Thursday, April 28, 2016

The Oral History of Export Control

Export control regulations are hugely important, and because of that, I and many of us in the software security industry have been sitting in on the ISTAC committee meetings for the last year at the Commerce Department. (Disclosure: I have applied to be on the committee and the White House is reviewing my application.)

These are meetings held by subject matter experts to advise the Commerce Department on how to improve or implement or remove regulations that control anything from Satellite systems to encryption.

I want to take a few minutes to tell you some things that would shock you if you come from an engineering or software development or even a legal background with regards to the process.

No Change Control Management or History

When you write export control regulations you have only an oral history. Nobody knows in the meetings why a particular regulation exists or is worded in any particular way or what the changes are that have gotten it to that point or what other pieces of law it effects or who worked on it or anything that would normally be on GitHub for an equivalent project in the real world.

Some of the things export control regulations are supposed to do are secret (and come from the DoD/IC), but a lot are not, and having a documented trail of what has happened would allow for a much better regulation writing.

No Testing



In the software industry we like to write something called "Unit Tests" for any major codebase. Export control is a kind of giant complicated codebase that lawyers execute to determine criminal liability over technical issues. But in every meeting people are always left guessing at the "intended capture" and "unintended capture" for any particular regulation. This is easy to fix with a simple wiki that links to a set of things you can run through as a checklist. I have done one for unintended captures for the Wassenaar "Intrusion Software" regulations. But it is telling that for most new regulations I've seen there is no specified INTENDED EFFECT. If you had software written like that you would run for the hills.

Basically, right now, we test our export control code in production.

The Future


If I get approved for the ISTAC I will endeavor to examine if it's possible to fix some of these issues, which I see as areas of basic government efficiency and transparency. It's really amazing how accessible the process is if you bother to show up for the meetings and get involved.    

Monday, April 25, 2016

Bandwidth and the Cyber Weapon of Availability

A key difference between the Immunity mindset on "Cyber Weapons" and the public one is that we see the ability to offer information that cannot be removed from the public Internet as an important, and perhaps the most important type of cyber weapon. If you don't think an AC-130 hurling USB keys full of videos and software into a city isn't a cyber weapon, then you won't agree with our paradigm and you'll have to live with being wrong. :)

Emin Gun Sirer has written two blogposts that should be must-reads by the policy sect or anyone in the security business and this is one of them:
http://hackingdistributed.com/2015/12/31/when-surveillance-is-accessible-by-all/

TL;DR summary: "All the databases are going to be available to everyone." Cyber intelligence has long depended on the gap between what people knew was publicly available and what they could access. You know how powerful even a PHONE BOOK DATABASE is when it's not publicly known to be accessible? Try running an Alias for an intel officer who didn't actually have an apartment in Istanbul when she said she did, and I can check in 20 seconds with my stolen DB. This is true for the OPM database, all the airline databases and of course the hospital databases. The same techniques that Twitter uses to figure out what brand of soap to sell you can detect a fake persona without breaking a digital sweat.

Following from these self-evident facts, eventually every service that uses aliases is going to transition to just having to timeslice from normal people with normal jobs, which is going to require they haven't alienated the entire technical community they rely on for access and influence. (In case you wanted a link to the Comey-misteps-of-the-day).

The obvious trendline is that the amount of data that makes a company run is a constant. Mail spools just don't get big that fast, and the important information in them gets bigger even slower. Remember when downloading a movie was a big deal? Now you download 4 in between waking up and heading to the airport onto your Kindle.

In other words: The increase in available bandwidth has completely shifted some equation and made "Offer" cyber weapons more important than they ever otherwise could have been. You only need a tiny dwell time on the main mail server of a company to end that company forever, and that dwell time is now smaller than the target's "Indicators of Compromise" analysis speed. Or as Microsoft's researcher Sasha would say: "You win automatically when your exfil time is less than log aggregation and analysis periods."

On a completely unrelated note, I'm headed to DC today to attend a conference at Georgetown on Cyber Policy. I think part of what annoys everyone in the cyber policy world about the State Dept. fucking up Wassenaar so much is that it has absorbed all the bandwidth available for analysis for two whole years on an important subject. The only silver lining is that by aligning the opposition to their bone-headedness on the subject we may have congealed a multi-cell predator out of the primordial soup. :)

Wednesday, April 13, 2016

Naming/Shaming Iran Was a Huge Mistake

By Dave Aitel, CEO of Immunity Inc.


The Department of Justice made a big mistake. By naming the seven Iranian hackers it claims were responsible for penetrating a New York dam in 2013 and disrupting US banking websites, it has exposed major inconsistencies in US policy which could have far reaching impacts on US cyber policy and future operations.

First of all, it’s worth pointing out that the US government admonished a foreign government for doing something which it itself is famous for - probing critical infrastructure systems. After all, the Stuxnet project, which targeted Iran’s nuclear facilities in 2010 (and is widely believed to have been a joint US/Israeli operation), is likely what propelled Iran into offensive cyber operations in the first place. 

Some will see the DOJ’s announcement as a consistent follow-through in US government policy. After all, we named both China and North Korea in previous attacks and we levied sanctions on private Chinese companies as well. Why shouldn’t Iran get the same treatment?

Here are the problems, as I and others in the security community see them:

What are the ‘red lines’ the US government is trying to draw here?

The US was well within its rights last year when it finally confronted China over its aggressive economic cyber-espionage against American companies and industries. Intellectual property theft is not a legitimate activity of nation-states. The threat of targeted sanctions on Chinese citizens and private Chinese companies for data theft was justified and long overdue and changed Chinese policy at the top level.

But the situation with Iran is different. Just as the foreign intelligence service behind the Office of Personnel Management (OPM) breach was operating within customary espionage norms, so too are the Iranians operating within these boundaries when probing US systems without producing a “kinetic” effect (such as triggering a physical malfunction, damage or outage). And while there are no set norms when it comes to distributed denial-of-service (DDoS) attacks, as the Iranians used against the US financial sector in 2012 and 2013, this mode of attack cannot legitimately be claimed as posing a serious threat to our critical infrastructure. DDoS is inconvenient, but it’s hardly damaging. The Iranians use of DDoS likely had more to do with sending a message to Washington about its use of economic sanctions than anything else. 

Why was this a DOJ decision? Why wasn’t the State Department involved? 

Normally, when we want to change a nation-state’s behavior, we use customary nation-state to nation-state channels. We don’t sue individuals who are working for that country. 

Foreign diplomacy is the State department’s job, not the job of the FBI or a local police department. Something is very wrong with how the US government is coordinating on this issue. The US could, at any time, and probably did, reach out to the Iranian government and ask them to stop the DDoS attacks against the banks allegedly conducted by these seven individuals. But if they were conducting Iranian state operations, then holding them personally responsible is a huge change in policy. If they were not, then why mention the Iranian Revolutionary Guard Corps (IRGC) in the indictment at all?   

From an operational security perspective, this announcement was extremely harmful, now and in the future. 

By releasing this indictment, the government accomplished two things, both of which are bad from an intelligence standpoint. 

First, it showed the world what the US government knows about the Iranian effort. 

That means we’ve potentially exposed the sources and methods used by the government to make this determination. It’s generally not a good idea to blow operational security unless you’re truly getting something better in return. In fact, it’s standard practice for the US government to undergo an “equities process” to evaluate these types of risks before proceeding with a public disclosure. But what did the US government actually get out of this announcement? Does anyone seriously think those Iranians will face jail time here in the States? We still have Americans in Iranian cells - do we want them kept there as trading cards for later? 

Secondly, this announcement revealed what the US does not know about other, similar efforts like last year’s DDoS attack on Github. After all, if the US is willing to indict the Iranians for DDoSing the banking system, why didn’t they indict the Chinese team behind the Github attack? Is it because we don’t know who was behind that attack? Or are the rules different for the Chinese and the Iranians?

By saying we’re going to indict foreign citizens when we know who is behind a specific cyber attack, we are demonstrating to the world the precise boundaries of our knowledge. This is not a wise plan.

This announcement puts US cyber operatives in the cross-hairs.

The DOJ just put a target on the backs of all US intelligence community employees and contractors who are involved in offensive cyber operations around the world.

These indictments create a sort of international precedent that other countries could one day use to justify actions against private citizens in the US and its allies. By blurring the established cyber norms, the US Department of Justice is creating a complex and messy situation for itself and others in future cyber operations. Could Russia use a similar action against British or German cyber teams? Do we want Hezbollah interdicting American computer scientists when they travel in the region?

What the Department of Justice has done is dangerous and contravenes all standing nation-state policy on the issue, all for a few headlines and feel-good photo-ops. I, along with many others in the information security field, hope they can find a way to reconsider.

Monday, April 11, 2016

"Learning to Win"

Nate Fick's 2016 INFILTRATE Keynote on "Learning to Win" in Cyber is here: https://vimeo.com/161996596

It's funny, but it's also full of a lot of outside the box thinking that you may enjoy, especially if you're in the policy world.




Thursday, March 24, 2016

A checklist of scenarios for Wassenaar text judging

We all know that personally I think (along with most of the security community) that we would be much better off removing any language related to "intrusion software" from Wassenaar's export control regulations.

But people are putting together lots of texts to examine. However, in the software world, we do something called "Test Driven Development" - writing the tests first so you can tell if your software works by constantly running testing over it as you develop it. The list in this blog is solely concerned with "unintended capture". Basically all of these scenarios are banned by the current proposed US implementation, in case you wondered why the whole industry is up in arms about it and are new to this blog. Please help me add to it by sending me emails and tweets!


  • You are Kaspersky and you have captured a sample of Stuxnet. You send this to some researchers in Hungary to help you analyze it
  • You are a penetration tester for E&Y, and you want to buy and use CANVAS or Metasploit Pro while traveling to your customer sites, both domestically and abroad.
  • You are a researcher working for Booze Allen Hamilton, and you find an issue with a commonly used Korean word processor. You send an exploit for this to your Korean friend so he can talk to the vendor for you after making sure it really works.
  • You are Tavis Ormandy, and you travel to Singapore to give a talk on Antivirus Security, including demonstrating some 0day they won't fix
  • You work for Symantec and you turn your head to the left and talk to the H1-B employee who sits next to you about a vulnerability
  • You are a company that does threat intelligence and you send samples of various trojans and their C2's to your customers so they can help protect themselves
  • You run Blackhat and you want to have a conference and do trainings with an international crowd of people without running all your slides or attendees through the NSA for approval.
  • ...


Wednesday, March 23, 2016

A networked war requires a networked peace?

Book Link: https://ccdcoe.org/multimedia/international-cyber-norms-legal-policy-industry-perspectives.html

I have some serious questions about how much "Cyber Excellence" you can get when only one of the authors of your book has any technical background in their Bios. But disregarding the urge to ask why quoting, say, POLITICO or the ECONOMIST is how policy-suggestions are made, I wanted to analyse in depth what the book was actually saying.

To be fair, it says a lot of things, but it also says their opposites, leaving a reader wondering which of those paths is going forwards and which is backwards. The book itself primarily seems to reflect internal struggles with whether policymaking around cyber norms is even possible.

This book would have been ten times better if it had focused on two things:

1. Every person in the book who claimed that yes, geography and cyber were totally connected and therefor all sorts of laws were simple to apply to cyber needs to go and take five random IP addresses and Geolocate them. Then someone should point out to them how onion routing, VPNs, co-hosting, and content delivery networks work. You can tell people in this book who don't know what they are talking about because they go on and on about "scholars" opinions when what they should be doing is learning how to use traceroute.

2. Stuxnet is the acceptable norm. And this book should have focused very clearly on WHY that is so from a technical perspective, because the answer is very interesting, and not at all in coherence with the policies espoused in this book (or by the cyber norms crowd in general) :) .



---------------------------------------------------------------------
My notes are in italics below, along with what I felt were telling excerpts of each chapter.

Chapter 2
The Nature of  International Law Cyber Norms
Michael N. Schmitt and Liis Vihul

One of the better chapters, but also one of the most ambivalent. Perhaps because of that.

"With respect to the jus ad bellum, the primary terminological obstacle deals with the use of the word ‘attack’. Article 51 of the UN Charter allows states to use force in self-defence in situations amounting to an ‘armed attack’. Not all hostile cyber operations directed at a state rise to this level. As a general matter (the precise threshold is by no means settled), such operations must result in the destruction of property or injury to persons before qualifying as an armed attack that opens the door to a forceful response, whether kinetic or cyber in nature."
- Is destruction of an entire industrial sector over a decade "destruction of property". How much data destruction is "destruction of property"?

Finally, a similar IHL-based debate is underway as to whether the term ‘civilian object’ extends to data.61 If so interpreted, a cyber operation designed to destroy civilian data would be prohibited by Article 52 of Additional Protocol I, which bans direct attacks against civilian objects. If not, civilian data is a lawful object of attack, except in those circumstances where its loss might cause physical damage to objects or injury to persons. The critical and unresolved fault line in the debate lies between interpretations that limit the term to entities that are tangible, which is arguably the plain meaning of the term ‘object’, and those based on the argument that in contemporary understanding the ordinary meaning of ‘object’ includes data.62

Where does dropping of mail spools fall, I wonder?

 Therefore, it can be difficult to point to a particular state’s cyber practice to support an argument that a norm has emerged. States, including victim states, may be reticent in revealing their knowledge of a cyber operation, because doing so may disclose capabilities that they deem essential to their security. Undisclosed acts cannot, as a practical matter, amount to state practice contributing to the emergence of customary international law.

. From an international security perspective, normative clarity is not always helpful. Two recent examples are illustrative. The relative silence of states in reaction to the 2010 Stuxnet operation against Iranian nuclear enrichment centrifuges does not necessarily indicate that states believe that the operation was lawful (assuming for the sake of analysis that it was launched by other states, since only states can violate the prohibition on the use of force set forth in Article 2(4) of the UN Charter). On the contrary, they may have concluded that the attack violated the prohibition on the use of force because it was not in response to an Iranian armed attack pursuant to the treaty and customary law of self-defence. Yet those states may logically have decided that the operation was nevertheless a sensible means of avoiding a pre-emptive and destabilising kinetic attack against the facilities by Israel.



Considered in concert, these factors render improbable the rapid crystallisation of new customary norms to govern cyberspace. Therefore, the normative impact of customary law on cyber conflict is most likely to take place in the guise of interpretation of existing customary norms, and if so, interpretive dilemmas similar to those affecting treaty interpretation will surface.


Chapter 3
Cyber Law Development and the United States Law of War Manual
Sean Watts
Clearly trying to push an agenda but needs to go back and learn traceroute.

In early treatments of the subject, a viewpoint emerged that might be termed Exceptionalist. According to this view, cyberspace represented an unprecedented novelty entirely unlike other domains previously regulated by international law. Exceptionalists imagined an Internet owned and regulated by no one, over which states could not and should not exert sovereignty. Some Exceptionalist views ran so strong that they issued manifesto-like declarations of independence that defied states to intervene.1 They advanced a view that Professor Kristen Eichensehr aptly termed ‘cyber as sovereign’.

In response to Exceptionalists, a view developed that might be termed Sovereigntist. According to the Sovereigntist view, cyberspace, while novel with respect to the conditions that informed the creation of most existing treaties and customs, remains fully subject to international law. The Sovereigntist view continues to recognise sovereign states as both the stewards and subjects of international law in cyberspace.3 Scholars sometimes refer in this respect to a ‘cybered Westphalian age’.4 

These debates concerning the role of international law in managing cyberspace spawned a cottage industry of legal commentary and scholarship seeking to influence and shape future cyber law. Overwhelmingly resolved in favour of Sovereigntists, these debates were in large part conducted by and between non-state actors such as academics, non-governmental organisations, and think tanks.6 They produced commentary and claims that in both quantitative and qualitative terms have dwarfed the input of sovereign states. 

This is the kind of horrible grandiosity this chapter is full of. 

At minimum, the observation confirms the US viewpoint that a number of important regulatory ambiguities and even voids exist under the current legal framework.
...
 Nothing about the structure, composition or operation of cyberspace convinces the Manual’s authors that cyberspace is a legal void or unregulated by existing law.

This whole chapter was written to draw this rather tenuous conclusion, the reader senses immediately.

What the Manual clarifies with respect to cyber operations and what it leaves unresolved should be understood simply as a snapshot of the state of international law cyber norms as well as an indication of a single state’s limited interest in immediately cultivating more developed and meaningful international norms in that area.

Chapter 4
The International Legal Regulation of State-Sponsored Cyber Espionage
Russell Buchan
This chapter was pure fantasy.  

In light of state practice, however, ‘[t]he argument that cyberspace constitutes a law-free zone is no longer taken seriously’.
Here, again the lady is protesting quite a lot.

By analogy, I would argue that where a state stores confidential information in servers located in another state or transmits such information through cyber infrastructure located in another state, that information represents ‘a crucial dimension of national sovereignty that presupposes the nation state’ and the right to have that information protected from intrusion flows from the general entitlement of states to have their political integrity respected, that is their sovereignty.
The whole chapter is full of this kind of ridiculous legal rationalization. Don't even bother reading it. Did anyone peer review this book?


