Showing posts with label Keeping Ourselves Secure. Show all posts
Showing posts with label Keeping Ourselves Secure. Show all posts

Wednesday, December 10, 2025

The National Security Strategy, 2025


This past week, with none of the fanfare that has accompanied past releases of the document, Der Furor's administration released its 2025 National Security Strategy

The National Security Strategy (or NSS), released annually, explains an administration's view of the challenges the United States faces around the world and provides the framework around which government agencies are expected to plan their activities to implement the president's national security vision. As you might expect from an administration largely staffed with unqualified and incompetent people, the 2025 NSS is a mess, described by one commentator as seeming to have been written by either a fourth-grader or AI. Reading it, you might be excused for thinking the cover should have read a bit differently - 


First of all, as anyone who has watched one of Der Furor's Cabinet meetings could have expected, the document is heavy on effusive praise of the matchless accomplishments of the Supreme Leader ...

"President Trump has cemented his legacy as The President of Peace. In addition to the remarkable success achieved during his first term with the historic Abraham Accords, President Trump has leveraged his dealmaking ability to secure unprecedented peace in eight conflicts throughout the world over the course of just eight months of his second term." (Page 8)

"President Trump has set a new global standard" (Page 12) 

"[The] “Trump Corollary” to the Monroe Doctrine is a common-sense and potent restoration of American power and priorities" (Page 15)

"President Trump single-handedly reversed more than three decades of mistaken American assumptions about China" (Page 19) 

"President Trump is building alliances and strengthening partnerships in the Indo-Pacific that will be the bedrock of security and prosperity long into the future." (Page 19)

"President Trump’s May 2025 state visits to Persian Gulf countries demonstrated the power and appeal of American technology." (Page 23) 

"The Israeli-Palestinian conflict remains thorny, but thanks to the ceasefire and release of hostages President Trump negotiated, progress toward a more permanent peace has been made." (Page 28) 

"President Trump’s ability to unite the Arab  world at Sharm el-Sheikh in pursuit of peace and  normalization will allow the United States to finally prioritize American interests." (Page 29) 

You could be forgiven for thinking that there's no need for any government other than the all-powerful genius of Der Furor.

While claiming to have "rebuilt our alliances" (Page i), this president has thoroughly wrecked our international standing and insulted and alienated traditional allies who now decline to share intelligence information they fear may be used to facilitate war crimes ... as if we were in an actual war Constitutionally declared by Congress.

I could go on, but I call your attention to this excellent article by Eliot Cohen in The Atlantic, which discusses the incoherence and idiocy of this NSS while acknowledging that it does contain "three ideas that, stripped of the rants and the brownnosing, are important and at least partially true*." You may also be interested in this article by Jason Horowitz from the New York Times, which looks at the "strategy" in terms of its showcasing of Der Furor's contempt for European leaders.

The "National Security Strategy for 2025" demonstrates how, in the space of a mere 11 months, one shallow, spiteful, unserious man ignorant of all but his own prejudices, aided and abetted by a servile Congress and a loftily arrogant Supreme Court, has destroyed our standing in the world and our reputation as a reliable ally.

Have as good a day as you can consistent with the destruction of our international reputation and the debasement of competent and accountable government.

More thoughts coming.

Bilbo

* These are: (1) acknowledgement of the importance to the United States of the Western Hemisphere; (2) a change in approach to African nations from direct development aid to improvement in commerce; and (3) emphasizing the threat of uncontrolled mass migration to European nations.

Tuesday, April 25, 2023

Of MICE and Men



Those of you who have been with me for a while know that I spent my entire career working in the world of military intelligence, on active duty in the Air Force and later, after my military retirement, as a government contractor supporting Air Force programs ... a total of more than 40 years dealing with secret stuff. I think this gives me a certain amount of authority to talk about the related topics of (1) the need to protect government secrets, (2) how we protect those secrets, and (3) the attitude of some people toward the protection of those secrets.

The immediate impetus for me to write this post was the arrest of a young Air National Guard Airman for his cavalier sharing of classified material he downloaded from secure networks in the course of his job as an IT specialist. Here's a guy who, like many thousands of other clearance-holders, was investigated and adjudicated before being granted access to classified material. Unlike most of those others, he chose to ignore the security guidelines in place and recklessly share extraordinarily sensitive material. Why did he do that?

People who make a living catching those who leak classified material will tell you that there are four reasons most people engage in espionage: for money, for ideology, because they've been compromised (blackmailed), or as an ego trip - hence the acronym MICE. But in the case of the young airman now sitting in jail, none of these really seem to apply. His motivation appears to have been a muddled mixture of a need to show off to his online friends, mixed with a confused desire to show "the people" what is really happening in the world. He apparently believed that the vast experience he'd amassed as a 21-year-old Airman First Class gave him the expertise and the authority to expose information that could (and likely will) cost lives.

So, IMHO, he's both ignorant and traitorous, and he deserves to be in jail ... as does a certain former president who was also (and continues to be) blithely cavalier with sensitive material. Guess which one is in jail? Hint ... it's not the one who can hire reinforced battalions of lawyers and convince ignorant laymen that he's being unfairly picked on.

But the question in my mind is this: how was it that this 21-year-old Airman was able to access such extraordinarily sensitive information? In short, because of two things: networks and the traditional tension between the need to protect information and the need to make it easily available to those who need it (who have a need to know).

When I entered the world of military intelligence in 1973, back when dinosaurs roamed the earth, everything was on paper. It was stored in big, heavy safes which were kept in locked rooms which were often alarmed. If the contents were really sensitive, the safe would have two combination locks, and no single person was allowed to have both combinations. The most sensitive documents had unique control numbers and had to be signed in and out, and the records of their storage and access were audited at regular intervals. Most copy machines in secure areas needed a special key (which had to be signed for) to be operated, and had counters that recorded the number of copies made. Yes, things got leaked back then in the stone age, but it was a lot more cumbersome and dangerous to do so.

By the mid-80s or so, word processors started to become widespread, followed by standalone PCs, which begat networks and digital storage and transfer. This had both advantages and disadvantages. It reduced the amount of loose paper that needed to be stored in expensive, bulky safes and controlled with cumbersome handling measures, but it also introduced security vulnerabilities in storage and transfer. The IT specialists who set up, managed, and maintained the networks had to be authorized for access to the highest level of material on their networks - not because they had a need to know, but because the nature of their work gave them the opportunity to see everything that was there. This is what made the IT Airman in Massachusetts so dangerous.

Let's talk about the whole need to know issue. Need to know is supposedly one of the criteria for access to classified information ... it's not enough to be approved for access to information classified at a certain level - there must be an operational reason for you to have that access - a need to know. Some programs are considered so sensitive that the rule for access becomes "Must Know" - you cannot do your job unless you have access to that information. There's also another school of thought that says increased access to various sources and types of classified information leads to better analysis and improved decision-making ... this is the "Need to Share" camp. 

So, what does all this mean?

Classification is expensive and cumbersome. Safes rated to store paper files and removable electronic media are big (take up space), heavy (require buildings that can support their weight*), and very expensive. Networks become more expensive as the amount of digital protection increases, and increasing levels of protection often require multiple sets of equipment, independent connections, and separate access methods ... and wireless connectivity is dangerous in itself, being subject to interception en route. 

In my last job before retirement, I had three separate computers on my desk which allowed me to access four different networks at increasing levels of sensitivity. And the offices in which I worked, located in the already-heavily-defended Pentagon, were secured by combination locks and multiple alarms and access control policies and systems.

So, yeah, all this security is cumbersome and very, very expensive. Is it necessary? In some cases, certainly. In other cases, maybe. In still other cases, probably not. Who decides? Who makes the rules about what needs to be protected at what level, for how long, and from whom? Who watches the watchers? 

This is the hand-wringing discussion we have every time there's a major compromise of our intelligence and security. I don't profess to have the right answer ... I have suggestions that might help**, but it's no longer my problem. The people we pay to be security officers will have to figure it out. We will always have information that needs to be protected, we will always have people who want access to it that they shouldn't have, and no security system is perfect. As my dad used to say, locking all the doors and windows keeps the honest people out.

