Rabu, 06 Maret 2019

E-Mails From Within The Nsa Bureaucracy



Earlier this month, the NSA declassified a huge gear upwardly of internal e-mails, next FOIA-requests most the outcome of whether Edward Snowden had raised concerns most the NSA's surveillance programs through proper channels within the agency.

> Download the declassified e-mails (very large pdf)

Here, nosotros volition stimulate got a expect at the administrative details these internal NSA e-mails provide. Next fourth dimension nosotros volition run into what their content says most the concerns that Snowden claimed to stimulate got raised.



Internal e-mail from NSA manager Michael Rogers. In the signature block nosotros run into his
NSANet together with SIPRNet e-mail addresses together with his non-secure telephone give away (all redacted)
(Click to enlarge - See also: NSA manager Alexander's phones)



E-mail addresses

Except from the classification markings, the NSA's internal e-mails aren't really dissimilar from those exchanged past times most other people around the world. But they produce demo for event some details most the internal communications networks of the agency.

From the signature blocks underneath the e-mails nosotros larn that, depending on their business office together with tasks, NSA employees stimulate got e-mail addresses for i or to a greater extent than of the next 4 estimator networks:

- NSANet for messages classified upwardly to Top Secret/SCI (Five Eyes signals intelligence). On this network the address format for e-mail is jjdoe@nsa

- JWICS for messages classified upwardly to Top Secret/SCI (US intelligence). The address format is jjdoe@nsa.ic.gov

- SIPRNET for messages classified upwardly to Secret (mainly USA military). The address format is jjdoe@nsa.smil.mil

- UNCL for unclassified messages, probable through NIPRNet. The address format is jjdoe@nsa.gov


For e-mail, all NSA employees stimulate got display names inwards a standardized format: outset comes their identify unit of measurement name, given advert together with middle initial, sometimes followed past times "Jr" or a high military machine rank. Then follows "NSA" together with the proper organizational designator, so "USA" for their nationality together with lastly "CIV" for civilian employees, "CTR" for contractors, "USN" for Navy, "USA" for Army or "USAF" for Air Force members.

Thus, the display advert of the electrical current NSA manager is "Rogers Michael southward ADM NSA-D USA USN", spell that of the previous manager was "Alexander Keith B GEN NSA-D USA USA". In 2012, Snowden had the display advert "Snowden Edward J NSA-FHX4 USA CTR":



E-mail from Snowden every bit systems administrator inwards Hawaii, August 2012
The redacted component subdivision of the classification marking
seems to cover a dissemination marking *
(Click to enlarge)


The organizational designator FHX4 is interesting. FH stands for Field station Hawaii, but X4, beingness unit of measurement 4 of sectionalization X, is nonetheless a mystery. The champaign station divisions stimulate got the same designators every bit those at NSA headquarters, where there's also a sectionalization X, but so far no document gave an indication what it does.

The signature block shows that Snowden worked every bit a systems administrator for Dell's Advanced Solutions Group together with that he was deployed at the Technology Department of NSA's Cryptologic Center inwards Hawaii, to a greater extent than specifically at the Office of Information Sharing. The latter has the organizational designator (F)HT322 together with is hence dissimilar from that inwards Snowden's display name.

> See the listing of NSA's Organizational Designators


In the declassified messages nosotros exclusively run into display names, non the actual e-mail addresses behind them. Therefore, exclusively the classification markings on the messages supply an indication on which network they were exchanged.

From an e-mail that was declassified before nosotros know that inwards Apr 2013 Snowden used the address "ejsnowd@nsa.ic.gov", which is the format for the JWICS network, but was evidently used on NSANet.*

From i of the declassified e-mails most NSA's internal investigation it seems that Snowden had but ii postal service accounts: "we stimulate got his TS [Top Secret] NSANet e-mail together with his UNCLASSIFIED NSA.gov email", but this is followed past times some redacted lines.*

Finally, the signature blocks of some NSA employees also supply a link to their dropbox for sending them files that may live also large for e-mail. Such dropboxes stimulate got addresses similar "http://urn.nsa.ic.gov/dropbox/[...]".



Example of an NSA message, amongst inwards the signature block e-mail addresses for JWICS together with an
unclassified network, together with telephone numbers for the NSTS together with the non-secure telephone networks
OPS 2B is the wider together with lower i of the ii dark NSA headquarters buildings
(Click to enlarge)


Telephone numbers

Besides e-mail addresses, many messages also stimulate got telephone numbers inwards the signature blocks. They demo numbers for i or to a greater extent than of the telephone systems used at NSA:

- NSTS, which stands for National Secure Telephone System together with is NSA's internal telephone network for secure calls. Numbers for this network stimulate got the format 969-8765 together with are ofttimes marked amongst "(s)" for "secure"

- STE, which stands for Secure Terminal Equipment, beingness a telephone device capable of encrypting telephone calls on its own. Telephone numbers tin ship away live written inwards the format (301) 234-5678 or every bit STE 9876.

- BLACK, CMCL or Commercial, which are numbers for non-secure telephones that may also access earth telephone network. They stimulate got the regular format (301) 234-5678 together with are ofttimes marked amongst "(b)" for "black" (as opposed to "red") or amongst "(u)" for unclassified.



The NSA/CSS Threat Operations Center (NTOC) at NSA headquarters, amongst from left to right:
an STE secure phone, a belike non-secure telephone together with a telephone for the NSTS
(Photo: NSA, 2012 - Click to enlarge)


TIKICUBE

Finally, releasing such a huge gear upwardly of documents inwards which many parts had to live redacted e'er bears the opportunity that something is overlooked. That also happened this time, every bit inwards i e-mail from an investigator from NSA's Counterintelligence Investigations unit of measurement Q311 they forgot to redact the codeword TIKICUBE:




TIKICUBE appears to live a unit of measurement of the Investigations Division Q3. Whether this mightiness live a particular unit of measurement investigating the Snowden leak isn't clear though.

The abbreviations behind the investigators advert are: CFE for Certified Fraud Examiner together with CISSP for Certified Information Systems Security Professional.

We also run into that this investigation sectionalization is non located at the NSA headquarters complex at Fort Meade, but at FANX. This stands for Friendship Annex, a complex of NSA business office buildings inwards Linthicum, nigh Baltimore, some 12 km. or 7.5 miles north-east of Fort Meade.

The famous blue-black drinking glass headquarters buildings are OPS 2A together with OPS 2B, spell the SIGINT sectionalization is evidently inwards the apartment 3-story edifice from the belatedly 1950s, designated OPS 1.


Tidak ada komentar:

Posting Komentar