Monday, March 07, 2011
Today in Federal IT
Tom Temin finds out how his broadband service measures up courtesy of the FCC.
John Zyskowski gives us a wrap up of the recent RSA conference.
William Matthews: CIA blames 'technical difficulties' for website crash
NASA Now: Solar Storms.
Via Fedsphere created by Netspective.
Tuesday, June 30, 2009
Monday, February 02, 2009
Tuesday, August 19, 2008
FOIA, torture, and records management
But the judge, the Southern District of New York's Alvin Hellerstein, said at a hearing that he would give the government 10 days to produce a declaration to convince him why he should refrain from a contempt finding and from ordering production of a list of the tapes, information on witnesses and any documents or memoranda relevant to the Freedom of Information Act request of the American Civil Liberties Union.
So now the CIA must produce a list of evidence that it destroyed. How does an administrator produce such a list. Imagine the buck passing going on right now within the agency, for those who destroyed the evidence are keen to arrange that someone else be responsible for describing that which was destroyed, leaving that individual or individuals on the hook for any contempt citation.
All the worker bees within the agency and their contractors are going to play this by the book, let the big shots go to jail.
Thursday, July 24, 2008
Anti-CIA paranoia
When classes at the University of Washington resume this fall, some students at the school will be under the watchful eye of a Central Intelligence Agency spook. In fact, some of them will even be learning from him.
This fall, Dr. Tim Thomas, a CIA agent specializing in "open source" data mining, will begin a two-year stint as an officer-in-residence at the UW's Institute for National Security Education and Research (INSER), which is financed by the Office of the Director of National Intelligence. That office is an umbrella organization for groups such as the U.S. Marine Corps Intelligence Department, the Department of Homeland Security, and the CIA—which will provide the university with $2.5 million in grant money over the next five years.
There is nothing sinister in what is described here. We use this sort of technology in public relations. We use software that spiders the internet for anything concerning our clients and then analyze it for trends. The difference is that this sort of data-mining from publicly available sources is looking for different material for different purposes.
The threat to freedom does not come from data-mining, it comes from lack of privacy. If our financial, medical, and other personal data is subject to this sort of monitoring then indeed freedom is at risk.
Open source intelligence is reading my blog, subscribing to my twitter feed, and otherwise following publicly available information. Snooping is tapping my phone, reading my email, and a bunch of other things that infringe on my right to privacy. These are not subtle distinctions.
Friday, March 21, 2008
Some considerations in writing marketing copy for security agencies
Is there any way one can figure out some of the CIA's most highly guarded secrets from a corporate website?
Absolutely.
I’ve done it. (And you can count on it that America’s friends and enemies alike have, too.) ...
... Heckle and Jeckle also brag about a micro-electromechanical facility which becomes particularly interesting in conjunction with their job openings announcements. Reviewing the skill sets they're looking for, it quickly becomes apparent that they design and program their own computer chips, so they're clearly creating proprietary cutting-edge gadgets. It's notable how frequently they're searching for engineers with experience in one of the most miserable operating systems for mobile devices: Windows mobile. They're also regularly seeking programmers versed in another mobile device language: Symbian. Now this information taken in conjunction with their specialty and their prior claims of micro-electromechanical facilities suggests they're designing and creating a lot of mobile, hand held covert communications devices.
And here I'd venture a pure guess that these are probably designed to look like standard run-of-the-mill Treos and other smart phones, blending their “intelligent phones” into the mobile world. The largest consumer of such gizmos is, of course, the CIA's DS&T, adding to suspicions that Heckle and Jeckle is a major DS&T contractor. The primary use of such covert communications gear is for communications with nonofficial cover officers (NOCs) and agents. So the information on Heckle and Jeckle's site suggests that they are likely designing and creating the latest must-have accessories for NOCs and agents, a far cry from the clunky COVCOM gear of yesteryear. (And from the Agency's point of view, knowledge of this would be a serious security breech. Keep in mind the CIA does not even allow contractors to acknowledge their affiliation with the Agency, let alone divulge the programs they are working on, particularly such sensitivities ones.)
