Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 Overview  





2 Operational details  





3 Reactions and countermeasures  





4 Gallery  





5 See also  





6 References  





7 External links  














MUSCULAR






Español
Euskara
فارسی
Français
עברית
Português
Русский
 

Edit links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 




In other projects  



Wikimedia Commons
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 


MUSCULAR (DS-200B), located in the United Kingdom,[1] is the name of a surveillance program jointly operated by Britain's Government Communications Headquarters (GCHQ) and the U.S. National Security Agency (NSA) that was revealed by documents released by Edward Snowden and interviews with knowledgeable officials.[2] GCHQ is the primary operator of the program.[1] GCHQ and the NSA have secretly broken into the main communications links that connect the data centersofYahoo! and Google.[3] Substantive information about the program was made public at the end of October 2013.

Overview

[edit]
Idea behind the MUSCULAR program, which gave direct access to Google and Yahoo private clouds, no warrants needed.
Idea behind the MUSCULAR program, which gave direct access to Google and Yahoo private clouds, no warrants needed.

The programme is jointly run by:

MUSCULAR is one of at least four other similar programs that rely on a trusted 2nd party, programs which together are known as WINDSTOP. In a 30-day period from December 2012 to January 2013, MUSCULAR was responsible for collecting 181 million records. It was however dwarfed by another WINDSTOP program known (insofar) only by its code DS-300 and codename INCENSER, which collected over 14 billion records in the same period.[4]

Operational details

[edit]

According to the leaked document the NSA's acquisitions directorate sends millions of records every day from internal Yahoo! and Google networks to data warehouses at the agency's headquarters at Fort Meade, Maryland. The program operates via an access point known as DS-200B, which is outside the United States, and it relies on an unnamed telecommunications operator to provide secret access for the NSA and the GCHQ.[3]

According to The Washington Post, the MUSCULAR program collects more than twice as many data points ("selectors" in NSA jargon) compared to the better known PRISM.[2] Unlike PRISM, the MUSCULAR program requires no (FISA or other type of) warrants.[dubiousdiscuss]

Because of the huge amount of data involved, MUSCULAR has presented a special challenge to NSA's Special Source Operations. For example, when Yahoo! decided to migrate a large amount of mailboxes between its data centers, the NSA's PINWALE database (their primary analytical database for the Internet) was quickly overwhelmed with the data coming from MUSCULAR.[5]

Closely related programmes are called INCENSER and TURMOIL. TURMOIL, belonging to the NSA, is a system for processing the data collected from MUSCULAR.[1]

According to a post-it style note from the presentation, the exploitation relied on the fact that (at the time at least) data was transmitted unencrypted inside Google's private cloud, with "Google Front End Servers" stripping and respectively adding back SSL from/to external connections. After the information about MUSCULAR was published by the press, Google announced that it was working on deploying encrypted communication between its datacenters.[2]

Reactions and countermeasures

[edit]

In early November 2013, Google announced that it was encrypting traffic between its data centers.[6] In mid-November, Yahoo! announced similar plans.[7]

In December 2013, Microsoft announced similar plans and used the expression "advanced persistent threat" in their press release (signed-off by their top legal representative), which the press immediately interpreted as comparison of the NSA with the Chinese government-sponsored hackers.[8][9]

Google engineer Brandon Downey stated the following on Google+:[10]

"Fuck these guys. I've spent the last ten years of my life trying to keep Google's users safe and secure from the many diverse threats Google faces… But after spending all that time helping in my tiny way to protect Google -- one of the greatest things to arise from the internet -- seeing this, well, it's just a little like coming home from War with Sauron, destroying the One Ring, only to discover the NSA is on the front porch of the Shire chopping down the Party Tree and outsourcing all the hobbit farmers with half-orcs and whips."

[edit]

See also

[edit]

References

[edit]
  1. ^ a b c Gellman, Barton; Soltani, Ashkan; Peterson, Andrea (November 4, 2013). "How we know the NSA had access to internal Google and Yahoo cloud data". The Washington Post. Retrieved November 5, 2013.
  • ^ a b c Gellman, Barton; Soltani, Ashkan (October 30, 2013). "NSA infiltrates links to Yahoo, Google data centers worldwide, Snowden documents say". The Washington Post. Retrieved October 31, 2013.
  • ^ a b Gellman, Barton; DeLong, Matt. "How the NSA's MUSCULAR program collects too much data from Yahoo and Google". The Washington Post. Archived from the original on 30 October 2013. Retrieved 28 December 2013.
  • ^ Gellman, Barton; DeLong, Matt (2013-10-30). "One month, hundreds of millions of records collected". The Washington Post. Archived from the original on 2019-04-16. Retrieved 2014-01-27.
  • ^ Gallagher, Sean (October 31, 2013). "How the NSA's MUSCULAR tapped Google's and Yahoo's private networks". Ars Technica. Retrieved November 1, 2013.
  • ^ Gallagher, Sean (2013-11-06). "Googlers say "F*** you" to NSA, company encrypts internal network". Ars Technica. Retrieved 2014-01-15.
  • ^ Brandom, Russell (2013-11-18). "Yahoo plans to encrypt all internal data by early 2014 to keep the NSA out". The Verge. Retrieved 2014-01-27.
  • ^ Danny Yadron (2013-12-05). "Microsoft Compares NSA to 'Advanced Persistent Threat' - Digits - WSJ". Blogs.wsj.com. Retrieved 2014-01-15.
  • ^ Tom Warren (2013-12-05). "Microsoft labels US government a 'persistent threat' in plan to cut off NSA spying". The Verge. Retrieved 2014-01-15.
  • ^ Opam, Kwame (2013-11-06). "Google engineers issue 'fuck you' to NSA over surveillance scandal". The Verge. Retrieved 2023-04-17.
  • [edit]
    Retrieved from "https://en.wikipedia.org/w/index.php?title=MUSCULAR&oldid=1170849914"

    Categories: 
    GCHQ operations
    National Security Agency operations
    Intelligence agency programmes revealed by Edward Snowden
    Secret government programs
    Surveillance scandals
    Hacking of Yahoo!
    Google
    Email hacking
    Cyberattacks
    Hidden categories: 
    Articles with short description
    Short description is different from Wikidata
    Articles containing potentially dated statements from 2007
    All articles containing potentially dated statements
    All accuracy disputes
    Articles with disputed statements from February 2014
    Articles to be expanded from January 2014
    All articles to be expanded
    Articles using small message boxes
     



    This page was last edited on 17 August 2023, at 16:00 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki