Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Snowden: A Review
Articles

Snowden: A Review

ISBuzz TeamBy ISBuzz TeamSeptember 23, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Overview

Oliver Stone’s new film, Snowden, reignites the national debate around the potentially competing interests of protecting America from terrorism and protecting our civil liberties. Stone uses two National Security Agency (NSA) initiatives to ask how much power the U.S. government should have under the Foreign Intelligence Surveillance Act (FISA) to conduct electronic surveillance, emergency eavesdropping, and physical searches without a warrant.
 NSA Initiatives

  • Verizon—the NSA ordered Verizon (and other telecoms) to hand over the telephone records of millions of US customers, calling within the U.S. and overseas. The records, which include the phone numbers of both parties, cell site location, trunk identifiers, call time and duration, etc.,  are considered “metadata” or transactional information, rather than communications data, and therefore don’t require a warrant.
  • PRISM—the NSA surveillance program used to collect the private communications of people using Internet services like Microsoft, Yahoo, Google, Facebook, Skype, AOL, Apple, YouTube, PalTalk, etc. by accessing their information directly from these companies’ servers—under the authority of FISA section 702. Although these companies deny giving the government direct server access for bulk data collection, they do admit to providing individual user information in response to specific FISA requests.

To demonstrate how the NSA runs this “dragnet on the whole word,” the movie highlights XKEYSCORE, the web interface to the program behind PRISM. It looks like Google in that you type in keyword selectors to search on topics like ‘every threat made about the President since February 3rd,’ and the search results return relevant information from internet users’ public and private emails, social posts, chats, etc.—thanks to the power of hundreds of servers working 24/7 around the globe.
Security Vulnerabilities

Ironically, XKEYSCORE is built on a Linux open stack that may have design deficiencies, leaving it vulnerable to insider attack. For example, XKEYSCORE relies on system logs to track analysts’ search queries when they log into the web browser. However, systems administrators can directly query MySQL databases housing stored data, thereby bypassing systems log so their search queries can’t be tracked.

Another potential vulnerability is that systems admins use the same shared account— under the name oper—to log into XKEYSCORE servers to configure them. If a rogue admin does something malicious, it hard to trace back to him/her since the login account is shared.

No doubt these security risks have been addressed since Snowden’s whistleblowing. But, since other bugs in the code or less-than-perfect security protocols may still exist, the risk of an insider working on behalf of another country, or outside group, could still incapacitate XKEYSCORE, or put it in the wrong hands.

Possible Quotes/Comments

One of the most significant points made in the film is that war no longer happens only on the ground; it is fought in cyberspace. The real threats to the U.S. economy and political system come from hackers in countries like China, Russia and the Middle East.

Chinese hackers, for instance, have syphoned billions of dollars from U.S. companies using tactics like accessing CEOs’ email accounts to trick corporate finance departments into wiring money to banks in Hong Kong and the mainland. Russian hackers have also tried to inject malware into Hillary Clinton’s infamous private email server by sending fraudulent emails asking her to pay traffic tickets by clicking on a link, which would download a malware file, allowing them remote access to her server.

We can debate whether Snowden is a hero, as some civil libertarians contend, or a traitor as some such as Presidential Candidate Donald Trump once asserted. The larger issue is that we must be prepared to deal with the cyber threats facing our nation, both internal and external, in a way that protects American interests without steamrolling over the Bill of Rights.

[su_box title=”About Tuula Hoiska Fai” style=”noise” box_color=”#336588″][short_info id=’89555′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}