Chapter 5
Beyond ‘Quasi-Norms’:  The Challenges and Potential  of Engaging with Norms  in Cyberspace
Toni Erskine and Madeline Carr
Rips up the bombastic and confident tone of the previous chapters by pointing out they are not looking at norms, but just normative aspirations (aka, wishful fucking thinking).

It is not at all surprising to think that agents with particular interests or values will seek to impose rules and codes of conduct on practices that further these interests or values. This is a common, and often laudable, occurrence in discussions of cyberspace. Our very simple point is that these preferred principles and proposed rules are not norms. They are normative aspirations.

This tension between the desire to apply domestic law to digital information that does not remain tethered by geography and the promotion of an online experience that transcends territorial borders is a common framework within which justifications for imposing sovereign control are put forward. What is important here is not exactly how these actors account for their failure to adhere to the principle of de-territorialised data, but the perceived need to do so.

Chapter 6
United Nations Group  of Governmental Experts:  The Estonian Perspective
Marina Kaljurand

A rather sad chapter of helpless indignation.

A major breakthrough on detailed interpretations of international law applicable in cyberspace was not to be expected. However, any consideration that the Group would be able to bring out and agree upon, in addition to the general declaration of 2013, would be a positive development. Estonia recognised that there are complex issues concerning the application of international law, in particular the ‘thresholds’ for a breach of sovereignty, use of force, aggression or armed attack. However, in our view such questions cannot be set theoretically, but rather on a case-by-case basis and taking into account all relevant facts and circumstances. The absence of definitions of these concepts does not mean the impossibility of application of international law.

The preamble of Resolution 58/199 sets a non-exhaustive list of examples of critical infrastructures, such as those used for the generation, transmission and distribution of energy, air and maritime transport, banking and financial services, e-commerce, water supply, food distribution and public health – and the critical information infrastructures that increasingly interconnect and affect their operations.

Estonia sees the 2015 Report as a remarkable achievement. Given the ideological battle and differences in national ICT capabilities, taking the 2013 consensus further was a difficult, but successfully completed task. In particular, Estonia welcomes attention to norms of responsible state behaviour that, in the absence of shared detailed consensus on how international law applies in cyberspace, is a way forward towards building such understanding.


Chapter 7
Patryk Pawlak

CBM's in all flavors and charts. A good chapter - not too technical, but covers some ground. Worth a read.


Chapter 8
Outer Space
Paul Meyer

The following paragraph sets the flavor of badness for the whole chapter. It is like reading Scientology's Dianetics but just because a childhood friend made you.
The third common feature is that while military activity is present in both environments, and has been for several years, these environments have not yet been ‘weaponised’ or transformed into active battle zones. In this context, weaponisation means the general introduction into an environment of offensive arms capable of destroying or damaging objects within that same environment. 

The report recommends that a further GGE be created in 2016, although mere continuation of GGE studies may begin to suffer from diminishing returns. It is evident in the cyber security field that as countries move beyond statements of lofty general principles and begin to address specific measures, divisions of views become more pronounced and concrete outcomes more elusive.

Chapter 9
Greg Austin
China
This chapter avoids the obvious conclusions at all costs.

 A legal norm is the result of diplomatic compromise among the states which crafted it. Moral rectitude is in the eye of the beholder. Thus any privileging of one country’s normative position over that of another state – for example suggesting that the US position is preferred over China’s – is a statement of an individual ethical choice not one of political or legal analysis. 

 One import of this was that the membership of the SCO (all authoritarian states) strongly identified with China’s positions on most issues, especially the balance to be struck between state sovereignty and international openness. 

From the GGE:
States should not attack each other’s critical infrastructure for the purpose of damaging it; • States should not target each other’s cyber emergency response systems; and • States should assist in the investigation of cyber attacks and cyber crime launched from their territories when requested to do so by other states.102

This is not a commitment to refrain from all use of military cyber assets against each other. Article 4 only says that each country has an equal right of self-defence in cyberspace against ‘unlawful use or unsanctioned interference in the information resources of the other side, particularly through computer attack’. Neither Russia nor China regards cyber espionage or preparations for war in cyberspace as ‘unlawful’ or ‘unsanctioned’. 

One important change has been in China’s sense of urgency in using such norms to restrain countries like the US from more rapid strengthening of what China sees as the US hegemonic position in cyberspace. 

By September 2015, there are increasing signs that China feels obliged to cooperate in cyberspace rather than risk the fabric of its economic ties. China’s economy is almost certainly not immune from serious damage that could be brought on by a US cyber attack. 

Chapter 10
Technological Integrity  and the Role of Industry  in Emerging Cyber Norms
Ilias Chantzos and Shireen Alam
An argument against govt control of crypto, written pre-Apple lawsuit, I assume.


Technological integrity is a principle that promotes privacy measures and shuns the prospect of hidden functionality. Law enforcement agencies around the world are battling against widespread encryption and asserting that a lack of backdoors is causing criminal – including terrorist – investigations to ‘go dark’.3 However, it is nearly impossible to have the luxury of strict security together with surveillance, since beyond a certain point the ability to survey erodes security.4 In turn, this means that there remains no option for governments to have spying capabilities without creating this opportunity to criminals. 

Some concrete ways in which the cyber security industry plays a role in influencing cyber norms include: 1) developing the latest technologies and their use; 2) monitoring and informing on the evolution of the threat landscape; 3) engaging in Public Private Partnerships (PPP) and capacity-building efforts; 4) assisting law enforcement in fighting cyber crime; and 5) providing technologies and scalable capabilities to enable countries to implement regulations and public policies.


Government agencies at all levels should form meaningful partnerships with the private sector. A single player does not have all the answers, resources, skills, assets or scalable capabilities to counter rapidly growing and evolving cyber threats. Therefore, it is in the interests of all parties to foster different collaboration models that enable the exchange of information, as well as the dissemination of expertise and capacity-building. 

Missing is the idea that governments are often the adversary. :)


Chapter 11
Microsoft whinging.



Friday, March 18, 2016

"I am a Chinese operator"

This piece was originally posted to the DailyDave mailing list (which you should subscribe to!) but I am including it below since it illustrates the concept better than my post here:

So here I am as a Chinese tool developer and operator on one of the
lesser known, but higher skills teams, sitting at my desk drinking
Starbucks, uber-ironically, as I like to do.  We work for the PLA out
of an office in Shanghai, but we don't have a catchy name. Just the
world's most boring cover company that in theory does IT Support for the
local businesses, but in reality does anything but.

I'm finishing up a heap overflow in Flash, technically an integer
overflow, that leads to heap corruption, if you must know. The PLA group
I work for has given me about a few million 32-bit key numbers, which
are stored on a laptop that has never been connected to any network, and
is itself stored in a safe in the back room. I open it up, and run a
quick script to find a 32-bit number from the set that has no bad bytes
in it, and also is a NOP for the purposes of this exploit.

I use that as the fill-string for my exploit, and then for my Javascript
obfuscator pick another one of the numbers and use that as my XOR key.
The third one I use inside the shellcode itself. I mark these three
numbers as used in a file so I don't reuse them later. All my other
variables names are unrelated 32-bit numbers, because why not? But this
is a heap overflow, and not an MFC application, so I don't have room to
sign giant cryptographically secure blobs of random numbers with a
private key of any sort.

What I'm hacking today is a concrete company. They compete with the
Chinese concrete companies in many places of the world, but that's not
the point. They also supply the US Military's Asian bases. So while I
will be pulling down their entire Exchange server, once I get into their
network, which is basically a forgone conclusion, I'm not here for
industrial espionage purposes. Likewise, knowing how much they are
selling goes into our larger economic reports, which are used to make
decisions by the State in terms of interest rates and that sort of
thing. Stuff above my level.

I fire my exploit off at my target three times, to three different
people. One of them succeeds, and I've made my coffee money for the day
(and a bunch more, let's be honest, this is a good gig). I have been
told that if I give any email from this target to my friend who works in
construction, I will of course be fired.

But one of them gets silently caught, and Mandiant includes it in a
report, along with a long detailed description about my trojan, which I
stole from a Russian criminal group. Later, because that concrete
company has been losing a lot of business in Asia a DHS official is
asked if this intrusion is a potential violation of our agreement. He
looks at the very detailed internal Mandiant report on the initial
intrusion, and runs each interesting constant in the report through his
oracle, forwards and backwards, and he says, "I cannot say whether or
not it is the Chinese or the Russians, but they are CLAIMING to follow
our norms process, at least."