I couldn’t tweet a better description than the headline for this piece: After SolarWinds breach, lawmakers ask NSA for help in cracking Juniper cold case.

For those who haven’t heard this story, the context here is back in 2015 hackers broke into the source code repository of Juniper’s NetScreen firewalls and introduced serious vulnerabilities. 1/
Everyone has heard of the SolarWinds supply chain attack, but almost nobody outside our little community remembers Juniper. We don’t even know who the ultimate victim was. And there’s a reason for that. 2/
The reason is simple: following the Juniper hack, the FBI and Juniper put a tight lid on everything. Nobody, including members of Congress, were able to get straight answers about who did it or what the target was. So it vanished from our collective memory. 3/
This has real consequences. To some extent our lack of preparedness for SolarWinds is a direct result of our government’s decision to pretend that the previous major supply-chain attacks didn’t happen. 4/
Why has the Juniper attack been buried by secrecy? There are two possible answers. One has to do with the nature of the hack, which very likely repurposed an existing backdoor in NetScreen firewalls. The other has to do with the ultimate target. 5/
Regarding the first, we know that Juniper included a *likely* crypto backdoor based on an NSA algorithm called Dual_EC_DRBG even before the hack. We also know that the attackers repurposed that code to use new public keys of their choosing. This is very embarrassing. 6/
(We know this because people on Twitter and co-authors of mine were able to reverse engineer the details from the published firmware images. See here for a nice explanation. https://t.co/CPHw8oA6zA)
The second answer to “why was this buried” is much more speculative. It has to do with the identity of the actual target(s) that were attacked using the NetScreen vulnerabilities. We don’t know who they are, and they might be important. 8/
I continue to harbor the conspiracy theory that the Office of Personnel Management hack was in some way related to Juniper, based solely on the timing and some equipment manifests from that agency. I’m probably wrong, but that would be a hell of a reason to cover things up. 9/
The point here is that with attacks like this and a secrecy response, we’re screwed. Until we know what happened in these cases, we can’t learn from it. This makes us defenseless, and you can bet our adversaries prefer it that way. 10/
It’s as though the US government decided to react to Pearl Harbor by covering things up. You have to imagine that history would look a lot different. Hopefully we’ll stop making this mistake. //fin

More from Law

This issue was repeatedly highlighted bu Judge Totenberg:

Dominion’s system “does not produce a voter-verifiable paper ballot or a paper ballot marked with the voter’s choices in a format readable by the voter because the votes are tabulated solely from the unreadable QR code.”


Judge also found that Dominion's QR codes are NOT encrypted:

“Evidence plainly contradicts any contention that the QR codes or digital signatures are encrypted,”

This was “ultimately conceded by Mr. Cobb and expressly acknowledged later by Dr. Coomer during his testimony.”

Judge Totenberg said there was “demonstrable evidence” that the implementation of Dominion’s systems by Georgia placed voters at an “imminent risk of deprivation of their fundamental right to cast an effective vote,” which she defined as a “vote that is accurately counted.”

Judge Totenberg found that Dominion Systems inherently could not be audited.

She noted that auditors are severely limited and “can only determine whether the BMD printout was tabulated accurately, not whether the election outcome is correct.“

Totenberg stated in her ruling that a BMD printout “is not trustworthy” and the application of an Risk-Limiting audit (RLA) to an election that used BMD printouts “does not yield a true risk-limiting audit.”

Georgia used RLAs to claim no fraud...
We need to talk about the 'expert' witness statement evidence led by Ms Bell in her successful case before the Tavistock. THREAD

You can see who gave evidence in her support from these extracts from the Tavistock's Skeleton Argument.


Helpful for you to bear in mind that her solicitor was a man called Paul Conrathe, who has a long association with the religious right in the US (I have talked about him a number of times but this is as good a starting point as any).


I am not going to address here other criticisms that might be made of the form in which that evidence was given or the timing of its service before the court. I am just going to address, in alphabetical order, the individuals whose evidence Mr Conrathe led on Ms Bell's behalf.

The first witness, alphabetically, was Associate Professor of Sociology at the University of Oxford, Michael Biggs.

Mr Biggs was exposed for posting transphobic statements online under a fake twitter handle: @MrHenryWimbush according to this report.
High crime talk from Fredo


VA curfew


Sen. Grassley - Biden family investigated, potential financial crimes WW including China

Warning


March

You May Also Like

First thread of the year because I have time during MCO. As requested, a thread on the gods and spirits of Malay folk religion. Some are indigenous, some are of Indian origin, some have Islamic


Before I begin, it might be worth explaining the Malay conception of the spirit world. At its deepest level, Malay religious belief is animist. All living beings and even certain objects are said to have a soul. Natural phenomena are either controlled by or personified as spirits

Although these beings had to be respected, not all of them were powerful enough to be considered gods. Offerings would be made to the spirits that had greater influence on human life. Spells and incantations would invoke their


Two known examples of such elemental spirits that had god-like status are Raja Angin (king of the wind) and Mambang Tali Arus (spirit of river currents). There were undoubtedly many more which have been lost to time

Contact with ancient India brought the influence of Hinduism and Buddhism to SEA. What we now call Hinduism similarly developed in India out of native animism and the more formal Vedic tradition. This can be seen in the multitude of sacred animals and location-specific Hindu gods