Follow Intelligence? Watch the National Geospatial-Intelligence Agency

April 12, 2019

I read “Is Geospatial Intel the New Framework for Civilization? The NGA’s New Director Speaks His Mind.” The article contains several points which DarkCyber has identified as important. Are you into geo-fencing? If not, you may want to learn a bit more about this function.

Stephen E Arnold, April 12, 2019

Silos Persist: GAO Analysis of DHS Asserts

March 23, 2019

Government reports are often filled with useful information. Some reports can be difficult to locate. A good example is GAP-19-210 “Homeland Security: Research & Development Coordination Has Improved, but Additional Actions Need to Track and Evaluate Project.” This report is online as of March 23, 2019, at this link: In order to obtain a copy, right click on the link and download the PDF. Rendering of the document in a browser is not reliable.

I think this findability issue provides a good example of the information sharing issues discussed in the 59 page report.

If you are interested in the structure of DHS, the report contains several current organization charts.

The information about the technologies in use for border control is one of the first lists of this type which I have seen recently. You can find these data in Appendix I: Overview of the Science Technology Directorate’s Research and Development Projects on pages 48 and following.

This is a useful document because future procurements are hinted at.

A quick heads up. If you look for the document at, the document does not appear on the public facing Web site yet. Experimenting with the different options for locating public information, one selector returned a list of DHS related reports with the most recent document dated 2014.

Stephen E Arnold, March 23, 2019

Cellebrite Products on eBay?

March 8, 2019

Quite an assertion appeared in “Cellebrite’s phone Hacking Tools Going Cheaply on eBay, Many Still Contain Unwiped Data.”

Cellebrite, a unit of Japan’s Sun Corporation, offers specialized services and hardware to law enforcement agencies worldwide. Like other cyber security and policeware vendors, Cellebrite is a secretive company.

Prices much lower than Cellebrite’s. Cellebrite, it appears, may have need to revisit its product resale guidelines for its customers. More information about Cellebrite can be found on the company’s Web site.

Stephen E Arnold, March 8, 2019

Amazon Policeware Links

March 5, 2019

DarkCyber received a request for the four short Amazon policeware videos we created in late 2018. Here are the links:

October 30, 2018

November 6, 2018

November 13, 2018

November 20, 2018

Kenny Toth, March 5, 2019

Facebook and Digital Money

March 4, 2019

Digital currency like Bitcoin is often associated with cyber crime. Rightly or wrongly, Bitcoin evokes images of Dark Web markets selling drugs, an association reinforced by the Silk Road bust.

Facebook, on the other hand, evokes smiles from grandmothers, but a UK investigative body characterized Facebook is more negative terms. My recollection is that the British government sees Facebook as an example of Wild West capitalism which intentionally or unintentionally enables outfits like the now defunct Cambridge Analytica.

I thought about these associations when I worked my way through “Regarding Facebook’s Cryptocurerncy.” The write up asserted:

just because Facebook launches a stablecoin cryptocurrency for peer-to-peer payments doesn’t mean people will actually use it.

Facebook’s possible angle is getting money. The write up points out:

Remittances are the obvious target market here. And it would be huge, and important, and wonderful, if Facebook were to make remittances 10x cheaper and faster … but that would require much more than fast international stablecoin transfers, because, again, those stablecoins are not legal tender at their destination, and I don’t know if you’ve noticed but businesses tend to have this whole thing about receiving legal tender.

The fix is for Facebook to find ways to get organizations to accept Facecoins.

The other angle is:

for Facebook to establish relationships with cryptocurrency exchanges worldwide, or — even more dramatically — become or sponsor exchanges themselves.

The write up is interesting, but it left me with several questions zipping through my admittedly limited brain:

  1. How could bad actors make use of Facecoin?
  2. Will Facebook provide these digital currency data to government authorities?
  3. What third party services will Facebook enable through an existing or new API?
  4. What audit mechanisms are in place?
  5. What if Facebook’s presumed digital currency is used for illegal activities?

I would suggest that when digital currency becomes part of an organization which the British government views in a less than positive manner, regulatory authorities may be sitting on the sidelines.

Stephen E Arnold, March 4, 2019

Fortnite: A LE and Intel Gold Mine

January 21, 2019

Fortnite is not something that old folks like me spend much effort understanding. That might be a problem if you are over 35 and engaged in enforcement activities.

Next Friday (January 25, 2019), I will giving a lecture to computer science students at one of Kentucky’s more interesting universities. I won’t define “interesting.” There is a reception with yummy university snacks, and I do not want to be dis-invited.

I have to mention the new mechanisms bad actors use to evade surveillance. One of the handy dandy tools is a game. Yep, Fortnite. That’s the game you probably don’t think about.

Consider these data points from one of my go to, real news, frightened of acquisition sources, USA Today:

  • One in five parents find it “moderately difficult” to get their progeny to stop playing
  • 27 percent of teens play Fortnite when in school classes
  • 50 percent of the teens in the survey use Fortnite to “keep up” with their friends
  • 44 percent have made a “friend” online within the game
  • 47 percent of teen girls play as well
  • 61 percent of teens have played.

Ah, the digital cocktail: Chat, in game money which can be used for money laundering, audio, an opportunity for grooming, learning new dances like the one Athletic Madrid’s Antoine Griezmann does when he scores a goal.


Now this game has made news in a different way.

Newsweek reported that Fortnite data have been compromised. “Fortnite Hack Could Have Accessed Accounts, V-Buck Purchases, & Chat” states:

Fortnite boasts more than 200 million active players, and a recent exploit found by Check Point Software Technologies could have put all of them at risk. The vulnerability, first discovered in November and patched by developers at Epic Games, could have been devastating. If leveraged, it would give third-parties full access to user account details, payment information and even in-game chat audio.

What’s the big deal?

Wherever there are young people, chat, digital currency, and minimal parental understanding, the game may provide:

  • A Petri dish for sexual predators looking for young people to groom
  • A mechanism for exchanging messages about drugs, weapons, and terrorist plans in plain view if one knows how and where to look
  • A conduit for money laundering. My hunch you, gentle reader, may not know how game currencies can be used to convert illegal gains into a hot property which can sell quickly to motivated buyers.

Net net: Fortnite may be more than a game, and it may be time to do more than say, “Put down that game. Come to dinner. Now.”

I will ask the audience on Friday, “Who plays Fortnite?” I will let you know if I learn anything or just get grumbles and blank stares from students and faculty alike.

Stephen E Arnold, January 21, 2019

Dedrone Study Analyzes Drone Activity at UK Airports

January 9, 2019

We wonder if would be bad actors are reading about drones?

A very brief write-up at OodaLoop calls our attention to an interesting study—“2018 Results: Dedrone UK Airport Counter-Drone Study.” By quietly installing monitoring devices at four UK airports,

Dedrone was able to track drone incursions, and deploy counter measures, at those locations. The company shares their results in a detailed blog post, complete with charts, conclusions, and a list of sources for further research. We suggest curious readers check it out. Meanwhile, the OodaLoop piece zeroes in on these takeaways:

“With 285 drones detected over a 148-day period (just under 2 per day), the study concluding with three key learnings and next steps: ‘1. the problem of unauthorized drones at airports is real, not anecdotal: Drones have appeared and disrupted UK airports in the past year, causing loss of revenue due to closed runways. Drone pilots fly a broad spectrum of technology from different drone manufacturers, and detection technology must be able to capture all drone activity: Drone detection systems must be able to detect all kinds of drones, regardless of the manufacturer. While DJI is the global market leader in drone technology by sales, they only represent 44% of the incursions at the airports studied. 3. UK drone pilots come out to fly at airports around the same time and days, and airports can strategically prepare for increased incursions during these period: The majority of the incursions occurred on weekend afternoons when drone hobbyists may be flying drones to capture footage for personal use.’ Finally, it is important to recognize that ‘all drones near airports are a threat, regardless of the pilot’s intentions.’”

Yes, I mentioned Dedrone deployed counter measures at its test airports when incursions were discovered. Though they may seem the most obvious, airports are not the only sites at risk from pesky drones. Dedrone has leapt upon on an emerging need—to secure organizations’ airspace from the increasing risk of drone intrusions. Founded in 2014, the company brought its first solution to market the next year. Based in San Francisco, they also happen to be hiring as of this writing.

Cynthia Murrell, January 9, 2019

Amazonia, January 7, 2019

January 7, 2019

The Bezos bulldozer keeps on pushing through the virgin forest. Crunch, crunch—That’s the sound of the power of the machine creating new revenue streets and highways. Consider these bits of Amazonia:

One of the Five Eyes Is Smiling

One branch of the British government has inked a deal with Amazon to build the “Crown Marketplace.” Think in terms of the British version of GSA/DSA running on Amazon’s AWS infrastructure, buying goodies from Amazon’s warehouses, and getting some of the stuff delivered in nifty Amazon trucks. When will GHCQ follow the CIA’s approach and use Amazon for plumbing? Source: The Telegraph which dearly wants your email address.

GovCloud West: EC2 High Memory Arrives

Most commercial outfits won’t care or understand the steady expansion of the breadth and depth of the GovCloud. Mark your calendar, while some folks were guzzling Champaign, Amazon Amazon EC2 High Memory instances with up to 12 TB of memory to the US GovCloud West region. Source: Amazon itself. Want to know more about “high memory”? Click this link.

FBI Uses Amazon Facial Recognition Service

The policeware landscape is being reshaped by the Bezos bulldozer. Navigate to “FBI Pilot Programme Uses Amazon’s Controversial Facial Recognition Software.” Keep in mind that this write up comes from the ever friendly, always objective Sputnik News. The write up reports:

Sputnik reported that the artificial intelligence behind Rekognition, which can identify, track, and analyze people and recognize up to 100 faces in a single image, was being marketed by Amazon to US police departments for as little as $6 a month. That tiny fee gave law enforcement agencies access to Amazon Web Services (AWS). In turn, Amazon requested that those agencies recommend the brand to their partners, including body camera manufacturers, according to documents obtained by the American Civil Liberties Union (ACLU).

That’s a compelling price point for many law enforcement entities. True or false. Well, the secret region is a thing.

Perception Health Embraces the AWS Marketplace

The Amazon watchers at noted this statement:

Perception Health, a leading provider of healthcare market prediction software, announced today their inclusion on the new machine learning (ML) and artificial intelligence (AI) discovery page on AWS Marketplace.

Why? Bezos’ bulldozer is turning to health. Perception Health wants to dabble in the machine learning marketplace Amazon has built along side its streaming data marketplace. Perception likes the strokes Amazon doles out to its partners. Good partner, the Bezos bulldozer rumbles softly. Source: PRNewswire

Where’s That Blog Belong?

The answer is on AWS. WordPress is a popular blogging platform. WPEngine stated:

WP Engine leverages a modern technology stack to make sure our customers have the resources they need to scale their WordPress environments. It’s why we give our customers access to a suite of developer tools they can use to build great websites, and it’s why we utilize best-in-class technologies like Amazon Web Services (AWS) to add resiliency and speed to our digital experience platform.

Different cheer, same enthusiasm. Source: WPEngine

PHP and Amazon

You know PHP. You want zero hardware to drag down your nights and weekends. You will embrace AWS Lamda. Details are in “Severless PHP on AWS Lambda.” If you want to know more about AWS Lambda, click here. Source: PHPDeveloper

Microservices on Amazon

Screw up one part of a microservice based app and you can have an exciting time of it. But what if one wants to combine the goodness of microservices with the Bezos bulldozer? No problem. Details plus code appear in “How to Deploy a Microservice Application to AWS.” Now about those microservices which don’t “service”? Sparse info, gentle reader.

H2O Analytics Run Better on AWS

Hard to believe that an Amazon partner helps market itself and Amazon with such enthusiasm. Here’s an example of nerd cheerleading:

If you haven’t started migrating your analytics to the cloud, then hopefully this will convince you to start reconsidering. The opportunity to have access to a 64, 96 or even 128 core machines with 2TB of RAM rarely crosses the path of most Data Scientists. This can mostly be accredited to the fact that most of us don’t really need such a large machine for what we need to achieve, see Szilard’s twitter posts if you need convincing. Another reason that we don’t use these big machines are purely because we just don’t have access to such machines within our working environments. Luckily for us, access to cloud computing have become more accessible and well, lets be honest, cheap as chips.

Yep, rah rah. Source: Digital Age Economist (aren’t all economists now alive “digital age economists”?)

Facial Recognition: Not for LE and Intel Professionals? What? Hello, Reality Calling

July 30, 2018

I read “Facial Recognition Gives Police a Powerful New Tracking Tool. It’s Also Raising Alarms.” The write up is one of many pointing out that using technology to spot persons of interest is not a good idea. The Telegraph has a story which suggests that Amazon is having some doubts about its Rekognition facial recognition system. What? Hello, reality calling.

The “Raising Alarms” story makes this statement, obtained from an interview with an outfit called Kairos. I circled these statements:

“Time is winding down but it’s not too late for someone to take a stand and keep this from happening,” said Brian Brackeen, the CEO of the facial recognition firm Kairos, who wants tech firms to join him in keeping the technology out of law enforcement’s hands. Brackeen, who is black, said he has long been troubled by facial recognition algorithms’ struggle to distinguish faces of people with dark skin, and the implications of its use by the government and police. If they do get it, he recently wrote, “there’s simply no way that face recognition software will be not used to harm citizens.”

The write up points out:

Many law enforcement agencies — including the FBI, the Pinellas County Sheriff’s Office in Florida, the Ohio Bureau of Criminal Investigation and several departments in San Diego — have been using those databases for years, typically in static situations — comparing a photo or video still to a database of mug shots or licenses. Maryland’s system was used to identify the suspect who allegedly massacred journalists at the Capital Gazette newspaper last month in Annapolis and to monitor protesters following the 2015 death of Freddie Gray in Baltimore.

Yep, even the Hollywood gangster films have featured a victim flipping through a collection of mug shots. The idea is pretty simple. Bad actors who end up in a collection of mug shots are often involved in other crimes. Looking at images is one way for LE and intel professionals to figure out if there is a clue to be followed.

Now what’s the difference between having software look for matches? Software can locate similar fingerprints. Software can locate similar images, maybe even the image of the person who committed a crime. The idea of a 50 year old man robbed at an ATM flipping through images of bad actors in a Chicago police station is, from my point of view, a bridge too far. The 50 year old will either lose concentration or just point at some image and say, “Yeah, yeah, that looks like the guy.”

Let’s go with software because there are a lot of bad actors, there are some folks on Facebook who are bad actors, and there are bad actors wandering around in a crowd. Don’t believe me. Go to Rio, stay in a fancy hotel, and wander around on a Saturday night. How long before you are robbed? Maybe never, but maybe within 15 minutes. Give this test a try.

Software, like humans, makes errors. However, it seems to make sense to use available technology to take actions required by government rules and regulations. That means that big companies are going to chase government contracts. That means that stopping companies from providing facial recognition technology is pretty much impossible.

I would suggest that the barn is on fire, the horses have escaped, and Costco built a new superstore on the land. Well, maybe I will suggest that this has happened.

Facial recognition systems are tools which have been and will continue to be used. Today’s systems can be fooled. I showed a pair of glasses which can baffle most facial recognition systems in my DarkCyber video a couple of months ago.

The flaws in the algorithms will be improved slowly. The challenge of crowds, lousy lightning, disguises, hats, shadows, and the other impediments to higher accuracy will be reduced slowly and over time.

But let’s get down to basics: The facial recognition systems are here to stay. In the US, the UK, and most countries on the planet. Go to a small city in Ecuador. Guess what? There is a Chinese developed facial recognition system monitoring certain areas of most cities. Why? Flipping through a book with hundreds of thousands of images in an attempt to identify a suspect doesn’t work too well. Toss in Snapchat and YouTube. Software is the path forward. Period.

Facial recognition systems, despite their accuracy rates, provide a useful tool. Here’s the shocker. These systems have been around for decades. Remember the Rand Tablet. That was in the 1960s. Progress is being made.

Outrage is arriving a little late.

Stephen E Arnold, July 30, 2018

Amazon Rekognition: The View from Harrods Creek

July 29, 2018

I read the stories about Amazon’s facial recognition system. A representative example of this genre is “Amazon’s Facial Recognition Tool Misidentified 28 Members of Congress in ACLU Test.” The write up explains the sample. The confidence level was set at 80 percent. Amazon recommends 95 percent.

The result? Twenty eight individuals were misidentified.

At a breakfast meeting this morning (Sunday, July 29, 2018) one uninformed Kentucky resident asked:

What if these individuals are criminals?

Another person responded:

Just 28?

I jotted down the remarks on my mobile phone. Ah, the Bluegrass state.

Stephen E Arnold, July 29, 2018

Next Page »

  • Archives

  • Recent Posts

  • Meta