Showing posts with label Obama. Show all posts
Showing posts with label Obama. Show all posts

Friday, April 19, 2013

How Obama's BlackBerry got secured

(Updated: November 1, 2013)

Around January 20, 2009, when Barack Obama took over the office of president of the United States, there was quite a lot of media attention about the fact that he had to give up his BlackBerry, because it was considered to be a security risk.

This caused almost world wide media attention, but the follow-up was less accurately covered and a number of different stories were told. Here we will show that Obama actually kept his beloved BlackBerry, but only after it had been secured by special encryption software and some additional security measures.


Barack Obama using his BlackBerry 8830 during the election campaign in 2008
(Photo: Getty Images)


Obama's predecessor, George W. Bush, also used a BlackBerry during the 2000 presidential campaign, but had to give it up, as well as the use of any e-mail software, upon taking office. Three days earlier, he sent out a final e-mail to 42 friends and family members to inform them that he would no longer correspond electronically.

Eight years later, Barack Obama was also forced to give up his BlackBerry, not only because of concerns that its communications and e-mail could be intercepted, but also because of the Presidential Records Act of 1978. This makes all written White House communications public property and subject to examination under the Freedom of Information Act (FOIA).

However, this time Obama definitely wanted keep using this popular business phone to stay in touch with people outside the White House bubble. Therefore, the Secret Service, The White House Communications Agency (WHCA) and the National Security Agency (NSA) went looking for a solution.


US President Obama using a silver BlackBerry 8830
Nokia E61 or E62, as recognized by someone here

Sectéra Edge

Some media suggested Obama had to change his BlackBerry for the Sectéra Edge, a highly secured PDA, which is produced by General Dynamics for the US military. But the Sectéra Edge is quite big, heavy (340 grams) and bulky and therefore hardly convenient for someone used to a BlackBerry. This solution would also require everyone that Obama would like to communicate with to have the same phone, which is priced between 2650,- and 3350,- USD. Secure communications are only possible if both ends use the same (or compatible) encryption devices.

According to other sources, the Sectéra Edge was only used in addition to Obama's BlackBerry, until a permanent solution was worked out. Reports weren't clear about how exactly these two devices were combined. Probably the Sectéra Edge acted like an encryptor, which was plugged into the BlackBerry, so Obama could keep using this device to make a call or send out an e-mail, which then went through the Sectéra Edge, encrypting it, before going over the telecommunications network.


The Sectéra Edge, manufactured by General Dynamics

Compromise

That latter, temporary solution must have been even more cumbersome, so a compromise was made, in which president Obama could keep using a BlackBerry, but equipped with a software package to encrypt phone calls and text and email messages.

For this purpose, the security agencies choose the SecurVoice application, which was developed by The Genesis Key, in cooperation with engineers from BlackBerry manufacturer Research In Motion (RIM). SecurVoice should not be confused with Secure-Voice.com, nor with SecuVOICE, which is used for securing the smart phone of the German chancellor Merkel.

After the NSA did all the necessary tests and checking to make sure the software met federal standards like FIPS 140-2, the highly secured BlackBerry was delivered to the president somewhere in May or June 2009. He also gave up his old e-mail address and switched to a new one, which is kept secret.

Maybe we can see the new, secured BlackBerry in this picture below, where there are two BlackBerrys lying in front of Obama. The silver one seems to be the BlackBerry 8830, which he already used during the election campaign. The black one, probably a BlackBerry 8900, could then be the new secure one, as we can see the president using this one in later pictures:


President Barack Obama works with Jon Favreau, director of speechwriting, on the Normandy speech
aboard Air Force One enroute to Paris. In front of him are a black and a silver Blackberry.
(White House photo by Pete Souza, June 5, 2009 - click for a bigger picture!)


Detail from the picture above, showing the two BlackBerrys


The secure BlackBerry was not only issued to the president, but also to a small group of people with whom he likes to stay in close contact with. This because, as said, it's only possible to have secure communications if both ends are using the same encryption method. This limited Obama's goal of keeping in touch with the outside world: encryption (still) means exclusion.

The number of people able to message and call the president is probably only between ten and twenty. Included are vice-president Biden, Obama's chief of staff and some of his top advisers, his press secretary, first lady Michelle Obama, a few other family members, and a small group of personal friends from Chicago.

On October 30, 2013, Obama's press secretary Jay Carney said that the president will continue to use his (secured) BlackBerry, despite concerns about eavesdropping which came up after it was revealed that NSA intercepted the communications of 35 world leaders.


The Genesis Key

The SecurVoice software for the presidential BlackBerry was developed for a small company called The Genesis Key, Inc., based in Washington DC. This company was founded in October 2008 by W. Steven Garrett, who took the name from an item used in the 1986 computer game The Legend of Zelda.

The software was developed in the previous four years, apparantly for one of the projects of Steve I. Cooper, a former special assistant to the president, senior director for information integration, and CIO (Chief Information Officer) for the Office of Homeland Security. He is now a member of the advisory board of SecurDigital, Inc., a firm founded in October 2009 by Bruce Magown and Steven Garrett to distribute the SecurVoice software applications.

Steven Garrett is a man with a quite surprising background. His Linked-In profiles show that he has been involved in a very wide range of businesess, like manufacturing plants for Fannies Fat Free Cheesecakes and Fat Free Burger (providing microwave-ready cheeseburgers to military commissaries) and marketing & sales for Lion Sportswear and Faded Glory Jeans. He also developed a highly secure appartment building, named Garrett Place. At his twitter account he describes himself as "Proven Rainmaker, Change Agent, Strategist, and Driving Force for Unprecedented, Exponential Growth in Revenues, Earnings, and Market Valuation".


SecurVoice

The Genesis Key released the SecurVoice software in December 2008, claiming this to be the world's first completely secure voice and data encryption solution. Allthough there were already a number of other hardware and software encryption solutions, the SecurVoice application should be able to protect global voice connections between and within all types of cell, satellite, PBX, SDR and VOIP phones and phone systems.

SecurVoice is 100% Java based, which should make it device- and carrier-independent, but according to the website, the software is currently only operational on the Blackberry operating system version 4.5 and up. Software porting for other operating systems, like Symbian, Brew, Windows Mobile, Google, and iPhone is said to be underway.

With SecurVoice, each phone can be loaded with up to three levels of security, each one accessible through a separate icon and recognizable by a different ringtone. When dialing a number and this number has a cryptographic key associated with it, then the call is automatically placed as a secured call. If a phone number has no cryptographic key associated with it, then the cell phone operates normally and the call is placed unencrypted.

The SecurVoice software comes in two versions:
- Phone-to-Phone (P2P), where secure calls are made directly from one cell phone to another. The price for government users is 1795,- USD per application.
- Phone-to-Server (P2S), where secure calls are routed from the phone to an enterprise server and back. The price of a server license is between 2500,- and 25.000,- USD.

It's likely, that for Obama the server solution was chosen. This allows a centralized key management, monitoring of all secure calls and record keeping of the messages. One source says the president may have to wait up to 50 minutes for an e-mail reply, as the system actively sniffs out incoming messages for viruses or Trojan horses.


Overview of the SecurVoice application options
(by The Genesis Key/SecurDigital)


Encryption

The SecurVoice software features a dual-layered, or hybrid encryption scheme, which means it combines symmetrical and asymmetrical encryption algorithms. It performs the voice encryption in real time by using a fast symmetric cipher, using a strong key. This key is then encrypted with a public-key or asymmetrical cryptosystem, like RSA or ECC, and transmitted together with the encrypted message. This is also how the vast majority of present-day communications encryption works.

The SecurVoice symmetric encryption uses a 256-bit session (conversation) key, which replaces the encryption every second with non-reoccurring numbers. This session key is a combination (salted hash) of the sender Base Secure Key (stored in the recipient key store) and a random session key. According to the manufacturer, SecurVoice uses classified Type 1 encryption algorithms, which are restricted to government and military users. For corporate users, public crypto algorithms like AES are used.

In case of a SecurVoice enterprise server, the software converts voice into encrypted data, which is then sent over the carrier network to the SecurVoice Enterprise Server where it is decrypted. It is then re-encrypted and sent back over the carrier network to the receiving phone, where it is decrypted and converted back to voice. It's also possible to select different encryption algorithms, so that, for example, encryption from a cell phone to the enterprise server may be the AES algorithm with a 128-bit, while from the server to the receiving phone this may be done by using Elliptic Curve Cryptography (ECC).


President Obama using his BlackBerry 8900 in the limousine while traveling
from the University of Indonesia to the airport in Jakarta, Indonesia.
(White House Photo by Pete Souza, November 10, 2010)

Security risks

As Obama wanted to keep using a BlackBerry device, the security solution is software only. This still leaves risks like compromised hardware and hacking by means of social engineering. Therefore, some security specialists say that it's not impossible to hack Obama's BlackBerry and that foreign states and other hackers will likely try to do so.

To minimize these risks, the secured BlackBerrys prevent forwarding e-mail messages from the president and sending him attachments. His secret e-mail address is likely to be changed regularly as well and Obama's friends and staff members were lectured about these security issues.

Another risk of the president using a BlackBerry, like a cell phone in general, is that enemies can try to track the president's location in real-time, even when GPS is disabled. Every cell phone regularly transmits it's IMEI-number to the cell tower, and this can be intercepted by devices like a Triggerfish. How this tracking can be done, and countered, is described in this, respectively this article.

One source says the presidential BlackBerry can only connect to a secure base station, which can be used to hide the IMEI-number of the device and thus prevent tracking it. This would mean the White House Communications Agency has to carry such a secure base station wherever the president goes.

There must be also a secure base station inside the presidential limousine, as we can see in the picture above. First because using a foreign cell phone network would be a big security risk, but also because the limousine is most likely constructed like a Faraday cage, and therefore a BlackBerry could only be used if there's a base station in the car itself (and probably also in Air Force One). The secure base station is probably connected to a secure satellite link with Washington.



President Obama uses his BlackBerry for calling Mitt Romney
(White House photo by Pete Souza, November 6, 2012)



President Obama using his old BlackBerry, during a campaign
visit to Albuquerque, New Mexico in August 2008

Conclusion

As we have seen, president Obama has kept his BlackBerry, but only after it had been secured. This took quite some effort: newly developed software had to be tested within a couple of months, all his contacts have to use the same software, limiting their number to a rather small group, and a secure base station has to follow the president. Nonetheless, this ad hoc solution for the president marks the beginning of an era in which top level mobile communications will no longer be secured with dedicated hardware, but by using software applications for regular commercial smartphones.


> See also: Some SIGINT and COMSEC during the Nuclear Security Summit



Sources and Links
- CNN.com: 'I made Obama's BlackBerry'
- FoxNews.com: Obama Getting Super-Secure BlackBerry
- New York Times: Symbol of Elite Access: E-Mail to the Chief
- Washington Times: Obama soon to get secure BlackBerry
- The Telegraph: Barack Obama's BlackBerry 'no fun'
- September 2010: The X-Change Corporation Acquires Genesis Key, Inc.
- Radio interview about SecurVoice: Telecom Junkies - Secret Agent Phone
- Interview with Steven Garrett: Wireless Technology Risks and Enterprise Security
- See also: securvoice.blogspot.com

Monday, May 28, 2012

Obama on vacation



In the previous post we saw the cool phones the American president uses in his Oval Office. This time we take a look at the telephone equipment he uses when he is on vacation, because "Presidents don't get vacations, they just get a change of scenery." as a former president once said.

For this purpose we have two nice pictures from the vacation of president Obama from August 18 to August 29, 2011 on the Blue Heron Farm in Chilmark on the island of Martha's Vineyard, Massachusetts.

In the first picture we see president Barack Obama, reflected in a mirror, conducting a conference call on the situation in Libya with his national security staff. Also participating is John Brennan, Assistant to the President for Homeland Security and Counterterrorism, who sits on the right:


President Barack Obama and his assistant John Brennan in a conference call. August 22, 2011
Note how the telephone and power cables are taped onto the table
(White House photo by Pete Souza - click for a bigger version)


On the table we see two sets of the Secure Terminal Equipment (STE), made by L3 Communications. This is a telephone capable of making secured calls up to the level of Top Secret. The STE is the successor of the legendary STU-III system and is used for secure end-to-end communications throughout the government and the military of the US. For the President Of The United States (POTUS), these phones are used when he is travelling or staying somewhere outside the White House.

In the second picture we see Obama monitoring Hurricane Irene with John Brennan, Assistant to the President for Homeland Security and Counterterrorism (in light blue shirt) and some other officials. They are waiting for a conference call on the hurricane with affected governors and mayors:


Obama monitoring Hurricane Irene with his assistant John Brennan
and some other officials. August 26, 2011
(White House photo by Pete Souza - click for a bigger version)


This picture shows the same table as in the previous one, but with different chairs and different phones. There are two telephone sets on each side of the table: an regular white Panasonic KX-TS108W office phone, and a dark gray Cisco 7975G Unified IP Phone.

The white phone sets are most likely part of the private branch exchange (PBX) of the holiday house and therefore have no special security features. As we can see in this picture, the conference call is made using these white phones.

The Cisco phones are more interesting, because they belong to the highly secure Executive Voice over Secure IP (VoSIP) phone network, which was installed in 2007-2008. For this network the common high end Cisco IP telephone sets are used, but with a bright yellow bezel faceplate, instead of the standard silver one. Yellow indicates that this network is cleared for conversations up to Top Secret/SCI, the highest classification level.

As the second picture is taken some days later than the first one, it looks like the White House Communications Agency (WHCA) eventually installed this secure network instead of the STE phones. In the pictures you can see that the cables of the STE-phones are only provisionarily taped onto the table, but the cables of the Cisco ones are neatly bound by tie bands. The latter phones allows the president to make calls with the highest classification level.

A bit strange however, is the fact these phones are sitting in what seems to be a not very secure room (note the open door in the first and the open window in te second picture and that it's a temporarily hired location). For example former president G.W. Bush had such communications equipment in a special room without windows at his ranch in Texas.

For (non-secure) mobile communications during president Obama's vacation, the telecommunications company Verizon installs two temporary cell towers, known as cell on wheels, on Martha's Vineyard. Apparently the island normally lacks a sufficient cell phone coverage, so these extra towers are needed to provide the president and his staff with a good reception.

This also leads to the somewhat odd situation that local people only have a good cell phone reception during the time the president is on the island. Then suddenly their phones ring and text messages arrive in places where it's quiet during the rest of the year!


- NY Times-article: If Phones Ring, Obama Is Here, With Cell Power

Friday, February 3, 2012

Does Obama really lack cool phones?

(Updated: December 21, 2014)

In April last year, US president Obama told some fundraisers that he was disappointed by the communications equipment he found in the White House:

"I always thought I was gonna have like really cool phones and stuff," he said during a Q&A session with contributors at a fund-raising meeting in Chicago on April 14, 2011.

"We can't get our phones to work." Acting out his exasperation, he said: "Come on, guys. I'm the president of the United States! Where's the fancy buttons and stuff and the big screen comes up? It doesn't happen."

Obama made these remarks after the press pool had left and may not have realized some reporters back at the White House could still hear his comments. The president was probably responding to a question about bottlenecks in technological innovation and he used his White House experience as an example.


A lot of people would probably like to believe these remarks of the president, symbolizing the outdated state of the federal government. But in fact, what Obama said, isn't quite true.

In 2006-2007 president George W. Bush had the White House Situation Room completely renovated, providing it with state-of-the-art communications facilities. Since then the real Situation Room has all the phones and videoscreens and other stuff, which was before only seen in movies.

Also, when Obama took over the office in January 2009, he found quite a cool phone on the presidential desk in the Oval Office: an Integrated Services Telephone 2, or IST-2. This is a so called red phone (I'll explain that term in a later blog post) capable of making both secure and non-secure calls from one single instrument:



Not a cool phone? An IST-2 telephone on Obama's desk, March 29, 2009
(White House photo by Pete Souza)


The IST-2 was installed in the White House in 2007. It's a phone specially designed for the US Defense Red Switch Network (DRSN), which connects the president and the Pentagon with all major military command centers. These new phones were part of an upgrade of the communications system, which became necessary after some serious communication problems occured during the 9/11 attacks.

Therefore, the problems caused by outdated equipment should have been solved under president Bush. This would leave nothing to complain about for Obama anymore.

But there's an other interesting fact. Only a few weeks before Obama made his aforementioned remarks in April 2011, the rather rare IST-phone had just been replaced by two more ordinary sets:



The Cisco 7975 and the Lucent 8520 on Obama's desk, July 31, 2011
Also on the desk appears to be the iPad Obama got from Steve Jobs in May 2011
(White House photo by Pete Souza)


Now we see a Cisco 7975G Unified IP Phone (with expansion module 7916) behind a Avaya/Lucent 8520T on Obama's desk. This Lucent phone is from the most widely used business phone series worldwide, but is dating back to the mid-nineties. The Cisco 7975G is a VoIP (Voice over IP) telephone, and as such also one of the most widely used.

Both are high-end multiline models, with many functions and large displays, with the Cisco one even having a full colour touchscreen. This phone is also "cool", not because of having the military grade specifications or the exclusiveness like the IST-2, but because the phone (and its ringtone in particular) became an almost iconic item from the highly popular tv-series 24:



A Cisco 7970 IP Phone used in the CTU operations center in the tv-series 24
(screen cap by www.24tv.de)


This series, which was broadcasted between 2001 and 2010, shaped people's imagination of the presidency and was in many ways a forerunner of reality. For example there was a popular black president (David Palmer) years before Obama was elected, and much of the fancy communications equipment from the series, like video teleconferencing, was implemented in the real White House Situation Room in 2007. And now the real president also has the same cool Cisco phone as the heroes used in the tv-series.

So, as we have seen, Obama didn't really tell the truth. The story he told the fundraisers was true during the beginning of the Bush administration, but not during his. Obama actually has some quite cool phones at his disposal, but maybe the only thing is that he just doesn't realize that ;-)


Update:
A great picture of the phones Obama uses in the Oval Office was released on December 16, 2014, when he made a call, using the non-secure telephone, to president Raúl Castro of Cuba:


President Obama calling president Raúl Castro of Cuba, December 16, 2014
Also notice the specially secured Blackberry at his right hand
(White House Photo by Pete Souza - Click to enlarge)




Links
- Report on CBS News: Obama laments lack of "cool phones" at the White House
- About the renovation of the White House Situation Room
- Pictures of more "Obama Phones" at Cryptome.org
- Dutch article about Obama's gadgets at ZDNet.nl
- Extensive German fanpage of the 24-series