back

by AdamN·9y ago·view on hn ↗
Cool Tom Clancy premise but the CIA and NSA are looking pretty tarnished with their core data processes leaking publicly. This costs them a ton of political capital. They have channels to give the vendors the exploits in a controlled way - which they would do if they wanted to (and surely have if they think the exploit is too broadly known).
1 comments
I agree. I say this somewhat regularly, so sorry to repeat it, but --- and I'm not especially well-informed here --- I think the best way to evaluate NSA and CIA motives, at least with respect to infosec, is that their #1 objective isn't geopolitical, but simply headcount. Whatever secures the most budget is going to be at the top of their stack of objectives.

Massive turnover, which is what events like this create, works directly against the goal of securing more headcount: it means they're spending a big chunk of their recruiting energy just retaining the headcount numbers they already have.

I disagree with your premise that headcount is the primary objective, but agree that career progression is the end goal of many, if not most, executives in the IC.

Headcount is one of many metrics that can constitute success and eventual promotion. I posit that giving flashy results to customers is the #1 best way for a particular executive to make a name for herself and advance. FBI is a great example of this, constantly attempting to make splashy headlines; it presses its advantage of being able to go to the press.

I've only seen headcount increase in response to what WH, ODNI, and Congressional intelligence committees view as crises. Headcount shuffles away for objectives that aren't considered sexy, e.g. Russian linguists and analysts in the late 1990s-2000s.

I understand what you're saying but I don't think we have two different interpretations of the same worldview, but that instead we simply disagree. I think budget and headcount are more important objectives to NSA than flashy results. If there's a tradeoff to be made between achieving a flashy objective and securing more budget, I think NSA is likely to pursue the latter, not the former.

To me and for the kind of work I do, this has important implications: it means that you shouldn't do things to make it harder for NSA to do their job (that's just feeding them, just like feeding in DOTA or LOL) --- you have to make things intractable for them.

I know you have worked with former IC cryptographers and developers at Matasano/NCC Group. I still assert that this world view is inaccurate. I respect where you're coming from.

Intelligence agencies are lead by people. Those people have motivations that inform their decision-making. Prestige, power, increased income, and (often, but not always) patriotism are, in my opinion, their primary motivators. This should for the most part be similar for any corporate executive.

Unless there are hard metrics tying headcount to performance reviews and promotion considerations, and simultaneously soft-power incentives for having more headcount, then other things will dominate. In the military, splashy achievements dominate. Or at the minimum, making your boss and your boss's boss like you is essential.

The current NSA chief didn't get his job because he was in charge of the largest Fleet. He got it by networking, seniority, luck, and having a reputation for excellence (I do not know if it is deserved). The same can be said about civilian executives in the IC, who are rated in a more arduous, more holistic manner.

Your bottom line is correct in the specific case. If a Latacora client is targeted by the NSA with high priority, you cannot protect it unless you make it intractable for them. For the rest of us, using boring commodity mitigations, such as TLS and MFA, and sound network architecture are fine. Intractable-for-all is a noble effort, but I don't think it's realistic.

Configured properly, boring TLS can be made effectively intractable. From a cryptographic perspective, I don't think intractable is at all unrealistic --- and I don't know many crypto engineers who think it is.
That's the least interesting part of my comment. Sure, TLS is great. What about the rest?
I don't know how incompatible the rest of it is with things I already said. I would just suggest that the NSA is less motivated by preventing terrorism than it is by protecting and expanding the careers of the NSA rank and file.