Bonum Certa Men Certa

Cablegate Reveals Government Requesting Access to Microsoft Data, Kill Switches

White House



Summary: Despite the fact that only a fraction of Cablegate has yet been released, new evidence already surfaces about the US government's concern (and role) in the seemingly-private computer industry

"Cablegate" is one of the reasons we have not posted so much this month. Personally I have posted over a thousand links/dents about it in the past week alone. The threat to Wikileaks is a threat to all of us who leak documents that serve as evidence of misconduct. Techrights did this many times before, so it's important to defend the practice.



One of the most major (and first) revelations coming out of Cablegate is to do with fear of Iran's nuclear programme. Given what can be found in Cablegate (not to mention brutal retaliation against Wikileaks), it is clear that the US government goes very far to get its way. Earlier this year we covered Stuxnet on many occasions as people raised suspicions that Stuxnet had something to do with governments and secret services. Experts who suggested this were not obscure people; some were well regarded in their field. As a roundup of Stuxnet posts consider:

  1. Ralph Langner Says Windows Malware Possibly Designed to Derail Iran's Nuclear Programme
  2. Windows Viruses Can be Politically Motivated Sometimes
  3. Who Needs Windows Back Doors When It's So Insecure?
  4. Windows Insecurity Becomes a Political Issue
  5. Windows, Stuxnet, and Public Stoning
  6. Stuxnet Grows Beyond Siemens-Windows Infections
  7. Has BP Already Abandoned Windows?
  8. Reports: Apple to Charge for (Security) Updates
  9. Windows Viruses Can be Politically Motivated Sometimes
  10. New Flaw in Windows Facilitates More DDOS Attacks
  11. Siemens is Bad for Industry, Partly Due to Microsoft
  12. Microsoft Security Issues in The British Press, Vista and Vista 7 No Panacea
  13. Microsoft's Negligence in Patching (Worst Amongst All Companies) to Blame for Stuxnet
  14. Microsoft Software: a Darwin Test for Incompetence
  15. Bad September for Microsoft Security, Symantec Buyout Rumours
  16. Microsoft Claims Credit for Failing in Security
  17. Many Windows Servers Being Abandoned; Minnesota Goes the Opposite Direction by Giving Microsoft Its Data
  18. Windows Users Still Under Attack From Stuxnet, Halo, and Zeus
  19. Security Propaganda From Microsoft: Villains Become Heroes
  20. Security Problems in iOS and Windows
  21. Eye on Security: BBC Propaganda, Rootkits, and Stuxnet in Iran's Nuclear Facilities
  22. Eye on Security: ClamAV Says Windows is a Virus, Microsoft Compromises Mac OS X, and Stuxnet Runs Wild
  23. Windows Kernel Vulnerability for Thanksgiving, Insecurity Used for Surveillance Again


"Stuxnet Still Out of Control At Iran Nuclear Sites" summarises Slashdot which says:

"Iran's nuclear program is still in chaos despite its leaders' adamant claim that they have contained the computer worm that attacked their facilities, cybersecurity experts in the US and Europe say. Last week President Mahmoud Ahmadinejad, after months of denials, admitted that the worm had penetrated Iran's nuclear sites, but he said it was detected and controlled. The second part of that claim, experts say, doesn't ring true. Owners of several security sites have discovered huge bumps in traffic from Iran, as the country tries to deal with Stuxnet. 'Our traffic from Iran has really spiked,' said a corporate officer who asked that neither he nor his company be named. 'Iran now represents 14.9 percent of total traffic, surpassing the United States with a total of 12.1 percent.'"


The original article comes from The Atlantic and says that "Stuxnet Disrupted Iranian Centrifuges":

Malicious software apparently designed to disrupt the Iranian nuclear program was able to do just that, Iran's president acknowledged today. Security researchers found that the Stuxnet worm could insinuate itself into industrial control systems -- and if it found a particular brand and arrangement of motor controllers would begin a long-term sabotage program. Now, in the wake of the apparent assassination of an Iranian nuclear scientist, Mahmoud Ahmadinejad acknowledged that Stuxnet did hit his country's centrifuge facility, though he downplayed its impact.


Techrights does not deal directly with politics, so staying more focused on technical aspects of this, what are the chances of targeted attacks? This needn't imply that Stuxnet was created by governments as some people allege. Either way, in the wake of Cablegate, it is unreasonable to rule out anything for which there is evidence.

In a new cable which goes back to 2004 it emerges that Microsoft produced code which would put a "black screen" on any computer running Windows upon some trigger invocation (e.g. war, not just counterfeiting). Some would call it a "kill switch". What's interesting here is that it took years for people to actually discover what black screens of death truly are. That's how secretive it was. This enabled control from the outside. To quote a relevant part of this newly-released cable:

WHAT'S DRIVING CHINA -------------------- ۦ8. (C) According to another well-respected tech sector analyst here, a number of historical, cultural, and technological factors have coalesced to put China in a technologically-aggressive state-of-mind. One contributing factor was Microsoft's flubbed 2004 strategy to deter intellectual property theft by darkening computer monitors running unlicensed Windows operating software. This consultant believes that example of U.S. technology effectively wielding power over China's personal computers helped spur China's aggressive campaign for source codes and its own technology. This, combined with growing Chinese pride, economic clout and influence, and the "weakened" position of the U.S. and its allies after the global economic downturn, are emboldening the Chinese to take ever more aggressive positions in advancing its innovative industries at the expense of foreign ones.

ۦ9. (C) A local Microsoft executive applauds the Secretary's speech and the Administration's commitment "to organize sustained, targeted, persistent engagement on the full range of Internet-related issues" with China. This executive said the Secretary's remarks were "right on point," particularly for companies who "desperately need the help of the USG" in the face of "harassment, threats and actual shutdowns of service, threats of licenses being revoked, resistance to provide legal authority, mandates to place servers in China, etc." Our local APCO contact described the Google issue as a "stirring of the beehive," but says the kind of harassment Microsoft describes is a fact of worsening life here which


But wait. It gets worse. Not only remote control of people's machines (in another country) is a feature to the US government and other governments. They also gather people's data as this other new cable reveals:

ۦ12. (U) Assisting Brazil in creating legislation to counter cybercrimes, including online child pornography and tracking of sex offenders, represents another potential area of cooperation on law enforcement matters. Brazil lacks cybercrime laws and the Congress has opened a Parliamentary Committee of Inquiry (CPI) to look at the issue and come up with draft legislation. As part of the CPI's work, the CPI was able to obtain over 3,000 Google records of identified child pornography that had been distributed on the Internet from Brazil. The chairman of the CPI has voiced his concern about, in his view, inadequate cooperation from Google and its subsidiary Orkut, a relationship site. Google, Orkut, Microsoft, and all other Internet service providers are required to report the discovery of child pornography on the Internet and DHS/ICE has established a mechanism to have access to this information which has been reported. DHS/ICE has already initiated the practice of sharing this information with Brazilian Federal Police. Related to the CPI, its Chairman has made inquiries to the Mission on the case of DHS/ICE Deportation officer accused of child exploitation at a hotel in Brazil. The U.S. is seeking the toughest penalty possible, whether in Brazil or the U.S., and is fully cooperating with Brazilian authorities.


Only about 0.5% of the cables have been released so far, so there is a lot more coming, also about companies like Microsoft. Microsoft's eGovernment lobbyist Anke Domscheit-Berg has praised Wikileaks, but that was before Cablegate, i.e. when mostly information about crimes and wars was released.

The cables above ought to teach why Free software is essential to people's independence and countries' autonomy. By controlling information and software one controls almost everything and the latest developments around ACTA, TSA, and COICA law show that the government wants more control over people. It will change the law if necessary, in order to ensure continued domination over an increasingly upset population.

Access to personal data and 'jailing' of people inside devices is a threat to the hacker culture (which Wikileaks thrives in) and even just to control over one's life. In separate news, "Apple quietly drops iOS jailbreak detection API" and Google's Chrome OS seems like somewhat of a jail rather than a GNU/Linux distribution. About Apple we learn that:

Apple has disabled, without explanation, a jailbreak detection API in iOS less than six months after introducing it. Device management vendors say the reasons for the decision are a mystery, but insist they can use alternatives to discover if an iPhone, iPod touch or iPad has been modified so they can load and modify applications outside of Apple's iTunes-based App Store.


Nobody should need to 'jailbreak' a device in the first place.

Software freedom is not just about power (to the user). It's about control of one's own destiny and if society is indeed closing down and repressing the population, then now more than ever people and their governments should migrate away from proprietary software.

Recent Techrights' Posts

A Week After a Worldwide Windows Outage Microsoft is 'Bricking' Windows All On Its Own, Cannot Blame Others Anymore
A look back at a week of lousy press coverage, Microsoft deceit, and lessons to be learned
 
Links 26/07/2024: Hamburgerization of Sushi and GNU/Linux Primer
Links for the day
Links 26/07/2024: Tesco Cutbacks and Fake Patent Courts
Links for the day
Links 26/07/2024: Grimy Residue of the 'AI' Bubble and Tensions Around Alaska
Links for the day
Gemini Links 26/07/2024: More Computers and Tilde Hosting
Links for the day
Links 26/07/2024: "AI" Hype Debunked and Elon Musk's "X" Already Spreads Political Disinformation
Links for the day
"Why you boss is insatiably horny for firing you and replacing you with software."
Ask McDonalds how this "AI" nonsense with IBM worked out for them
No Olympics
We really need to focus on real news
Nobody Holds the GNOME Foundation Accountable (Not Even IRS), It's Governed by Lawyers, Not Geeks, and Headed by a Shaman Crank
GNOME is a deeply oppressive institutions that eats its own
[Meme] The 'Modern' Web and 'Linux' Foundation Reinforcing Monopolies and Cementing centralisation
They don't care about the users and issuing a few bytes with random characters costs them next to nothing. It gives them control over billions of human beings.
'Boiling the Frog' or How Online Certificate Status Protocol (OCSP) is Being Abandoned at Short Notice by Let's Encrypt
This isn't a lack of foresight but planned obsolescence
When the LLM Bubble Implodes Completely Microsoft Will be 'Finished'
Excuses like, "it's not ready yet" or "we'll fix it" won't pass muster
"An escalator can never break: it can only become stairs"
The lesson of this story is, if you do evil things, bad things will come your way. So don't do evil things.
When Wikileaks Was Still Primarily a Wiki
less than 14 years ago the international media based its war journalism on what Wikileaks had published
The Free Software Foundation Speaks Out Against Microsoft
the problem is bigger than Microsoft and in the long run - seeing Microsoft's demise - we'll need to emphasise Software Freedom
IRC Proceedings: Thursday, July 25, 2024
IRC logs for Thursday, July 25, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Links 26/07/2024: E-mail on OpenBSD and Emacs Fun
Links for the day
Links 25/07/2024: Talks of Increased Pension Age and Biden Explains Dropping Out
Links for the day
Links 25/07/2024: Paul Watson, Kernel Bug, and Taskwarrior
Links for the day
[Meme] Microsoft's "Dinobabies" Not Amused
a slur that comes from Microsoft's friends at IBM
Flashback: Microsoft Enslaves Black People (Modern Slavery) for Profit, or Even for Losses (Still Sinking in Debt Due to LLMs' Failure)
"Paid Kenyan Workers Less Than $2 Per Hour"
From Lion to Lamb: Microsoft Fell From 100% to 13% in Somalia (Lowest Since 2017)
If even one media outlet told you in 2010 that Microsoft would fall from 100% (of Web requests) to about 1 in 8 Web requests, you'd probably struggle to believe it
Microsoft Windows Became Rare in Antarctica
Antarctica's Web stats still near 0% for Windows
Links 25/07/2024: YouTube's Financial Problem (Even After Mass Layoffs), Journalists Bemoan Bogus YouTube Takedown Demands
Links for the day
Gemini Now 70 Capsules Short of 4,000 and Let's Encrypt Sinks Below 100 (Capsules) as Self-Signed Leaps to 91%
The "gopher with encryption" protocol is getting more widely used and more independent from GAFAM
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 24, 2024
IRC logs for Wednesday, July 24, 2024
Techrights Statement on YouTube
YouTube is a dying platform
[Video] Julian Assange on the Right to Know
Publishing facts is spun as "espionage" by the US government and "treason" by the Russian government, to give two notable examples
Links 25/07/2024: Tesla's 45% Profit Drop, Humble Games Employees All Laid Off
Links for the day
Gemini Links 25/07/2024: Losing Grip and collapseOS
Links for the day