Not only have CIA programs been compromised, so have SOCOMs. Judging from the job postings for positions in Florida, Heckle and Jeckle are doing data mining and analytical work for SOCOM. Among other things that can be deduced, they search for relational patterns of terrorist activity and affiliations, looking at a wide array of seemingly innocuous relationships using open source and clandestinely gathered data, particularly focusing upon financial transactional data. I'm betting they have a very sophisticated quantitative model that they're constantly tweaking that underlies this process.
Again, Heckle and Jeckle job postings give us hints to other SOCOM programs. It appears that Heckle and Jeckle are involved in tracking SOCOM assets worldwide. Moving beyond Heckle and Jeckle's own website to other open sources, it's possible to learn some of the specs of related handhelds including whose low-earth orbiting satellites they use. Digging a little deeper, it's also possible to discover the code name of Heckle and Jeckle's RF geolocation program...
Your marketing needs to tell agencies enough so they know what you offer without giving away so much that you compromise national security. Clearly the security agencies need a federal intranet site that had pages for all of the contractors that would be accessible to all federal agencies with a need for such capabilities, but not accessible from the Internet. Your public website should market those products and services that are a matter of public record with some hint that you have additional products and services that are available on a custom basis without going into details.
This is also a perfect example of why security agencies need social media consultants, because clearly while they are reading blogs, they do not understand the implications of social media.
Sunday, October 14, 2007
A most unusual Call for Papers
In another popular and history-making move, DCI Hayden has issued an edict that all CIA employees are entitled to take three hours out of their 40 hour work week to do physical fitness training if they want to. Of course, this probably end up soon translating into six hours: three for actual PT and three for suiting up before and showering afterwards. Hayden will go into the history books, not only as the first CIA Director to investigate the CIA's watchdog, but, perhaps more significantly, as the fist DCI to to figure out how to get people off of the target and doing something totally unrelated to their jobs during wartime.
So DCI Hayden might become Mr. Popularity after all. Now if he would only do something about allowing those analysts from the Directorate of Intelligence (DI) to hold the posts of Chiefs of Station (COS), he might really win over the NCS.
And to help get CIA employees to take advantage of the new non-mission focused opportunity, a friend who is no stranger to dark, dangerous alleys overseas came up with a few "Jody calls" for the blue badgers to chant in cadence as they run around Headquarters while their green badger corporate buddies are inside, racking up those billable hours:
"DI, DI we're the best!
Now we can be COS.
We'll brief the Ambassador
And leave street work to DO whores!""Oh, HRM!
Oh-o, HRM!
Take your pencil follow me
Now we can sit in embassies.
We don't need to do The Farm
With EEO we'll wreak our harm."I invite The Spy Who Billed Me readers to do their part to help out by composing more Jody calls, perhaps some about our green badged friends. To kick things off, I'll give an autographed copy of OUTSOURCED to the author of the funniest one.
What the Hell is Going on with the CIA IG?
Monday, June 18, 2007
How important is supply-chain management?
Move aside, HUMNINT and IMINT, we've got contracts to execute! We'll find bin Laden: that's clearly outlined in the scope of service.
Tuesday, May 08, 2007
The coming debate over federal contracting
The timing of the news cycle was brilliant. The media was in the final stages of gearing up for the year's biggest spy non-event: the publication of Tenet's CYA memoir, a tome destined to soon become doorstops throughout the nation. At that juncture the office of the Director of National Intelligence chose to announce that the year-long study on the use of industrial contractors by the intelligence community was not going to be released. The number and use of industrial contractors was suddenly a matter of national security.
The debate over the use of contractors can be delayed, but not blocked. My advice to contractors is to make change your friend rather than your enemy.