KEMBAR78
Summarising Snowden and Snowden as internal threat | PPTX
Exposed NSA’s evil snooping
Good Guy
1
…for the world
Exposed internal secrets
BAAAAD Guy …for his organization
2
1
Xkeyscore
TAO
PRISM
GCHQ *
VictoryDance
http://projects.propublica.org/nsa-grid/
Hammerchant – Spy on VoIP & VPN
ANT catalog – Inject surveillance software in Apple cisco dell products
WellSpring – Collect images from email based on face recognition
DishFire – Collect upto 200million SMS a day
NoseySmurf – Smurf in iPhones & Android, turning on mic & track loc
Bullrun – NSA & GCHQ effort to weaken cryptography standards/tools
ShotGiant – program to break Chinese Huawei networks and products.
Upstream – program collects communications transiting the Internet
HappyFoot– use cookies & data from phone apps to identify users'
devices and physical locations
http://projects.propublica.org/nsa-grid/
Alphabetical list of NSA Programs and Tools
• A
AGILITY - NSA internet information tool or database
AGILEVIEW - NSA internet information tool or database
ALPHA - SIGINT Exchange Designator for Great Britain
ANCHORY - NSA software system which provides web access to textual
intelligence documents
AUTOSOURCE - NSA tool or database
AQUACADE - A class of SIGINT spy satellites (formerly RHYOLITE)
ASSOCIATION - NSA tool or database
• B
BANYAN - NSA tool or database
BELLTOPPER - NSA database
BELLVIEW -
BINOCULAR - Former NSA intelligence dissemination tool
BLACKPEARL - NSA tool or database
BLARNEY - NSA internet and telephony network collection program
BOUNDLESS INFORMANT - DNI and DNR data visualization tool.
BULLRUN
BYEMAN (BYE) - Retired control system for overhead collection systems
(1961-2005)
• C
CADENCE - NSA collection tasking tool or database
CANYON - Class of COMINT spy satellites (1968-1977)
CANNON LIGHT - Counterintelligence database of the US Army
CHESS- Compartment of TALENT KEYHOLE for the U-2 spy plane
CONFIRM - NSA database for personell access
CONTRAOCTAVE - NSA tool or database
CONVEYANCE - A voice content ingest processor? / Provide filtering for PRISM.
CORONA - A series of photographic surveillance satellites (1959-1972)
COURIERSKILL - NSA Collection mission system
CREST - Database which automatically translates foreign language intercepts in
English
CRYPTO ENABLED - collection derived from AO's efforts to enable crypto (cf.
lemonde.fr)
CULTWEAVE - Smaller size SIGINT database *
• D
DANCINGOASIS - (?)
DELTA - Compartment for COMINT material from intercepts of Soviet military
operations
DIKTER - SIGINT Exchange Designator for Norway
DINAR - Predecessor of the UMBRA compartment for COMINT
DISHFIRE - NSA internet information tool or database
DROPMIRE - passive collection of emanations using an antenna
DRTBOX -
DRUID - SIGINT Exchange Designator for third party countries
DYNAMO - SIGINT Exchange Designator for Denmark
• E
ECHELON - A SIGINT collection network run by Australia, Canada,
New Zealand, the United Kingdom, and the United States,
ECHO - SIGINT Exchange Designator for Australia
EVILOLIVE -
• F
FAIRVIEW - NSA internet and telephony network collection program
FALLOUT - DNI metadata ingest processor / Provides filtering for
PRISM.
FISHBOWL - NSA program for securing commercial smartphones
FOREMAN - ?
FOXACID - target the TOR's users
• G
GMMA (G) - Compartment for highly sensitive communication
intercepts
GAMUT - NSA collection tasking tool or database
GENIE - implants of spywares
GENTE - multi-stage opetation; jumping the airgap etc. (lemonde.fr -
GLOBAL BROKER - NSA tool or database
• H
HAVE BLUE - Development program of the F-117A Stealth fighter-
bomber
HAVE QUICK (HQ) - Frequency-hopping system used to protect military
UHF radio traffic
HERCULES - CIA terrorism database
HIGHTIDE - NSA tool or database
HIGHLANDS - spywares implants
• I
INDIA - SIGINT Exchange Designator for New Zealand
INTRUDER - Series of ELINT and COMINT spy satellites (since 2009)
ISHTAR - SIGINT Exchange Designator for Japan
IVY BELLS - NSA, CIA and Navy operation to place wire taps on Soviet
underwater communication cables
• J
JEROBOAM - Another name used for the TRUMPET spy satellites
JUGGERNAUT - Picks up all signals from mobile networks
JUMPSEAT - Class of SIGINT reconnaissance satellites (1971-1983)
• K
KLONDIKE (KDK) - Control system for sensitive geospatial intelligence
• L
• LIFESAVER - imaging of the hard driver (from lemonde.fr
LITHIUM - ?
LOPERS - Software application for Public Switched Telephone Networks
• M
MAGIC LANTERN - A keystroke logging software developed by the FBI
MAGNETIC - sensor collection of magnetic emanations (lemonde.fr)
MAGNUM - Series of SIGINT spy satellites (since 1985)
MAILORDER -
MAIN CORE - Federal database of personal and financial data of
suspicious US citizens
MAINWAY - NSA database of bulk phone metadata (Call records DB)
MARINA - NSA database of bulk internet metadata (Internet records DB)
MENTOR - Class of SIGINT spy satellites (since 1995)
MESSIAH - NSA automated message handling system
METTLESOME - NSA Collection mission system
MINARET - A sister project to Project SHAMROCK (1967-1973)
MINERALIZE - collection from LAN implant (lemonde.fr
MOONLIGHTPATH - An NSA collection program
MORAY - Retired compartment for the least sensitive COMINT material
• N
NUCLEON - Database for contents of phone calls (Voice data DB)
• O
OAKSTAR - NSA internet and telephony network collection program, voir
aussi "2013 mass surveillance disclosures".
OCEAN - (?) from lemonde.fr.
OCEANARIUM - Database for SIGINT from NSA and intelligence sharing
partners around the world.
OCELOT - Probably a NSA program for collection from internet and
telephony networks
OCTAVE - NSA tool for telephone network tasking
OCTSKYWARD - NSA tool or database
OSCAR - SIGINT Exchange Designator for the USA
• P
PATHFINDER - SIGINT analysis tool (made by SAIC)
PINWALE - Database for recorded signals intercepts/internet content (Video
data DB)
PLUS - NSA SIGINT production feedback program *
PRISM - NSA collection program for foreign internet data
PROTON - Smaller size SIGINT database
PURPLE - Codename for a Japanese diplomatic cryptosystem during WWII
PUZZLECUBE - NSA tool or database
• Q
QUANTUM - see FOXACID - target the TOR's users,
• R
RADON - host tap than can inject Ethernet packets onto the same target -
exploitation of denied networks (cf. lemonde.fr)
• RAGTIME (RT) - Codeword for four NSA surveillance programs
(Ragtime-A, B, C et P).
RAMPART / RAMPART-T - penetration of hard targets at or near leadership level
RENOIR - NSA telephone network visualization tool
RESERVE (RSV) - Control system for the National Reconnaissance Office (NRO)
RICHTER - SIGINT Exchange Designator for Germany
RUFF - Compartment of TALENT KEYHOLE for IMINT satellites
RHYOLITE - Class of SIGINT spy satellites (in 1975 changed to AQUACADE)
• S
• SABRE - Retired(?) SIGINT product codeword
SAVILLE - Narrow band voice encryption used for radio and telephone
communication
SCISSOR
SCORPIOFORE -
SHARKFIN - Sweeps up all-source communications intelligence at high speed and
volumes
SEMESTER - NSA SIGINT reporting tool
SENTINEL - NSA database security filter
SETTEE- SIGINT Exchange Designator for South Korea
• SHAMROCK - Operation for intercepting telegraphic data going in or
out the US (1945-1975)
SHELLTRUMPET - NSA metadata processing program
SILKWORTH - A software program used for the ECHELON system
SIRE - A software program used for the ECHELON system
SKYWRITER - NSA internet intelligence reporting tool
SOLIS - SIGINT product databases
SPHINX - Counterintelligence database of the Defense Intelligence
Agency
SPINNERET - an NSA operational branche?
SPOKE - Retired compartment for less sensitive COMINT material
STELLARWIND (STLW) - SCI compartment for the President's
Surveillance Program information
STONE GHOST - DIA classified network for information exchange
with UK, Canada and Australia
STORMBREW - NSA internet and telephony network collection
program
STUMPCURSOR - Foreign computer accessing program of the
NSA's Tailored Access Operations
• T
• TALENT KEYHOLE (TK) - Control system for space-based collection
platforms
TALK QUICK - An interim secure voice system created to satisfy urgent
requirements imposed by conditions to Southeast Asia. Function was
absorbed by AUTOSEVOCOM
TAPERLAY - covername for Global Numbering Data Base (GNDB)?
TAROTCARD - NSA tool or database
TEMPEST - Investigations and studies of compromising electronic
emanations
THINTREAD - NSA program for wiretapping and sophisticated analysis of
the resulting data
TRAFFICTHIEF - Part of the TURBULENCE and the PRISM programs
TRAILBLAZER - NSA Program to analyze data carried on communications
networks
TREASUREMAP - NSA internet content visualization tool
TRIBUTARY - NSA provided voice threat warning network
TRINE - Predecessor of the UMBRA compartment for COMINT
TRUMPET - Series of ELINT reconnaissance satellites (1994-2008)
TUNINGFORK - NSA tool or database
TURBULENCE - NSA Program to detect threats in cyberspace (2005- )
TURMOIL - Part of the TURBULENCE program
TUSKATTIRE - DNR (telephony) ingest processor
TUTELAGE - Part of the TURBULENCE program
• U
• UMBRA - Retired compartment for the most sensitive COMINT material
UNIFORM - SIGINT Exchange Designator for Canada
UPSTREAM -
• V
VAGRANT - computer screens / captures d'écrans
[lemonde.fr](http://www.lemonde.fr/international/article/2013/10/22/la-
diplomatie-francaise-sur-ecoute-aux-etats-unis35007173210.html
VORTEX - Class of SIGINT spy satellites (1978-1989)
• W
WEALTHYCLUSTER - Program to hunt down tips on terrorists in
cyberspace (2002- )
WEBCANDID - NSA tool or database
WHITEBOX -
• X
XCONCORD - Program for finding key words in foreign language
documents
XKEYSCORE (XKS) - Program for analysing SIGINT traffic
• Z
ZARF - Compartment of TALENT KEYHOLE for ELINT satellites
“If everything is terrorism,
then nothing is terrorism,”
- David Gomez, a former senior FBI agent.
2
INSIDER
No more than 22 personnel at NSA
were to have access to the highly
classified data
- Michael Hayden, former director of
the NSA and CIA,
“Does your organization have a way to
detect unauthorized access to your
data?”
“Does your organization uses and
monitors the available
technology”
Summarising Snowden and Snowden as internal threat
Summarising Snowden and Snowden as internal threat

Summarising Snowden and Snowden as internal threat

  • 2.
    Exposed NSA’s evilsnooping Good Guy 1 …for the world
  • 3.
    Exposed internal secrets BAAAADGuy …for his organization 2
  • 4.
  • 5.
  • 6.
    Hammerchant – Spyon VoIP & VPN ANT catalog – Inject surveillance software in Apple cisco dell products WellSpring – Collect images from email based on face recognition DishFire – Collect upto 200million SMS a day NoseySmurf – Smurf in iPhones & Android, turning on mic & track loc Bullrun – NSA & GCHQ effort to weaken cryptography standards/tools ShotGiant – program to break Chinese Huawei networks and products. Upstream – program collects communications transiting the Internet HappyFoot– use cookies & data from phone apps to identify users' devices and physical locations http://projects.propublica.org/nsa-grid/
  • 7.
    Alphabetical list ofNSA Programs and Tools • A AGILITY - NSA internet information tool or database AGILEVIEW - NSA internet information tool or database ALPHA - SIGINT Exchange Designator for Great Britain ANCHORY - NSA software system which provides web access to textual intelligence documents AUTOSOURCE - NSA tool or database AQUACADE - A class of SIGINT spy satellites (formerly RHYOLITE) ASSOCIATION - NSA tool or database • B BANYAN - NSA tool or database BELLTOPPER - NSA database BELLVIEW - BINOCULAR - Former NSA intelligence dissemination tool BLACKPEARL - NSA tool or database BLARNEY - NSA internet and telephony network collection program BOUNDLESS INFORMANT - DNI and DNR data visualization tool. BULLRUN BYEMAN (BYE) - Retired control system for overhead collection systems (1961-2005)
  • 8.
    • C CADENCE -NSA collection tasking tool or database CANYON - Class of COMINT spy satellites (1968-1977) CANNON LIGHT - Counterintelligence database of the US Army CHESS- Compartment of TALENT KEYHOLE for the U-2 spy plane CONFIRM - NSA database for personell access CONTRAOCTAVE - NSA tool or database CONVEYANCE - A voice content ingest processor? / Provide filtering for PRISM. CORONA - A series of photographic surveillance satellites (1959-1972) COURIERSKILL - NSA Collection mission system CREST - Database which automatically translates foreign language intercepts in English CRYPTO ENABLED - collection derived from AO's efforts to enable crypto (cf. lemonde.fr) CULTWEAVE - Smaller size SIGINT database * • D DANCINGOASIS - (?) DELTA - Compartment for COMINT material from intercepts of Soviet military operations DIKTER - SIGINT Exchange Designator for Norway DINAR - Predecessor of the UMBRA compartment for COMINT DISHFIRE - NSA internet information tool or database DROPMIRE - passive collection of emanations using an antenna DRTBOX - DRUID - SIGINT Exchange Designator for third party countries DYNAMO - SIGINT Exchange Designator for Denmark
  • 9.
    • E ECHELON -A SIGINT collection network run by Australia, Canada, New Zealand, the United Kingdom, and the United States, ECHO - SIGINT Exchange Designator for Australia EVILOLIVE - • F FAIRVIEW - NSA internet and telephony network collection program FALLOUT - DNI metadata ingest processor / Provides filtering for PRISM. FISHBOWL - NSA program for securing commercial smartphones FOREMAN - ? FOXACID - target the TOR's users • G GMMA (G) - Compartment for highly sensitive communication intercepts GAMUT - NSA collection tasking tool or database GENIE - implants of spywares GENTE - multi-stage opetation; jumping the airgap etc. (lemonde.fr - GLOBAL BROKER - NSA tool or database
  • 10.
    • H HAVE BLUE- Development program of the F-117A Stealth fighter- bomber HAVE QUICK (HQ) - Frequency-hopping system used to protect military UHF radio traffic HERCULES - CIA terrorism database HIGHTIDE - NSA tool or database HIGHLANDS - spywares implants • I INDIA - SIGINT Exchange Designator for New Zealand INTRUDER - Series of ELINT and COMINT spy satellites (since 2009) ISHTAR - SIGINT Exchange Designator for Japan IVY BELLS - NSA, CIA and Navy operation to place wire taps on Soviet underwater communication cables • J JEROBOAM - Another name used for the TRUMPET spy satellites JUGGERNAUT - Picks up all signals from mobile networks JUMPSEAT - Class of SIGINT reconnaissance satellites (1971-1983) • K KLONDIKE (KDK) - Control system for sensitive geospatial intelligence
  • 11.
    • L • LIFESAVER- imaging of the hard driver (from lemonde.fr LITHIUM - ? LOPERS - Software application for Public Switched Telephone Networks • M MAGIC LANTERN - A keystroke logging software developed by the FBI MAGNETIC - sensor collection of magnetic emanations (lemonde.fr) MAGNUM - Series of SIGINT spy satellites (since 1985) MAILORDER - MAIN CORE - Federal database of personal and financial data of suspicious US citizens MAINWAY - NSA database of bulk phone metadata (Call records DB) MARINA - NSA database of bulk internet metadata (Internet records DB) MENTOR - Class of SIGINT spy satellites (since 1995) MESSIAH - NSA automated message handling system METTLESOME - NSA Collection mission system MINARET - A sister project to Project SHAMROCK (1967-1973) MINERALIZE - collection from LAN implant (lemonde.fr MOONLIGHTPATH - An NSA collection program MORAY - Retired compartment for the least sensitive COMINT material • N NUCLEON - Database for contents of phone calls (Voice data DB)
  • 12.
    • O OAKSTAR -NSA internet and telephony network collection program, voir aussi "2013 mass surveillance disclosures". OCEAN - (?) from lemonde.fr. OCEANARIUM - Database for SIGINT from NSA and intelligence sharing partners around the world. OCELOT - Probably a NSA program for collection from internet and telephony networks OCTAVE - NSA tool for telephone network tasking OCTSKYWARD - NSA tool or database OSCAR - SIGINT Exchange Designator for the USA • P PATHFINDER - SIGINT analysis tool (made by SAIC) PINWALE - Database for recorded signals intercepts/internet content (Video data DB) PLUS - NSA SIGINT production feedback program * PRISM - NSA collection program for foreign internet data PROTON - Smaller size SIGINT database PURPLE - Codename for a Japanese diplomatic cryptosystem during WWII PUZZLECUBE - NSA tool or database • Q QUANTUM - see FOXACID - target the TOR's users,
  • 13.
    • R RADON -host tap than can inject Ethernet packets onto the same target - exploitation of denied networks (cf. lemonde.fr) • RAGTIME (RT) - Codeword for four NSA surveillance programs (Ragtime-A, B, C et P). RAMPART / RAMPART-T - penetration of hard targets at or near leadership level RENOIR - NSA telephone network visualization tool RESERVE (RSV) - Control system for the National Reconnaissance Office (NRO) RICHTER - SIGINT Exchange Designator for Germany RUFF - Compartment of TALENT KEYHOLE for IMINT satellites RHYOLITE - Class of SIGINT spy satellites (in 1975 changed to AQUACADE) • S • SABRE - Retired(?) SIGINT product codeword SAVILLE - Narrow band voice encryption used for radio and telephone communication SCISSOR SCORPIOFORE - SHARKFIN - Sweeps up all-source communications intelligence at high speed and volumes SEMESTER - NSA SIGINT reporting tool SENTINEL - NSA database security filter SETTEE- SIGINT Exchange Designator for South Korea
  • 14.
    • SHAMROCK -Operation for intercepting telegraphic data going in or out the US (1945-1975) SHELLTRUMPET - NSA metadata processing program SILKWORTH - A software program used for the ECHELON system SIRE - A software program used for the ECHELON system SKYWRITER - NSA internet intelligence reporting tool SOLIS - SIGINT product databases SPHINX - Counterintelligence database of the Defense Intelligence Agency SPINNERET - an NSA operational branche? SPOKE - Retired compartment for less sensitive COMINT material STELLARWIND (STLW) - SCI compartment for the President's Surveillance Program information STONE GHOST - DIA classified network for information exchange with UK, Canada and Australia STORMBREW - NSA internet and telephony network collection program STUMPCURSOR - Foreign computer accessing program of the NSA's Tailored Access Operations
  • 15.
    • T • TALENTKEYHOLE (TK) - Control system for space-based collection platforms TALK QUICK - An interim secure voice system created to satisfy urgent requirements imposed by conditions to Southeast Asia. Function was absorbed by AUTOSEVOCOM TAPERLAY - covername for Global Numbering Data Base (GNDB)? TAROTCARD - NSA tool or database TEMPEST - Investigations and studies of compromising electronic emanations THINTREAD - NSA program for wiretapping and sophisticated analysis of the resulting data TRAFFICTHIEF - Part of the TURBULENCE and the PRISM programs TRAILBLAZER - NSA Program to analyze data carried on communications networks TREASUREMAP - NSA internet content visualization tool TRIBUTARY - NSA provided voice threat warning network TRINE - Predecessor of the UMBRA compartment for COMINT TRUMPET - Series of ELINT reconnaissance satellites (1994-2008) TUNINGFORK - NSA tool or database TURBULENCE - NSA Program to detect threats in cyberspace (2005- ) TURMOIL - Part of the TURBULENCE program TUSKATTIRE - DNR (telephony) ingest processor TUTELAGE - Part of the TURBULENCE program
  • 16.
    • U • UMBRA- Retired compartment for the most sensitive COMINT material UNIFORM - SIGINT Exchange Designator for Canada UPSTREAM - • V VAGRANT - computer screens / captures d'écrans [lemonde.fr](http://www.lemonde.fr/international/article/2013/10/22/la- diplomatie-francaise-sur-ecoute-aux-etats-unis35007173210.html VORTEX - Class of SIGINT spy satellites (1978-1989) • W WEALTHYCLUSTER - Program to hunt down tips on terrorists in cyberspace (2002- ) WEBCANDID - NSA tool or database WHITEBOX - • X XCONCORD - Program for finding key words in foreign language documents XKEYSCORE (XKS) - Program for analysing SIGINT traffic • Z ZARF - Compartment of TALENT KEYHOLE for ELINT satellites
  • 18.
    “If everything isterrorism, then nothing is terrorism,” - David Gomez, a former senior FBI agent.
  • 19.
  • 20.
    No more than22 personnel at NSA were to have access to the highly classified data - Michael Hayden, former director of the NSA and CIA,
  • 21.
    “Does your organizationhave a way to detect unauthorized access to your data?”
  • 22.
    “Does your organizationuses and monitors the available technology”

Editor's Notes

  • #7 GCHQ – global comm HQ Canada Sweden
  • #18 Obama has boosted the number of people on the no fly list more than ten-fold, to an all-time high of 47,000
  • #20 Snowden was a contract staff