If you happen to be a person with access to sensitive information, remember that you don't get a vote on who you can share it with. Things are classified at a particular level for a particular reason. If you disagree, you can try to work it out with the person who originally classified it, or look for official channels through which you can appeal the classification.

The Internet ain't one of them. 

Have a good day. Thanks for letting me get this off my chest. More thoughts coming.

Bilbo

* Many years ago, my unit's offices were in rickety old two-story World War II-era open-bay wooden barracks (they've long since been torn down). The four-drawer safes on the upper floor (and there were a lot of them) had to be placed next to wooden support beams, otherwise they'd have a better-than-even chance of crashing down onto the heads of those of us on the ground floor. You can bet that we were attuned to every noise those buildings made.

** Starting with figuring out how to prevent IT people from accessing network content while doing network maintenance. Don't ask me how.

Thursday, September 28, 2017

Number, Please


One of the stock scenes in movies about espionage and suspense during World War II and the Cold War (the first one) comes when the steely-eyed Gestapo agent or hostile policeman demands to "see your papers," and waits with outstretched hand while the hapless victim scrambles to provide his or her identification.

In the United States, of course, we don't have "papers" - a single national form of identification like most of the rest of the world does - no national ID, no internal passport, or whatever. The closest thing we have is a driver's license, and even those aren't necessarily accepted outside one's own home state.

But we do have Social Security Numbers.

It's virtually impossible nowadays to get credit, rent cars or apartments, go to school, or just about anything else without producing a valid Social Security Account Number (or SSAN). It's the key to your entire financial history and - along with your date of birth - is the information most prized by identity thieves and scammers. So widespread is the use of the SSAN, and so often have databases containing them been compromised, that they have become laughable - if not downright dangerous - as a form of unique and supposedly secure identification.

But what's the alternative? In an interesting and comprehensive Washington Post article, consumer technology reporter Hayley Tsukayama discussed the various alternatives that have been proposed as forms of unique identification and why each was found wanting. Biometrics (fingerprints, retinal scans, facial recognition, etc), blockchains, and a new national ID number have all been proposed, but each has faced opposition on the basis of security or privacy concerns.

Which leaves us with the original question: what's an appropriate, secure form of ID in a high-tech and supremely invasive world?

Nobody asked me, but I have a suggestion that makes use of a uniquely American trait: our love of firearms.

Why not kill a few birds with a single high-caliber stone by reinterpreting the Second Amendment to require every American to purchase and maintain a gun, and then use a combination of the manufacturer and the serial number of the personal firearm as the official ID? Instead of the traditional and badly compromised nine-digit SSAN (XXX-XX-XXXX), the average American would have an ID like "GlockABC1234," "SmithandWesson98047Z9X," or "Beretta54937Y." They might be difficult to remember at first, but that's a small price to pay for reinforcing the quintessential all-American love of guns.

I think this suggestion has a lot going for it: it honors the traditional American worship of firearms; expands the scope of the Second Amendment*; boosts the economy by greatly increasing the sale of firearms and ammunition; and produces an endless supply of possible ID numbers because of the differing numbering systems used by various manufacturers. In addition, because many Americans own large numbers of guns, the compromise of one ID number would not be a disaster because the individual could simply switch to another from his personal armory; those slackers who fail to maintain multiple guns could just buy a new one and start over. On the downside, I can see the more suspicious members of the pro-gun community objecting on the basis that this might make it easier for the government's Jackbooted Thugs™to swoop down in their black helicopters and confiscate everyone's guns ... after all, President Obama did that, right? Oh ... wait ... never mind.

That's my idea for improving national identification standards - what's yours? Leave a comment and be a ... big shot ... by offering a better idea if you have one.

Have a good day. Fire at will. More thoughts tomorrow.

Bilbo

* After all, the Supreme Court expanded its intent from the arming of a citizen's militia (itself a reflection of a traditional American opposition to a standing army that might suppress citizens' rights) to a guarantee of the right of weapon ownership for personal protection (see District of Columbia v Heller, 554 US 570).