Interesting Search Tool: Tumbex

December 13, 2022

Interest in Open Source Intelligence has crossed what I call the Murdoch Wall Street Journal threshold. My MWSJ is that a topic, person, or idea bubbles along for a period of time, in this instance, decades. OSINT was a concept was discussed by a number of people in the 1980s. In fact, one advocate — a former Marine Corps. officer and government professional — organized open source intelligence conferences decades ago. That’s dinobaby history, and I know that few “real news” people remember Robert David Steele or his concepts about open source in general or OSINT in particular. (If you are curious about the history, email the Beyond Search team at benkent2020 @ yahoo dot com. Why? I participated in Mr. Steele’s conferences for many years, and we worked on a number of open source projects for a range of clients until shortly before his death in August 2021.) Yep, history. Sometimes knowing about events can be helpful.

Let’s talk about online information; specifically, an OSINT tool available since 2014 if my memory is working this morning. The tool is called Tumbex. With it, one can search Tumblr content.

image

Here’s what the Web site says:

Tumbex indexes only tumblr posts which have caption or tags. We analyse the content and define if tumblr or posts are nsfw/adult. If your tumblr was detected as nsfw by mistake, you can request a review and we will manually check your tumblr.

This is interesting. However, with a bit of query testing one can find some quite sporty content on the service.

The service, allegedly became available in 2014, is hosted by the French outfit OVH. According to StatShow, Tumbex has experienced a jump in traffic. The site is not particularly low profile because it has a user base of an estimated one million humans or bots. (Please, keep in mind that click data are often highly suspect regardless of source.) FYI: StatShow can be a useful OSINT resource as well.

If you are interested in some of the OSINT resources my team relies upon, navigate to www.osintfix.com. Click the image and a new window will open with an OSINT resource displayed. No ads, no trackers, no editorial. Just an old fashioned 1994 Web site which can be used fill an idle moment.

Now that the MWSJ threshold has been crossed, OSINT is a thing, an almost-overnight success with some youthful experts emphasizing that the US government has been asleep at the switch. I am not sure that assessment is one I can fully support.

Stephen E Arnold, December 13, 2022

Don Quixote Rides Again: Instead of Windmills, the Target Is Official and True Government Documents

December 8, 2022

I read “Archiving Official Documents as an Act of Radical Journalism.” The main idea is that a non governmental entity will collect official and “true” government documents, save them, and make them searchable. Now this is an interesting idea, and it one that most of countries for which I have provided consulting services related to archiving information have solutions. The solutions range from the wild and wooly methods used in the Japanese government to the logical approach implemented in Sweden. There’s a carnival atmosphere in Brazil, and there is a fairly interesting method in Croatia. France? Mais oui.

In each of these countries, one has to have quite specific know how in order to obtain an official and true government document. I know from experience that a person not a resident of some of these countries has pretty much zero chance of getting a public transcript of public hearing. In some cases, even with appropriate insider assistance, finding the documents is often impossible. Sure, the documents are “there.” But due to budget constraints, lousy technology, or staff procedures — not a chance. The Vatican Library has a number of little discussed incidents where pages from old books get chopped out of a priceless volume. Where are those pages now? Hey, where’s that hymn book from the 14th century?

I want you to notice that I did not mention the US. In America we have what some might call “let many flowers bloom” methods. You might think the Library of Congress has government documents. Yeah, sort of, well, some. Keep in mind that the US Senate has documents as does the House. Where are the working drafts of a bill? Try chasing that one down, assuming you have connections and appropriate documentation to poke around. Who has the photos of government nuclear facilities from the 1950. I know where they used to be in the “old” building in Germantown, Maryland. I even know how to run the wonky vertical lift to look in the cardboard boxes. Now? You have to be kidding. What about the public documents from Health and Human Services related to MIC, RAC, and ZPIC? Oh, you haven’t heard about these? Good luck finding them. I could work through every US government agency in which I have worked and provide what I think are fun examples of official government documents that are often quite, quite, quite difficult to locate.

The write up explains its idea which puts a windmill in the targeting device:

Democracy’s Library, a new project of the Internet Archive that launched last month, has begun collecting the world’s government publications into a single, permanent, searchable online repository, so that everyone—journalists, authors, academics, and interested citizens—will always be able to find, read, and use them. It’s a very fundamental form of journalism.

I am not sure the idea is a good one. In some countries, collecting government documents could become what I would characterize as a “problem.” What type of problem? How about fine, jail time, or unpleasantness that can follow you around like Shakespeare’s spaniels at your heels.

Several observations:

  1. Public official government documents change, they disappear, and they become non public without warning. An archive of public government documents will become quite a management challenge when classification changes, regimes change, and when government bureaucracy changes course. Chase down a US government repository librarian at a US government repository library near you and ask some questions. Let me know how that works out when you bring up some of the administrative issues for documents in a collection.
  2. A collection of official and true documents which tries to be comprehensive from a single country is going to be radioactive. Searchable information is problematic. That’s why enterprise search vendors who say, “All the information in your organization is searchable” evokes statements like “Get this outfit out of my office.” Some data is harmless when isolated. Pile data and information together and the stuff can go critical.
  3. Electronic official and true government documents are often inaccessible. Examples range from public information stored in Lotus Notes which is not the world’s best document system in my opinion to PowerPoint reports prepared for a public conference about the US Army’s Distributed Common Ground Information System. Now try to get the public document and you may find that what was okay for a small fish conference in Tyson’s Corner is going to evoke some interesting responses as the requests buck up the line.
  4. Collecting and piling up official and true information sounds good … to some. Others may view the effort with some skepticism because public government information is essentially infinite. Once collected those data may never go away. Never is a long time. How about those FOIA requests?

What’s the fix? Answer: Don Quixote became an icon for a reason, and it was not just elegant Spanish prose.

Stephen E Arnold, December 2022

Small Snowden Item: Not Rooting for US Soccer Team?

December 6, 2022

I think the answer to the question, “Is Edward Snowden rooting for the US soccer team?” is no. I read “Edward Snowden Swears Allegiance to Russia and Receives Passport, Lawyer Says”. [Note: In the spirit of capitalism, you will have to pay to view the original story.] The Bezos affiliated real news outfit said:

It’s unclear whether Snowden swore the oath of allegiance at the same time as he was granted a passport, but the two are common procedures when foreigners become Russian citizens. The text includes swearing “to protect the freedom and independence of the Russian Federation, to be loyal to Russia, to respect its culture, history and traditions,” and to promise to “perform the duties of a citizen of the Russian Federation for the good of the state and society.” Kucherena [The estimable Mr. Snowden’s legal eagle] added that Snowden’s wife, Lindsay Mills, was also undergoing the Russian citizenship application process and that the couple’s children would likely attend Russian schools, when ready.

Interesting. I assume information will surface about the forthcoming Russian film “Dinner with Vlad” starring the bold, brave bag man Mr. Snowden and the somewhat weighty Mr. Segal. The plot is, as I understand it, Vlad asks his guests about Russia’s most appealing aspect. Mr. Snowden says, “It’s the great Internet connections”, and Mr. Seagal says, “It the food.” The three stars drink Russian vodka and engage in an arm wrestling competition. Vlad wins and the three drooks head to a cover band featuring Pussy Riot tunes. Mr. Snowden and Mr. Seagal give inspired lectures during the band’s break. Males in the audience are enlisted. Females? Well, fade to black.

Stephen E Arnold, December 6, 2022

TikTok: Back in the Surveillance Spotlight?

December 6, 2022

In western countries, especially the United States, TikTok is a platform showcasing the worst of its citizens. It also encourages poor behavior due to mob mentality/crowd psychology. Did you know that China owns TikTok and uses it to collect data on US citizens? It is probably manipulating algorithms to show Americans the worst of the worst as well. The FBI is finally catching on that TikTok is not a benign social media platform, but it is probably too little too late.

CNBC wrote that, “FBI Is ‘Extremely Concerned’ About China’s Influence Through TikTok On US Users.” FBI Director Christopher Wray warned US lawmakers about the potential threat TikTok poses:

“ ‘We do have national security concerns at least from the FBI’s end about TikTok,’ Wray told members of the House Homeland Security Committee in a hearing about worldwide threats. ‘They include the possibility that the Chinese government could use it to control data collection on millions of users. Or control the recommendation algorithm, which could be used for influence operations if they so chose. Or to control software on millions of devices, which gives it opportunity to potentially technically compromise personal devices.’”

TikTok’s parent company ByteDance denies any bad actions and condemns anyone who claims TikTok is anything more than a short video-sharing platform. The Hill has a similar take on the same story “FBI Head: China Has ‘Stolen More’ US Data ‘Than Every Other Nation Combined’” and uses the same quote from Wray but includes an additional one:

“There are still unresolved questions about data sharing between Chinese companies and the government in Beijing, said Wray, adding that ‘there’s a number of concerns there as to what is actually happening and actually being done.’”

What is interesting about China is that it is one of the world’s oldest countries and its cultural mentality is different from than the West. China could be patiently playing the long game to subvert the US government with the help of its citizens. How? They systemically use TikTok to condition Americans’ attention spans to be shorter and influence bad behavior.

Why is the FBI only concerned now?

Whitney Grace, December 6, 2022

Blue Chip Consulting: An Interesting Question with a Painfully Obvious Answer

November 30, 2022

I read “Why Is Booz Allen Renting Us Back Our Own National Parks?” The author is asking a BIG question with what may be a tiny answer.

The essay states:

Today I’m writing about how the giant government contracting firm Booz Allen and 13 government agencies have been renting back to the public access to our own lands by forcing us to pay junk fees to use national parks.

The essay runs through some historical information about land. Interesting, but I tuned that type of information when I had to take a class in US history as a freshman at the third-rate outfit which accepted me as a student. Sure, the professor became a US congress person and had influence. But the lectures about land, Henry Clay, and Manifest Destiny did not compute. (In 1962 I was trying to figure out how to get an IBM computer to accept a program to index Latin sermons. Land was a fungible, and I was and remain on the intangible side of life.)

A US government Web site becomes a point of reference in the essay. Now you may think that US government Web sites are no big deal. Rest assured that in preparing annual budgets, Web sites are indeed a big deal. Did you know that US national laboratories want traffic because click data let’s some labs say to a Congressional committee: “We are pulling in eyeballs because our research is Number One with a bullet.” Believe me. Some people’s jobs depend on getting an elected official to see Web traffic as germane to pulse weapon funding or more esoteric activities.

The Web site referenced is not involved in nuclear research information. Recreation.gov becomes a way for a government agency to demonstrate that it is [a] serving citizens, [b] demonstrating that it is operating as a business, not a service organization, and [c] in step with hip digital trends. The write up points out that my former employer Booz Allen does a great deal of business with the Federal sector. The write up points out that Booz Allen has been involved in interesting and often big dollar projects. Some of these projects are so-so; others not so so-so; and a number of them are home runs. Booz Allen is an organization of hitters, not sitters.

I noted this passage in the write up:

In 2017, Booz Allen got a 10-year $182 million contract to consolidate all booking for public lands and waters, with 13 separate agencies participating, from the Bureau of Land Management to the National Oceanic & Atmospheric Administration to the National Park Service to the Smithsonian Institution to the Tennessee Valley Authority to the US Forest Service. The funding structure of the site is exactly what George Washington Plunkitt would design. Though there’s a ten year contract with significant financial outlays, Booz Allen says the project was built “at no cost to the federal government.” In the contractor’s words, “the unique contractual agreement is a transaction-based fee model that lets the government and Booz Allen share in risk, reward, results, and impact.” In other words, Booz Allen gets to keep the fees charged to users who want access to national parks. Part of the deal was that Booz Allen would get the right to negotiate fees to third party sites that want access to data on Federal lands.

Then the essay notes:

Yes, Booz Allen gets to steal some pennies, but we have a remarkable system of public lands and waters that are broadly available for all of us to use on a relatively equal basis. And we can still see the power of George-ism in the advocacy of hikers and in the intense view that members of Congress had when they passed the Federal Lands Recreation Enhancement Act in 2004, which strictly regulated fees that Americans would have to pay to access our Federal lands.

Then the essay includes a statement which baffles me:

We are in a moment of institutional corruption, but these moments are transitory as institutions change.

Now let’s answer the question, “Why is Booz Allen renting us back our own national parks?”

My answer is my personal opinion, and you may choose to disagree:

  1. Government professionals directly or indirectly created a statement of work designed to help a unit of a government agency meet its annual objectives; for instance, cost recovery so citizens benefit without the agency spending government money. Remember that Booz Allen gets paid to create a fee generation system which pays Booz Allen and makes users of Recreation.gov really happy. At the same time, the agency officials get credit for a job well done and possibly some power or money related benefit.
  2. Booz Allen (in its present form) was shaped in the mid 1970s specifically to capture government contracts of any type. The purpose of the capture is to generate fee based revenue from professional services and in some cases by creating a fungible thing like a cartridge ejection mechanism. The object is to bill in accordance with the tasks set forth in the statement of work and implement applicable scope changes in order to respond to the client agency’s needs.
  3. The projects — whether Recreation.gov, the structure of the US Department of Navy, or providing inputs to space warfare analysts — give the professionals working in US government agencies a wide range of interesting work tasks. These tasks include, but are not limited to, attending meetings, meeting with sub-contractors, coordinating with other government entities, and in the case of national park projects, a field trip, maybe many field trips.

Thus, the answer to the question is that Booz Allen does not rent back national parks. Booz Allen plus a small number other blue chip consulting firms create work for Federal employees and for those paid directly by Booz Allen. Think of Booz Allen as the engine room of the government machine.

The march through history, the precedents for land use, and the other History 121 topics are completely irrelevant to making an essentially unmanageable and functionally impaired national park system appear to work reasonably well.

I would ask the author of the essay: What would be a better method? Would it be possible to find an optimally performing government agency and transport those systems and methods to those entities involved in Recreation.gov? How about using the Internal Revenue Service as a model? What if one snags the Social Security Agency or Health and Human Services as a model? We can jump branches and emulate the Senate sergeant at arm’s management methods? Do any of these provide a model?

To answer these questions my thought is that some government agencies will hire either Booz Allen or a similar firm.

Why? Booz Allen can do work, give government professionals tasks to complete, and send invoices.

The BIG question has a small, simple answer. Plus one can reserve a space for vanlifers whose rides conform to the National Park guidelines. That’s a deliverable.

Stephen E Arnold, November 30, 2022

France and US Businesses: Semi Permanent Immiscibility?

November 30, 2022

Unlike a pendulum, the French government and two US high-technology poster kids don’t see eye to eye. However, governments, particularly those in France, are not impressed with the business practices of some US firms. The tried and true “Senator, thank you for the question” and assurances that the companies in questions are following the ethical precepts of respected French philosophers don’t work. “France Directs Schools to Stop Using Microsoft Office & Google Workspace” reports:

In a recent response to an interrogation by a Member of the Parliament, the French Minister of Education clarified that French schools should not use Microsoft 365 and Google Workspace. The reasons behind the Ministry’s position are twofold. First, the Ministry is concerned about the confidentiality and lawfulness of data transfers. Second, reliance on European providers is coherent with the government’s “cloud at the center” policy.

The write up explains that France’s view of privacy and the practices of Apple and Google are not in sync. Then there is the issue of the cloud and where data and information “are.” Given modern network and data center technology, the “there” is often quite tricky to pin down. Tricky is not a word the current French government feels comfortable using when talking about schools, teachers, students, and research conducted by French universities.

How will this play out? France will get its way. That’s why some chickens have labels which mean conformance. No label on that chicken, no deal.

Stephen E Arnold, November 30, 2022

The Collision of Nation State Bias and High School Science Club Management

November 28, 2022

CNN offered some interesting pictures of the labor management misunderstanding in Zhengzhou, China. Even though I have been to China several times, I was not sure what made Zengzhou different from other “informed” cities struggling with what may be an ill-advised approach to Covid. In fact, the images of law enforcement and disgruntled individuals are not particularly unique. These images are more interesting when a blurry background of Apple and a Taiwanese company add a touch of chiaroscuro to the scenes.

What is interesting is that “Apple Has a Huge Problem with an iPhone Factory in China” mentions the “Taiwan contract manufacturing firm Foxconn.” CNN, however, does not offer any information about the involvement of individuals who want to create issues for Foxconn. China and Taiwan sort of coexist, but I am not certain that the Chinese provincial government either in Henan or the national government in Beijing are particularly concerned about what happens to either Apple of Foxconn.

The fact that workers suddenly became upset suggests that I have to exercise a willing suspension of disbelief and assume the dust up was spontaneous. Sorry, a “Hey, this just happened because of pay” or some similar dismissive comment won’t make me feel warm and fuzzy.

The write up asserts:

The Zhengzhou campus has been grappling with a Covid outbreak since mid-October that caused panic among its workers. Videos of people leaving Zhengzhou on foot went viral on Chinese social media in early November, forcing Foxconn to step up measures to get its staff back….  But on Tuesday [November 22, 2022] night, hundreds of workers, mostly new hires, began to protest against the terms of the payment packages offered to them and also about their living conditions. Scenes turned increasingly violent into the next day as workers clashed with a large number of security forces. By Wednesday [November 23] evening, the crowds had quieted, with protesters returning to their dormitories on the Foxconn campus after the company offered to pay the newly recruited workers 10,000 yuan ($1,400), or roughly two months of wages, to quit and leave the site altogether.

Seems straightforward. A  confluence of issues culminated in a protest.

Now let’s think about the issue this way. These are my working hypotheses.

First, Foxconn may not perceive the complaints of its employees as important. Sure, the factory workers have to do their job, but these are Chinese factory workers. Foxconn has a Taiwan spin. This may translate into Chinese government passivity. Let the Taiwan managers deal with the problems.

Second, Apple is a US outfit and it embraces some of the tenets of the high school science club management method. The kernel of the HSSCMM is that science club members know best. Others do not; therefore, if something is not on the radar of the science club, that “something” is irrelevant, silly, or just plain annoying.

Third, the workers have some awareness of the financial resources of Foxconn and Apple. Thus, like workers from an Apple store to the quiet halls of the Apple core spaceship, money talks.

Fourth, Covid. Yep, not going away it seems.

What happens when China is not too interested in Foxconn, Foxconn is not too interested in Chinese workers, and Apple is busy inventing ways to prevent people from upgrading the Mac computers?

That’s what CNN understands. Protests, clashes, and violence. Toss in some Covid fear and one has the exciting story for consumers of CNN “real” news.

Is there are fix? For China and its attitude to Taiwanese businesses which allegedly exploit Chinese workers, sure. I won’t explore that solution. For Foxconn, sure, but it will take time for Foxconn to de-China its production operations. For Apple, not really. The company will follow the logic of the science club: Find some people who will work for less.

Net net: Apple and its HSSCMM will probably not find too many fans in the Middle Kingdom. And Foxconn? Do China and Apple care?  Apple cares about money. China cares about the Middle Kingdom. Foxconn cares about what? Building plants in the US… soon?

Stephen E Arnold, November 28, 2022

Cyber Security? That Is a Good Question

November 25, 2022

This is not ideal. We learn from Yahoo Finance, “Russian Software Disguised as American Finds Its Way into U.S. Army, CDC Apps.” Reuters journalists James Pearson and Marisa Taylor report:

“Thousands of smartphone applications in Apple and Google’s online stores contain computer code developed by a technology company, Pushwoosh, that presents itself as based in the United States, but is actually Russian, Reuters has found. The Centers for Disease Control and Prevention (CDC), the United States’ main agency for fighting major health threats, said it had been deceived into believing Pushwoosh was based in the U.S. capital. After learning about its Russian roots from Reuters, it removed Pushwoosh software from seven public-facing apps, citing security concerns. The U.S. Army said it had removed an app containing Pushwoosh code in March because of the same concerns. That app was used by soldiers at one of the country’s main combat training bases. According to company documents publicly filed in Russia and reviewed by Reuters, Pushwoosh is headquartered in the Siberian town of Novosibirsk, where it is registered as a software company that also carries out data processing. … Pushwoosh is registered with the Russian government to pay taxes in Russia. On social media and in U.S. regulatory filings, however, it presents itself as a U.S. company, based at various times in California, Maryland and Washington, D.C., Reuters found.”

Pushwoosh’s software was included in the CDC’s main app and that share information on health concerns, including STDs. The Army had used the software in an information portal at, perhaps among other places, its National Training Center in California. Any data breach there could potentially reveal upcoming troop movements. Great. To be clear, there is no evidence data has been compromised. However, we do know Russia has a pesky habit of seizing any data it fancies from companies based within its borders.

Other entities apparently duped by Pushwoosh include the NRA, Britain’s Labor Party, large companies like Unilever, and makers of many items on Apple’s and Google’s app stores. The article includes details on how the company made it look like it was based in the US and states the FTC has the authority to prosecute those who engage in such deceptive practices. Whether it plans to bring charges is yet to be seen.

Cynthia Murrell, November 25, 2022

Are Governments Behaving Like Sheep?

November 24, 2022

North Korea, China, and possibly Russia are incarnates of Orwell’s Big Brother from the dystopian 1984 novel. The US government is compared to Big Brother (and rightly so) when it attempts to block free speech. The thing about outlawing free speech is that it takes too much energy to regulate. The US government wants to limit free speech, but only when it feels like it. We also do not want that, because the government lies. Gizmodo explains why we do not want the government to be Big Brother in: “You Really Don’t Want The Government To Be Your Content Moderator.”

The Department of Homeland Security is collaborating with tech firms and large businesses to repackage Bush’s “War on Terror” into a new product. They are building tools to monitor social media and combat disinformation. Why did this happen?

“In April, the Biden administration announced the launch of a Disinformation Governance Board, a new unit within DHS meant to “standardize the [government’s] treatment of disinformation” across various agencies. But the project was fumbled from the start: the unit initially failed to release a charter, leaving Americans to wonder just what exactly this shadowy new group with a creepy name was going to be doing. It didn’t take long for critics—on both the political left and right—to start referring to it as a “Ministry of Truth,” (the notorious propaganda bureau from George Orwell’s 1984). Though officials tried to salvage the effort. DHS shuttered the board in May after it had been operational for less than a month.”

Biden’s administration continued the Orwellian acts with a new organization: Cybersecurity and Infrastructure Security (CISA). Big businesses such as JPMorgan Chase and Twitter are working with the FBI and CISA to approach state-sponsored disinformation campaigns. The US government also wants to address COVID-19 vaccine efficacy, US support of Ukraine, Afghanistan withdrawal, and racial justice.

Is the US government is not an impartial entity despite what politicians claim?

Whitney Grace, November 24, 2022

From Our Pipe Dream Department: Harmful AI Must Pay Victims!

October 28, 2022

It looks like the European Commission is taking the potential for algorithms to cause harm seriously. The Register reports, “Europe Just Might Make it Easier for People to Sue for Damage Caused by AI Tech.”  Vice-president for values and transparency V?ra Jourová frames the measure as a way to foster trust in AI technologies. Apparently EU officials believe technical innovation is helped when the public knows appropriate guardrails are in place. What an interesting perspective. Writer Katyanna Quach describes:

“The proposed AI Liability Directive aims to do a few things. One main goal is updating product liability laws so that they effectively cover machine-learning systems and lower the burden-of-proof for a compensation claimant. This ought to make it easier for people to claim compensation, provided they can prove damage was done and that it’s likely a trained model was to blame. This means someone could, for instance, claim compensation if they believe they’ve been discriminated against by AI-powered recruitment software. The directive opens the door to claims for compensation following privacy blunders and damage caused by poor safety in the context of an AI system gone wrong. Another main aim is to give people the right to demand from organizations details of their use of artificial intelligence to aid compensation claims. That said, businesses can provide proof that no harm was done by an AI and can argue against giving away sensitive information, such as trade secrets. The directive is also supposed to give companies a clear understanding and guarantee of what the rules around AI liability are.”

Officials hope such clarity will encourage developers to move forward with AI technologies without the fear of being blindsided by unforeseen allegations. Another goal is to build the current patchwork of AI standards and legislation across Europe into a cohesive set of rules. Commissioner for Justice Didier Reynders declares citizen protection top priority, stating, “technologies like drones or delivery services operated by AI can only work when consumers feel safe and protected.” Really? I’d like to see US officials tell that to Amazon.

Cynthia Murrell, October 28, 2022

« Previous PageNext Page »

  • Archives

  • Recent Posts

  • Meta