compromised following last December's hack of Stratfor. And they're starting to release them. A formal press release and the first batch of emails are here. It remains to be seen if there will be any potential impacts to NGOs, but stay tuned.

3/6/2012 update - Released emails are now searchable at this site.

Labels:

Friday, February 24, 2012

Plugging Google Data Leaks

Recently, I was doing some online research on security conditions in Dadaab, Kenya. I was more than a little surprised to see not-meant-for-public-distribution security reports pop up in Google (the organization they belonged to shall remain nameless). My guess was someone must have inadvertently placed the files on an open part of the organization’s Web server and Google found them. Ouch!

One of the reports had a link that directed readers to additional information. Out of curiosity I clicked it. I shook my head in disbelief as an IBM Lotus Notes page for the organization’s Nairobi office appeared. There was staff information, internal documents, and even a social calendar listing events, locations, dates, and times. None of this data was password protected. All of it was readily available to anyone with a Web browser and Internet connection who stumbled on the page by accident or perhaps had a less than innocent motive.

You don't need to be a rocket scientist to understand the potential security implications here. Especially considering Al-Shabaab’s recent threats of escalating its terror campaign in Kenya. (Non-state actors are growing increasingly sophisticated when it comes to using the Internet for identifying vulnerabilities of potential targets, by the way.)

Unfortunately, data leaks like this are a fairly common problem across the Internet. Sometimes it’s not a big deal. But in the case of international humanitarian organizations, IT boo-boos like the one above could put staff members at serious, increased levels of risk.

Most humanitarian security practitioners don’t have the background to perform thorough information security audits. And that's OK. But I want to share with you a simple and quick way of finding common sources of Web site data leaks. It doesn’t require any real technical skills. You can even try it right after reading this post and see if your organization might have virtual vulnerabilities that could produce real-world risk.

First some background is required (I promise to keep the geeky stuff to a minimum). Search engines like Google have automated programs that locate and index Web pages. These programs are known as crawlers or bots (short for robots). They’re constantly connecting to publicly accessible Web sites all over the world and reporting back what they find.

In addition to Web pages, these bots also index other files they encounter, such as Word, Excel, PowerPoint, and Adobe Acrobat documents. This is how data leaks often occur. A server is misconfigured or a sensitive document is accidentally put in a directory that allows it to be publicly viewed. A bot crawling the Web finds the file and reports its contents and link location back to the search engine company. After the file is indexed, it may then show up in someone’s search results.

Because of the sheer volume of indexed Web sites, you may think locating documents with leaky data is like finding a needle in a haystack. But guess again. Thanks to a set of advanced search parameters you can use with Google (and other search engines), it’s easy to narrow your hunt.

Here’s how. Instead of searching for Web sites that contain a certain word, use the site: option. It allows you to confine a search to a specified domain (such as apple.com or un.org). Next, use the filetype: parameter. It searches for a specific file type (.pdf or .doc are two possibilities).

Here’s an example. If you type the following in Google, it will show all of the Adobe Acrobat files on the Electronic Frontier Foundation's (eff.org) Web site:

site:eff.org filetype:pdf

You can further refine your search by adding a keyword. For example here's how to list all of the PDF files on EFF's Web site that contain the word police.

site:eff.org filetype:pdf police

See where I’m going with all of this? You can quickly troll through a site looking for documents that contain data an organization might not have wanted to share (common file types to look for include: doc, docx, odt, pdf, ppt, pptx, txt, xls, and xlsx).

Hackers do this all the time, hunting for passwords, user accounts, social security numbers, credit card numbers, and other types of data that can easily be exploited. Investigative journalists do the same thing, but look for newsworthy tidbits on government Web sites. (Keep in mind not all documents you discover this way will be leaky. Lots of files are knowingly made public.)

None of this is really breaking news. Most information security professionals have been aware of Google Hacking for a long time. There’s a lot written about it on the Web and a couple of books have been published. And in most countries it’s even legal.

Give it a try on your organization’s Web site. Have your focal points search their country office Web sites. Did you find any leaky documents that could put staff at risk? If you did, let your IT staff know about it so they can start plugging the holes. You never know when someone might be interested in your organization for the wrong reasons.

Labels: ,

Monday, February 06, 2012

Nokero Lights

I've recently been hearing good things about solar products from a company called Nokero. The firm's impetus was to design an alternative to kerosene lanterns for developing countries (Nokero is short for no kerosene). Besides environmental concerns, Kerosene fumes and smoke aren't healthy; especially for children. While FreePlay and a few other businesses have long been providing wind-up, kinetic lighting devices, Nokero took a different approach and primarily went solar. Their N100 and N200 lights are LED powered and feature a replaceable, rechargeable AA battery (sustainable). They even look like conventional incandescent light bulbs (familiar). A durable, water-resistant design coupled with an affordable price makes these lights worth considering for office back-ups or primary lighting in austere environments.

Labels:

Wednesday, February 01, 2012

Safety and Security and Wordle

If you do much browsing on the Web, you most certainly have encountered a word cloud. Word clouds have nothing to do with cloud computing, but instead are a visual representation of text. Unique words on a Web site or from some other source are listed, arranged artistically and shown in different type sizes. The size depends on word frequency, with words used more often appearing larger compared to those that are used less. For example if Afghanistan was mentioned 12 times, and Pakistan twice, Afghanistan would be displayed significantly bigger.

If you're still a little unclear on all of this, a picture is worth a thousand words, so check out: www.wordle.net; a cool utility for creating word clouds from your own text or a specified Web site. Even if you're hip to word clouds, head over to Wordle anyway. When you get there, give some thought to how you could use a word cloud in an NGO safety and security context. If nothing leaps to mind, here are a few ideas.

Identifying perceived threats and vulnerabilities - Before meeting with headquarters and field management staff for the first time, I always like to get a sense of what people feel are primary threats and vulnerabilities. Responses typically vary by job responsibilities and experience. Displaying a word cloud with the top five perceived threats and vulnerabilities (previously emailed) is a great and visually engaging way to start a conversation.

Reviewing security reports - In reviewing security reports from field offices I'll sometimes create a word cloud of the document to see if there's anything I may have overlooked. On more than one occasion, seeing something in a word cloud has prompted me to ask questions about an issue that wasn't apparent.

Analyzing emails - You can also use a collection of emails as your word cloud source, looking for things you may have missed. I remember a lengthy exchange of email messages once, about employee theft in a field office. Everyone was focused on the emotionally charged event, which involved a longtime and trusted staff member. I created a word cloud for the discussion thread which led me to an unreported and unrelated sexual harassment incident. The theft case had everyone's attention, and an oblique reference in an email had gone unnoticed.

I don't claim word clouds are magic (keep in mind that word frequency doesn't always correlate with significance). But I do find that Wordle and similar visualization tools give me a different way of looking at text data that can be surprisingly useful.

Labels:

Sunday, December 25, 2011

Stratfor hacked (including credit cards)

A number of large humanitarian organizations use the private intelligence Web site Stratfor to keep up on world events. Yesterday the site was hacked by the group Anonymous (or maybe someone else), who released the business' client list. Supposedly the client credit card database was also compromised and is being used to make donations to non-profit organizations such as the Red Cross. Some preliminary details are here. If your organization subscribes to Stratfor, it would be prudent to check if any fraudulent transactions show up on your credit card in the coming days.

12/25/2011 1500 EST Update - As of a few hours ago, it appears credit card and personal information from the hack are now being posted on the Internet. This is going to come as very unpleasant, post-holiday surprise to the 4,000 plus businesses, organizations, agencies, and individuals impacted.

12/26/2011 Update - If you've ever subscribed to Stratfor or corresponded with someone that works there, it would be wise to check Cryptome's coverage of the hack. There is a staggering amount of personal information being released as a result of this compromise.

Labels:

Friday, December 16, 2011

Securing PCs and Macs - The NSA Way

Most NGO security practitioners I know tend not to be techies and leave computer security to the IT folks. That's a shame, because information security is becoming a necessary concern just about everywhere you go. In my opinion, anyone involved with humanitarian security should have at least a basic awareness of computer-related vulnerabilities and threats. However, this doesn't mean you need to be a techie. A little knowledge and common-sense go a long way in recognizing common vulnerabilities and having intelligent conversations with IT staff.

In the past I've blogged about some of the resources the National Security Agency (NSA) provides the public through its Information Assurance program. Today I want to steer you toward a collection of guides devoted to best practices in securing operating systems. You'll find how-to information for hardening various versions of Mac OS X and Windows. Check out what the NSA has to say about the type of operating system your organization uses. Even if it all doesn't make sense, I bet you'll learn something in the process. At the very least, pass the link on to someone in your IT department. It's a good lead-in to getting together for coffee to start coming up to speed on computer security basics.

Labels:

Sunday, December 04, 2011

Pondering Power Problem Possibilities

Most people in Western countries take electricity for granted. You flip a switch and the lights come on. Your phone or iPod runs out of juice, no big deal. You just plug it into the wall. If you've done much traveling though, especially visiting field offices, you quickly learn power is something not to be taken for granted. Dirty power and brownouts fry computers and printers. Rationed electricity forces you to schedule when you'll use electronic devices. Natural disasters and government crackdowns shut off power at inopportune times. Many NGOs turn to using diesel generators and power regulation systems to ensure they can operate their offices. But this can be quite costly.

During a crisis, communication is essential. People rely on their cell phones and radios to stay in touch and manage the situation. But what happens if power isn't available for an extended period and the batteries run down? As with any problem, there are a number of possible solutions.

If you have a generator in the office, whether large or small, you can press it into service (just remember a generator requires fuel, and you should have a pretty good idea of how long it will run on your existing fuel stocks).

Solar panels are an option in sunny environments. Small panels are available for charging consumer devices like mobile phones. Some of these products even have built-in batteries that store electricity when the sun isn't shining. (I've had good luck with Solio's products). Large panels that charge lead acid batteries such as those found in cars and trucks are an even better option. Bigger batteries store more juice and can charge more devices, quicker. (You'll need an adapter that converts the direct current of a battery to the alternating current required by a charger.) Rollable panels such as those produced by PowerFilm are portable but are more expensive than rigid panels.

You may have encountered hand-operated crank radios and lights developed by FreePlay; the company has produced a number of different devices for the humanitarian community. They also make a commercial, hand-operated charger for electronic devices. (The hand charger sounds good in theory, but takes a considerable amount of time and effort to fully charge a phone. It's best for getting a few minutes of talk time in. FreePlay used to offer a foot-operated charger that was easier to use, but unfortunately it's no longer listed on their Web site.)

Car chargers for radios and mobile phones plug into the cigarette lighter of a vehicle and provide power from the vehicle's electrical system. There are also inverters available that you plug into a cigarette lighter outlet. These allow you to use an electrical device with the inverter. For example you could plug a laptop computer into the inverter just like you would in an office wall electrical outlet. (Inverters have different power ratings, so be sure the wattage of the device doesn't exceed the maximum wattage of the inverter.)

Finally, one of my favorite power to the people solutions is pedal power. MNS Power offers free plans for building a bicycle power generator. It's not portable, but you can keep electronic devices charged up while getting some exercise and burning off stress in the office.

Remember that different electrical voltages are used throughout the world. Just because you can jam a plug into an outlet doesn't mean your device will run. Pay attention to the voltage and wattage numbers associated with your device and ensure primary and backup power systems will work with them (and not send them to a smoking and burning early grave).

Labels:

Wednesday, November 30, 2011

UN Server Hacked

The hacker group TeaMp0isoN (Team Poison) compromised a United Nations Development Program server and released a collection of email addresses, names and passwords to the Internet today. BBC news story is here. The list of the accounts, as originally posted by the hackers, is here.

UNDP is downplaying the security breach, saying the server was old and didn't contain current information. This is rather disingenuous, as surveys have shown most people use the same password over and over again for various accounts. If you worked or work for UNDP, it would be prudent to check the above link to see if any of your login information was compromised. There are also email accounts for people from the Organisation for Economic Co-operation and Development (OECD), the World Health Organisation (WHO), the UK's Office for National Statistics (ONS), other UN agencies, and a variety of governments and organizations.

If you're on the rather lengthy list and have used your password elsewhere, now is a good time to start changing passwords before someone accesses your other accounts (if they already haven't).

The server hack is bad news, but equally as bad is the poor password security practices of the majority of users (first name as password, no password used, less than 6 character password, all lower case password, etc.). This is a big fail for the IT staff in not ensuring strong passwords are used (a simple and automated process), a big fail for managers if they didn't educate staff and have policies about using strong passwords, and a big fail for users who should know better.

Labels:

Thursday, September 29, 2011

LRA Crisis Tracker Map

Earlier in the month I posted about an interactive map that tracked drug violence incidents in Mexico. I mentioned it would be nice to have similar maps available for other conflict zones where humanitarian organizations work. I got an email from FHI 360 security director Norm Sheehan, that Resolve and Invisible Children are doing just that. They've released an interactive map Web site that provides information on LRA (Lord's Resistance Army) attacks in central Africa.

The map is linked to a database of reported LRA incidents, compiled from UN, NGO, and media sources. Data ranges from 2009 to the present. Whats cool is that the information is nearly real-time, with new reports of LRA activity being updated hourly (the HF radio early warning system in DR Congo is linked into the system).

I'm a "map guy" and really have to give the creators of this tool some serious credit - it's very well designed and implemented.

If your organization is doing work in South Sudan, Central African Republic, or DR Congo this resource is a must. If you're not operating in Africa, you should still check it out. I suspect it's a glimpse of what will be common within the humanitarian community in the very near future.

Labels: , ,

Sunday, September 25, 2011

Social Media and Security

I want to spend a few minutes talking about social media. That includes blogging, tweeting, forum posting, and friending. Many humanitarian security practitioners don't give social media much thought. But let me give you some real world examples I've encountered where social media went wrong and security issues arose (names, locations, and organizations aren't revealed for obvious reasons):
  • Blog posts about upcoming program site visits (including dates, destinations, and routes) in an area noted for banditry
  • Blog posts that revealed the location of an ex-pat humanitarian worker's residence (the staff member later left the conflict zone country when a Western intelligence agency warned an abduction was being planned)
  • Photos posted on a personal Web site that showed the inside of a field office (including the location of the safe)
  • An interview that appeared in an online magazine where a staff member discussed the details of refugee camp security measures
  • A Facebook page belonging to an ex-pat staff member working in a Muslim country that contained culturally insensitive photos and comments
Good security practice is all about reducing risk. Yet in each of the above cases, not enough thought was given to the security implications of online activities and the potential impact to individuals and the employing organization. (I personally believe there's a tendency for many people to treat the Internet as a separate reality that seldom, if ever, intersects with real life.)

To reduce exposure to possible consequences, a good social media policy that spells out what is acceptable online behavior is a must. In tandem, educating staff about some of the risks to themselves and their colleagues from unmindful use of social media is also essential

This falls more into a human resources versus a security responsibility within most organizations (but shouldn't stop a good security practitioner from making others aware of the risk). If your organization doesn't have a social media policy (or wants to see how others are dealing with potential issues), check out this great, free resource that provides a database of over 170 social media policies from business, non-profit, and government.

Postscript: While on the subject of social media. The Mexican drug cartels are increasing their attacks on bloggers. Listen to a recent NPR story and see this news account about a female blogger being decapitated. I wonder if this type of activity will become more widespread (in varying degrees of violence) outside of Mexico and outside of a drug cartel context. It bears watching, especially in developing country conflict zones where actors' Internet savvy is often significantly underestimated. 9/27/11 - It's not just cartels putting the squeeze on bloggers. The State of Veracruz just passed a law that makes social media illegal if it undermines public order.

Labels: ,

Monday, September 19, 2011

Google Crisis Response

Google is involved in a number of worthy environmental and humanitarian causes. One of the lesser known projects is the Google Crisis Response Team. This is a small group within the company that makes critical information more accessible during natural disasters and humanitarian crises (the team maintains a Web site here). There are many elements of Google technology that can be put to use during a crisis. Check out this recent Google.org blog post where Nigel Snoad, the team project manager, discusses tools and resources that you may be able to put to use.

I'm all for having good technology at my disposal during events which require crisis management (tools like Google Earth have become indispensable to me for planning). My one caveat though, is you should always treat a technology-based solution as just another tool in your larger crisis response toolbox. In my opinion, having solid problem-solving and decision-making skills, that aren't dependent on a specific tool, is what's really essential. That foundation, coupled with a good understanding of the strengths and limitations of each of your tools (whether hi-tech or low-tech), will make you an infinitely more effective crisis manager.

Labels:

Friday, September 02, 2011

Inside the WikiLeaks Cables

Yesterday I posted about the unredacted U.S. government diplomatic cables that had found their way onto the Internet. I suggested that humanitarian organizations doing international work should review the content to see if they are mentioned. There hadn't been much NGO-related material mentioned in the cables officially released by WikiLeaks, but I suspected there might be in the unreleased cables (Update - as of today, WikiLeaks has released all of the cables).

