Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

MUSCULAR

From Wikipedia, the free encyclopedia
(Redirected fromMUSCULAR (surveillance program))
Joint UK and USA surveillance program

National Security Agency surveillance
Map of global NSA data collection as of 2007[update], with countries subject to the most data collection shown in red

MUSCULAR (DS-200B), located in theUnited Kingdom,[1] is the name of a surveillance program jointly operated by Britain'sGovernment Communications Headquarters (GCHQ) and the U.S.National Security Agency (NSA) that was revealed by documents released byEdward Snowden and interviews with knowledgeable officials.[2] GCHQ is the primary operator of the program.[1] GCHQ and the NSA have secretly broken into the main communications links that connect thedata centers ofYahoo! andGoogle.[3] Substantive information about the program was made public at the end of October 2013.

Overview

[edit]
Idea behind the MUSCULAR program, which gave direct access to Google and Yahoo private clouds, no warrants needed.
Idea behind the MUSCULAR program, which gave direct access to Google and Yahoo private clouds, no warrants needed.

The programme is jointly run by:

MUSCULAR is one of at least four other similar programs that rely on a trusted 2nd party, programs which together are known asWINDSTOP. In a 30-day period from December 2012 to January 2013, MUSCULAR was responsible for collecting 181 million records. It was however dwarfed by another WINDSTOP program known (insofar) only by its codeDS-300 and codenameINCENSER, which collected over 14 billion records in the same period.[4]

Operational details

[edit]

According to the leaked document the NSA's acquisitions directorate sends millions of records every day from internal Yahoo! and Google networks to data warehouses at the agency's headquarters atFort Meade, Maryland. The program operates via an access point known asDS-200B, which is outside the United States, and it relies on an unnamed telecommunications operator to provide secret access for the NSA and the GCHQ.[3]

According toThe Washington Post, the MUSCULAR program collects more than twice as many data points ("selectors" in NSA jargon) compared to the better knownPRISM.[2] Unlike PRISM, the MUSCULAR program requires no (FISA or other type of)warrants.[dubiousdiscuss]

Because of the huge amount of data involved, MUSCULAR has presented a special challenge to NSA'sSpecial Source Operations. For example, when Yahoo! decided to migrate a large amount of mailboxes between its data centers, the NSA'sPINWALE database (their primary analytical database for the Internet) was quickly overwhelmed with the data coming from MUSCULAR.[5]

Closely related programmes are called INCENSER andTURMOIL. TURMOIL, belonging to the NSA, is a system for processing the data collected from MUSCULAR.[1]

According to apost-it style note from the presentation, the exploitation relied on the fact that (at the time at least) data was transmitted unencrypted inside Google'sprivate cloud, with "Google Front End Servers" stripping and respectively adding backSSL from/to external connections. After the information about MUSCULAR was published by the press, Google announced that it was working on deployingencrypted communication between its datacenters.[2]

Reactions and countermeasures

[edit]
[icon]
This sectionneeds expansion. You can help byadding missing information.(January 2014)

In early November 2013, Google announced that it wasencrypting traffic between its data centers.[6] In mid-November, Yahoo! announced similar plans.[7]

In December 2013,Microsoft announced similar plans and used the expression "advanced persistent threat" in their press release (signed-off by their top legal representative), which the press immediately interpreted as comparison of the NSA with theChinese government-sponsored hackers.[8][9]

Google engineer Brandon Downey stated the following onGoogle+:[10]

"Fuck these guys.I've spent the last ten years of my life trying to keep Google's users safe and secure from the many diverse threats Google faces… But after spending all that time helping in my tiny way to protect Google -- one of the greatest things to arise from the internet -- seeing this, well, it's just a little like coming home from War with Sauron, destroying the One Ring, only to discover the NSA is on the front porch of the Shire chopping down the Party Tree and outsourcing all the hobbit farmers with half-orcs and whips."

Gallery

[edit]
  • Slide from NSA SSO presentation detailing the MUSCULAR capabilities
    Slide from NSA SSO presentation detailing the MUSCULAR capabilities
  • Internal NSA SSO update on the MUSCULAR operation, mentioning problem with Yahoo mailbox transfers, which required a throttling of data capture
    Internal NSA SSO update on the MUSCULAR operation, mentioning problem with Yahoo mailbox transfers, which required a throttling of data capture

See also

[edit]

References

[edit]
  1. ^abcGellman, Barton; Soltani, Ashkan; Peterson, Andrea (November 4, 2013)."How we know the NSA had access to internal Google and Yahoo cloud data".The Washington Post. RetrievedNovember 5, 2013.
  2. ^abcGellman, Barton; Soltani, Ashkan (October 30, 2013)."NSA infiltrates links to Yahoo, Google data centers worldwide, Snowden documents say".The Washington Post. RetrievedOctober 31, 2013.
  3. ^abGellman, Barton; DeLong, Matt."How the NSA's MUSCULAR program collects too much data from Yahoo and Google".The Washington Post. Archived fromthe original on 30 October 2013. Retrieved28 December 2013.
  4. ^Gellman, Barton; DeLong, Matt (2013-10-30)."One month, hundreds of millions of records collected".The Washington Post. Archived fromthe original on 2019-04-16. Retrieved2014-01-27.
  5. ^Gallagher, Sean (October 31, 2013)."How the NSA's MUSCULAR tapped Google's and Yahoo's private networks".Ars Technica. RetrievedNovember 1, 2013.
  6. ^Gallagher, Sean (2013-11-06)."Googlers say "F*** you" to NSA, company encrypts internal network".Ars Technica. Retrieved2014-01-15.
  7. ^Brandom, Russell (2013-11-18)."Yahoo plans to encrypt all internal data by early 2014 to keep the NSA out".The Verge. Retrieved2014-01-27.
  8. ^Danny Yadron (2013-12-05)."Microsoft Compares NSA to 'Advanced Persistent Threat' - Digits - WSJ". Blogs.wsj.com. Retrieved2014-01-15.
  9. ^Tom Warren (2013-12-05)."Microsoft labels US government a 'persistent threat' in plan to cut off NSA spying".The Verge. Retrieved2014-01-15.
  10. ^Opam, Kwame (2013-11-06)."Google engineers issue 'fuck you' to NSA over surveillance scandal".The Verge. Retrieved2023-04-17.

External links

[edit]
Locations
Leaders
Divisions
Technology
Controversy
Programs
Databases
Other
Retrieved from "https://en.wikipedia.org/w/index.php?title=MUSCULAR&oldid=1313800362"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp