Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cyber Security Lessons in the Wake of Project MUSCULAR
Articles

Cyber Security Lessons in the Wake of Project MUSCULAR

ISBuzz TeamBy ISBuzz TeamNovember 19, 2013Updated:April 30, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
MUSCULAR
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Recent revelations that the NSA has been infiltrating Yahoo! and Google point to two important lessons:  encryption key management is essential when it comes to cyber security, and just because an intelligence program is legal does not make it valuable.

Under a project codenamed “MUSCULAR,” the NSA sought to work around the restrictions of PRISM, another NSA info-sharing program that required cloud providers to pass select information onto the intelligence community.

Both Google and Yahoo! pass bits of data onto data centers.  In each of these exchanges, such as when a user conducts a web search, these centers communicate with and protect the user using Secure Socket Layer encrypted sessions—standard means of transmitting personal data which, in turn, could be connected to other sensitive information, such as credit card numbers.

MUSCULAR was much more robust than Prism in that the NSA penetrated Google and Yahoo! networks on the perimeter of their security defenses.  The NSA then used this access to infiltrate the data centers and disable the Secure Socket Layer encryption.  This in effect enabled the NSA to collect large amounts of data, including millions of user accounts containing downloadable email attachments.

Edward Snowden revealed the details of MUSCULAR, but his leaks urge us to go further and ask:  what do programs like “MUSCULAR” teach us about cyber security?

There are two lessons that come to mind.  First and foremost, encrypted key management cannot be underestimated.  That is, in addition to encrypting a piece of data before it leaves your cloud, it’s essential to also maintain control of the encryption keys.  Without this information, any attempt to crack the encryption algorithm—even by the NSA—would prove useless.  You would have to give your consent and hand over your keys to have your data read.

Second, legality and value are not the same when it comes to government programs. In a very elastic sense, MUSCULAR is technically legal under Executive Order 12333.  This holds true if one labels all the information the program has collected as “foreign intelligence.”  But this assumption is just rhetoric.  Under this skewed logic, anything from the weather to Angela Merkel’s private phone records can be construed as “foreign intelligence.”  That does not make it any more true.

Apparently, the American public agrees.  In a recent U.S. public survey, more than a majority of respondents said that they would support the NSA if they could be shown how its programs have thwarted terrorist plots.  Also, in a question asking Americans whether they feel confident with the information the intelligence community is providing President Obama, the share of “not at all confident” respondents rose from 8 to 11 percent in the year since the survey was last administered.

The American people are tired.  Going forward, this popular dissatisfaction will hopefully make for smarter cyber security all around:  better management of encryption keys on the part of businesses, and more necessary and palatable programs on the part of the NSA.

Dave BissonName: David Bisson

Twitter Handle: @DMBisson

 

 

Area of Expertise:

David specializes in cyber security as it relates to U.S. national security and to American military and strategic culture.

Professional Biography:

David is currently a senior at Bard College, where he is studying Political Studies and writing his senior thesis on cyberwar and cross-domain escalation.  He also works at the Hannah Arendt Center for Politics and Humanities at Bard College as an Outreach intern.  Post-graduation, David would like to leverage his extensive journalism experience as well as his interest in computer coding and social media to pursue a career in cyber security, both its practice and policy.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}