My hunch was correct. In skimming through the cables there is a large volume of communications about international NGOs and the UN. Some of it mundane (program reports), some of it controversial (country director opinions of host governments and leaders), some of it concerning security incidents (a few that I'd heard about through the community grapevine and others I hadn't). For example, here's an extract from a 2006 cable about the security situation in Darfur:

SUBJECT: DARFUR: NGO PRESENCE UNDER THREAT
--------------------------------------------------
NGOs Operating Under Increasingly Harsh Conditions
--------------------------------------------------
3. (C) A variety of occurrences over the past three months underscores the tenuous security environment faced by non-governmental organizations (NGOs) operating in Darfur.
The nature of the events and their severity are increasing; the potential for further deterioration during the holiday season put NGOs at increased risk. This is particularly true in the Gereida area of South Darfur, a town along the strategic Nyala ) Buram road that has seen ongoing conflict for more than two years between tribal militias, rebel groups, Sudan Armed Forces, Popular Defense Forces (PDF), and Janjaweed.

4. (C) Several recent events reflect this trend (Refs A and
B):
-- The rape, apparently designed to send a brutal warning to international humanitarian workers, of an Action Contre la Faim (ACF) expatriate worker;
-- The rising pace of vehicles car-jackings ) with 20 vehicles being stolen during the past month;
-- The selective theft of communications equipment and computers (Ref A), which impedes the ability of NGOs to conduct their normal activities, report on conditions, and communicate with outsiders;
-- The interrogation of CARE International workers, including regarding their private e-mail messages (Ref B);
-- The withdrawal of NGOs from Darfur and relocation of 400 humanitarian assistance workers so far in the month of December alone (Ref C); and
-- The decreased overall ability of the international community to deliver essential services and commodities for internally displaced persons (IDPS) in Darfur.

----------------------------------------------------
MFA: NGOs are Politically Manipulated, Need Courage
----------------------------------------------------
5. (C) During a December 21 meeting with State Minister of Foreign Affairs Ahmed Ali Karti, Charge Hume underscored the gravity of recent security events in Darfur, particularly in the Gereida area. The theft of a dozen vehicles, withdrawal of Oxfam and ACF, and sexual assault of a humanitarian worker jeopardized essential services and goods for 100,000 IDPs. Karti accused NGO workers of over-reacting, and not having the courage to remain in environments they knew to involve risk. Irritated, he stated they knew of Darfur\'s problems and were paid to do their work despite poor security. There is no perfume or roses in Darfur, he added, and NGO workers should refrain from reporting every wrong they encounter. The Sudanese Government cannot help them; they should return when there is stability. Finally, he accused NGO workers of \"trying to play politics,\" and being manipulated to send a \"political message.\"
Material such as this is interesting from a historical perspective, but my primary concern is about information that could increase risk to an organization and its staff. Unfortunately, this is also present. One organization I work with had the names of a few local staff members listed in a cable; discussing security conditions and their opinions of anti-government factions. Another cable mentioned how programming activities might be beneficial to military information operations. While this organization works hard to maintain its neutrality (including no military involvement) and uses an acceptance strategy, erroneous perception can be damning. The organization's headquarters and country management team are now reviewing selected cables, determining possible impacts and appropriate responses.

Considering some of the things I've read in the cables relating to the humanitarian community, I now feel even stronger about the need for international organizations to check if they are mentioned and in what context - especially since the full set of cables is now easily searchable at CableGateSearch. It's a worthwhile exercise to play "what-if" the media, host governments, or anti-government actors are also reading these cables. Certainly nothing may come of it, but it's always better to be prepared in case it does.

Labels: ,

Thursday, September 01, 2011

WikiLeaks Leaked Cables Update

In an earlier post, I suggested that security practitioners might want to pay attention to the content of leaked U.S. diplomatic cables in case information about their organization was present. Since perception can become reality, there's a chance the mention of an organization in some context might increase their risk exposure. Web sites such as CableDrum and CableGateSearch allow you to easily search for text in the cables that WikiLeaks has officially released.

Up until now, WikiLeaks has tightly controlled the flow of the compromised cables and hasn't released all of them. But as of yesterday, the entire, unredacted collection of cables (over 250,000) was unofficially leaked and has found its way onto the Internet (much to the dismay of WikiLeaks). 9/2/11 Update - There's a great description of how the encrypted cables were compromised here.

I'm not going to debate the legality or ethics of the release of this information. Only that the genie is out of the bottle, and anyone with a small amount of technical ability can now access the full set of cables.

A compressed version of the cables is currently available from various BitTorrent sources or can be directly downloaded (at the moment) from John Young's Cryptome disclosure site. The ~360 MB file is compressed in 7z format, you'll need a copy of the free compression utility 7-Zip to open the file. It uncompresses to a whopping ~1.7 GB text file. This is too large to open in Word or Excel for viewing (Excel's maximum number of lines is a bit over 65,000 and Word is constrained to around 100MB files but is also limited by system memory). So you'll either need to split the file into manageable chunks using a text file splitting program (such as HJSplit) or use a suitable text file reading program (Large Text File Viewer is a good, free Windows option). 9/2/11 Update - A colleague tipped me off to a much better and faster free program for viewing and searching large files. It's called Cream, a modern version of the old VIM programmer's editor, and is available here.

Searching through the entirety of such a large volume of unindexed data is a slow process (figure up to multiple hours for each text string you're interested in, depending on what program you're using). The search is going on in the background though, so you can be working on other things, checking the progress periodically and then clicking to search for the next instance of the text if it's found.

I suspect in the very near future someone will index all of the cables and put up an easy-to-use search Web site. But in the meantime, if you want to see if your organization is mentioned in any of the leaked cable traffic, the above information should help you get started. 9/2/11 Update - In response to the leak, WikiLeaks has now officially released all of the cables (with no redactions). They are available for browsing here or on CableGateSearch for full-text searching. I've written a follow-up to this post here.

Labels:

Monday, August 01, 2011

Possible sat phone alternative

DeLorme is a U.S. firm that got its start making paper maps, then got into digital maps and software, and now makes handheld GPS receivers in addition to maps. I've used their products over the years and they're pretty good with excellent customer support. The company recently announced a new product that may provide an affordable alternative to sat phones for field use. inReach is a small device that serves as an interface between an Android operating system cellular phone and the Iridium satellite network. It provides two-way, text-based communication through the mobile phone (an iPhone compatible version is supposed to be in the works). In addition the gadget also has GPS navigation and mapping functionality.

Pricing is supposed to be around $250 US for the device, with monthly plans starting at $9.95. This is considerably cheaper than an Iridium sat phone (around $1,000) and $30 to $40 monthly fees, plus airtime. Scheduled availability is sometime in the fall of 2011. There's more information about inReach, including photos, here.

Technology always looks good on paper before it's released and it's best to wait a bit and pay attention to the early reviews before purchasing a significant number of new electronic devices.

As a note, one downside to Iridium is coverage is blocked in certain parts of the world due to U.S. regulations (currently that includes Taliban controlled Afghanistan, Cuba, Iran, North Korea, Syria, and Sudan). I suspect Thuraya, which has more of a foothold within the humanitarian community (and so far has offered more rugged handsets) will also get into this market and other similar, competitive devices will emerge. Speaking of Thuraya, the British TV show Gadget did an un-scientific comparison of Iridium and Thuraya handsets last year. Check it out on YouTube.

Labels:

Tuesday, December 07, 2010

WikiLeaks

The USG cables that are being leaked by WikiLeaks provide a remarkable look behind the scenes at U.S. foreign policy and how the Department of State operates. There have been some interesting mentions of intelligence gathering targeted at U.N. and non-U.S. humanitarian organizations. While the main WikiLeaks site has been shut down, a large number of mirror sites have popped up.

It would be prudent to monitor the cables as they are released for any mentions of your organization and its activities. While personal names are being redacted, there is no guarantee organizational identities will be removed. The main security concern is depending on the context in which an organization is mentioned, groups may erroneously perceive some type of affiliation with USG, thus increasing risk - ranging from potential negative publicity to targeted attacks on facilities and/or staff. At the present there is a Web site that allows you to perform keyword searches of all publicly released cables. If the site is taken down, it's likely others will take its place and I'll update the link.

One other thing to mention. An encrypted, gigabyte-plus "insurance" file containing the unedited cables and other unreleased material has been available via BitTorrent since October. If anything happens to Julian Assange, supposedly the encryption key will be made public, providing anyone who downloaded the file with the raw information. Whether this is a bluff or not, remains to be seen. If the data is released, it's a forgone conclusion media outlets and both political and armed anti-government groups will be promptly mining it.

PS - USG has warned federal employees that since some cables are still classified, reading them is breaking the law. No word on if or how this stance may apply to organizations being funded by USAID.

Labels: