PDA

View Full Version : Leaked HB Gary email re. creating multiple internet "personas" (sockpuppets)



lapis
18th February 2011, 05:41 PM
"UPDATED: The HB Gary Email That Should Concern Us All" (http://www.dailykos.com/story/2011/02/16/945768/-UPDATED:-The-HB-Gary-Email-That-Should-Concern-Us-All)

As I wrote yesterday (http://www.dailykos.com/story/2011/02/14/944478/-HB-Gary-Federal-CEO-a-Daily-Kos-Member), there is a leaked email that has gotten surprisingly little attention around here. It's the one where Aaron Barr discusses his intention to post at Daily Kos - presumably something negative about Anonymous, the hacking group. But that's not the email I'm talking about here.

As I also mentioned yesterday, in some of the emails, HB Gary people are talking about creating "personas", what we would call sockpuppets. This is not new. PR firms have been using fake "people" to promote products and other things for a while now, both online and even in bars and coffee houses.

But for a defense contractor with ties to the federal government, Hunton & Williams, DOD, NSA, and the CIA - whose enemies are labor unions, progressive organizations, journalists, and progressive bloggers, a persona apparently goes far beyond creating a mere sockpuppet.

According to an embedded MS Word document found in one of the HB Gary emails, it involves creating an army of sockpuppets, with sophisticated "persona management" software that allows a small team of only a few people to appear to be many, while keeping the personas from accidentally cross-contaminating each other. Then, to top it off, the team can actually automate some functions so one persona can appear to be an entire Brooks Brothers riot online.

Persona management entails not just the deconfliction of persona artifacts such as names, email addresses, landing pages, and associated content. It also requires providing the human actors technology that takes the decision process out of the loop when using a specific persona. For this purpose we custom developed either virtual machines or thumb drives for each persona. This allowed the human actor to open a virtual machine or thumb drive with an associated persona and have all the appropriate email accounts, associations, web pages, social media accounts, etc. pre-established and configured with visual cues to remind the actor which persona he/she is using so as not to accidentally cross-contaminate personas during use.

And all of this is for the purposes of infiltration, data mining, and (here's the one that really worries me) ganging up on bloggers, commenters and otherwise "real" people to smear enemies and distort the truth.

This is an excerpt from one of the Word Documents, which was sent as an attachment by Aaron Barr, CEO of HB Gary's Federal subsidiary, to several of his colleagues to present to clients:

To build this capability we will create a set of personas on twitter,* ‬blogs,* ‬forums,* ‬buzz,* ‬and myspace under created names that fit the profile* (‬satellitejockey,* ‬hack3rman,* ‬etc*)‬.* ‬These accounts are maintained and updated automatically through RSS feeds,* ‬retweets,* ‬and linking together social media commenting between platforms.* ‬With a pool of these accounts to choose from,* ‬once you have a real name persona you create a Facebook and LinkedIn account using the given name,* ‬lock those accounts down and link these accounts to a selected* ‬#* ‬of previously created social media accounts,* ‬automatically pre-aging the real accounts.

Yes!!! That's how democracy and the first amendment are supposed to work.

In another Word document, one of the team spells out how automation can work so one person can be many personas:

Using the assigned social media accounts we can automate the posting of content that is relevant to the persona. In this case there are specific social media strategy website RSS feeds we can subscribe to and then repost content on twitter with the appropriate hashtags. In fact using hashtags and gaming some location based check-in services we can make it appear as if a persona was actually at a conference and introduce himself/herself to key individuals as part of the exercise, as one example. There are a variety of social media tricks we can use to add a level of realness to all fictitious personas

I don't know about you, but this concerns me greatly. It goes far beyond the mere ability for a government stooge, corporation or PR firm to hire people to post on sites like this one. They are talking about creating the illusion of consensus. And consensus is a powerful persuader. What has more effect, one guy saying BP is not at fault? Or 20 people saying it? For the weak minded, the number can make all the difference.

And another thing, this is just one little company of assholes. I can't believe there aren't others doing this already. From oil companies, political campaigns, PR firms, you name it. Public opinion means big bucks. And let's face it, what these guys are talking about is easy.

Just today I was listening to Stand Up with Pete Dominic on XM's POTUS channel. He was talking about the Wisconsin labor attack and how he had seen a lot of people email and contact the show in support of the Teachers there. Then he added a "but": "I've also seen a lot of anti-labor people on Twitter..."

Really? I thought. How do we know if those are real people? Twitter has to be the easiest thing to fake and to automate with retweets and 180 characrer max sentences. To the extent that the propaganda technique known as "Bandwagon" is an effective form of persuasion, which it definitely is, the ability for a few people to infiltrate a blog or social media site and appear to be many people, all taking one position in a debate, all agreeing, for example, that so and so is not credible, or a crook, is an incredibly powerful weapon.

How many times have you seen a diary get posted that reports some revelatory yet unfavorable tidbit about someone only to see a swarm of commenters arrive who hijack the thread, distract with a bunch of irrelevant nonsense, start throwing unsubstantiated accusations and ad hominem attacks to where before you know it, everyone's pretty much forgotten what the diary said in the first place.

Some times diaries deserve to be swarmed. But what if a diary is swarmed and it's really just one asshole working for a law firm that represents the oil company your diary was attacking?

I don't know about you, but it matters to me what fellow progressives think. I consider all views. And if there appears to be a consensus that some reporter isn't credible, for example, or some candidate for congress in another state can't be trusted, I won't base my entire judgment on it, but it carries some weight.

That's me. I believe there are many people though who will base their judgment on rumors and mob attacks. And for those people, a fake mob can be really effective.

I have no idea what to do about this problem, except just make sure everyone knows its possible, and so watches out for it.

-------------------------------------

Lastly, some here are falling for the meme that HB Gary personel, and especially Aaron Barr himself, are incompetent buffoons. This is a mistake. While Mr Barr may be a fool, he was not the one who fell for a spear fishing attack that allow an, apparently, 16 year old girl to gain access to their servers.

I have rummaged through the leaked email, some of which contain resumes for employees there. These guys are recruiting people with incredibly advanced skills from many different agencies and top universities like MIT.

HB Gary and its subsidiary, HB Gary Federal, as well as Berinco and Palantir, employed a lot of extremely qualified people with backgrounds in the NSA and ATT and other major organizations/corporations. These guys are pros.

Aaron Barr may be a mockery to Anonymous for running his mouth off. As he should be. But he's not an idiot and he wasn't the one who gave out the company's keys to a 16 yo girl.

I wanted to make this clear because it is in the interests of government and propagandists, and anyone else who wants this story to go away to try and blow all this off as one little company who wrote a proposal no one even read and who isn't even competent enough to protect its own servers so no one should pay any attention at all to what they were up to.

That is the narrative being spun, even here on this site, and it is entirely fictitious.

We are under attack. And the attackers are damn good at what they do. Pretending they're not, or that this isn't happening isn't going to make it better.

I do believe there are limitation to the effectiveness of such an attack on this site and others like it. This isn't twitter, and bullshit only goes so far, no matter how many personas are spreading it.

But everyone needs to be aware that not only are sites like this a target of attack, but that Daily Kos has been mentioned specifically as a target of attack.

Maybe this whole thing will be liberating. Maybe people will develop stronger spines and not be so easily swayed by raving mobs.

UPDATE: From another email, I found a government solicitation for this "Persona Management Software". (https://www.fbo.gov/index?s=opportunity&mode=form&id=d88e9d660336be91552fe8c1a51bacb2&tab=core&_cview=1)

This confirms that in fact, the US Gov. is attempting to use this kind of technology. But it appears from the solicitation it is contracted for use in foreign theaters like Afghanistan and Iraq. I can't imagine why this is posted on an open site. And whenthis was discovered by a couple of HB Gary staffers, they weren't too happy about it either:

The first email just had the title, "WTF Dude?"
The response email said, "This is posted on open source. Are you fucking serious?"

Here's the link to the solicitation at website "FedBizOps.gov". Yes, that name doesn't sound like cronyism at all...

Solicitation Number:
RTB220610
Notice Type:
Sources Sought
Synopsis:
Added: Jun 22, 2010 1:42 pm Modified: Jun 22, 2010 2:07 pmTrack Changes
0001- Online Persona Management Service. 50 User Licenses, 10 Personas per user.
Software will allow 10 personas per user, replete with background , history, supporting details, and cyber presences that are technically, culturally and geographacilly consistent. Individual applications will enable an operator to exercise a number of different online persons from the same workstation and without fear of being discovered by sophisticated adversaries. Personas must be able to appear to originate in nearly any part of the world and can interact through conventional online services and social media platforms. The service includes a user friendly application environment to maximize the user's situational awareness by displaying real-time local information.
0002- Secure Virtual Private Network (VPN). 1 each
VPN provides the ability for users to daily and automatically obtain randomly selected
IP addresses through which they can access the internet. The daily rotation of
the user s IP address prevents compromise during observation of likely or
targeted web sites or services, while hiding the existence of the operation. In
addition, may provide traffic mixing, blending the user s traffic with traffic from
multitudes of users from outside the organization. This traffic blending provides
excellent cover and powerful deniability. Anonymizer Enterprise Chameleon or equal

0003- Static IP Address Management. 50 each
Licence protects the identity of government agencies and enterprise
organizations. Enables organizations to manage their persistent online personas
by assigning static IP addresses to each persona. Individuals can perform
static impersonations, which allow them to look like the same person over time.
Also allows organizations that frequent same site/service often to easily switch IP
addresses to look like ordinary users as opposed to one organization. Anonymizer IP Mapper License or equal

0004- Virtual Private Servers, CONUS. 1 each
Provides CONUS or OCONUS points of presence locations that are setup for
each customer based on the geographic area of operations the customer is
operating within and which allow a customer?s online persona(s) to appear to
originate from. Ability to provide virtual private servers that are procured using
commercial hosting centers around the world and which are established
anonymously. Once procured, the geosite is incorporated into the network and
integrated within the customers environment and ready for use by the customer.
Unless specifically designated as shared, locations are dedicated for use by
each customer and never shared among other customers. Anonymizer Annual Dedicated CONUS Light Geosite or equal

0005- Virtual Private Servers, OCONUS. 8 Each
Provides CONUS or OCONUS points of presence locations that are setup for
each customer based on the geographic area of operations the customer is
operating within and which allow a customer?s online persona(s) to appear to
originate from. Ability to provide virtual private servers that are procured using
commercial hosting centers around the world and which are established
anonymously. Once procured, the geosite is incorporated into the network and
integrated within the customers environment and ready for use by the customer.
Unless specifically designated as shared, locations are dedicated for use by
each customer and never shared among other customers. Anonymizer Annual Dedicated OCONUS Light Geosite or equal

0006- Remote Access Secure Virtual Private Network. 1 each
Secure Operating Environment provides a reliable and protected computing
environment from which to stage and conduct operations. Every session uses a
clean Virtual Machine (VM) image. The solution is accessed through sets of
Virtual Private Network (VPN) devices located at each Customer facility. The
fully-managed VDI (Virtual Desktop Infrastructure) is an environment that allows
users remote access from their desktop into a VM. Upon session termination,
the VM is deleted and any virus, worm, or malicious software that the user inadvertently downloaded is destroyed. Anonymizer Virtual Desktop Infrastructure (VDI) Solution or equal.

Contracting Office Address:
2606 Brown Pelican Ave.
MacDill AFB, Florida 33621-5000
United States

Place of Performance:
Performance will be at MacDIll AFB, Kabul, Afghanistan and Baghdad, Iraq.
MacDill AFB , Florida 33679
United States

BabushkaLady
18th February 2011, 06:05 PM
And another thing, this is just one little company of assholes. I can't believe there aren't others doing this already. From oil companies, political campaigns, PR firms, you name it. Public opinion means big bucks. And let's face it, what these guys are talking about is easy.

Very interesting! Thanks for posting this.

mrnhtbr2232
18th February 2011, 06:52 PM
On forums like this I only witness occasional sock puppets, but some places are overrun with them. Any topic or argument can be derailed by red meat emotion and half-truths, and as we know practitioners abound. Assumed legitimacy is one of the modern day dangers for thinking people. For people that give it a free pass it is the foundation of deception. The fact there is software, groups, and governments that are constantly shaping and tossing the world of information is not remarkable. What's remarkable is how many people are successfully conditioned to believe it. The topic does not even matter. As long as assumed legitimacy is present, it combines with ego and creates gratification to the liability of the individual. While we geezer out and remain grumpy outsiders, the future generation is being shaped by every personal gadget imaginable, highly-effective targeted advertising, and suggestive artificial persons using social media. Most people will read something, assume it is true, and subconsciously store it as fact unquestioned. Edward Bernays would be proud.

Book
18th February 2011, 07:58 PM
The Megaphone Desktop Tool gives the user the option of going to a particular site with a poll, and if the user chooses to go to the site, the software then casts a vote automatically, when this is technically feasible. The vote is chosen by the distributors of Megaphone.

Giyus tries to save you the time and effort of locating the voting form inside the website, a seemingly simple task that may prove quite confusing at certain sites. Whenever we technically can we direct you straight to the voting action. If you have arrived at the poll results, it means that you were directed straight to the voting action and have already successfully voted. If for some reason you don't care to vote, you can always use the "No Thanks" link in the article alert popup. [9]

In the original version, the user was offered the option to vote or not to vote (see screenshot above), but was not offered the option to choose their own vote.

The software license provides for remote updates: "You understand and agree that Giyus.Org may provide updates, patches and/or new versions of the Software from time to time, including automatic updates that will be installed on your computer, with notice to You, as needed to continue to use the Services, and You hereby authorize such installations."

http://en.wikipedia.org/wiki/Megaphone_desktop_tool

:o

tater
18th February 2011, 09:25 PM
Jeez, this sounds ominous :o. Magnes is gonna need a raise and overtime approval. And cut him a little slack too y'all.

General of Darkness
18th February 2011, 09:29 PM
Jeez, this sounds ominous :o. Magnes is gonna need a raise and overtime approval. And cut him a little slack too y'all.


Shut your hole tater, before I ass punch your salad. ;)

keehah
18th February 2011, 09:32 PM
As long as the herd of internet slackers stays linked in herd, and can be motivated to do something for 30 seconds, they will always be king of the Google bombs!

tater
18th February 2011, 09:33 PM
Jeez, this sounds ominous :o. Magnes is gonna need a raise and overtime approval. And cut him a little slack too y'all.


Shut your hole tater, before I ass punch your salad. ;)


Ass punching? So my dick ain't good nuff for stabbing huh? I see how it is :D

General of Darkness
18th February 2011, 09:50 PM
Jeez, this sounds ominous :o. Magnes is gonna need a raise and overtime approval. And cut him a little slack too y'all.


Shut your hole tater, before I ass punch your salad. ;)


Ass punching? So my dick ain't good nuff for stabbing huh? I see how it is :D


Friday is knife sharpening night.

tater
18th February 2011, 09:54 PM
Jeez, this sounds ominous :o. Magnes is gonna need a raise and overtime approval. And cut him a little slack too y'all.


Shut your hole tater, before I ass punch your salad. ;)


Ass punching? So my dick ain't good nuff for stabbing huh? I see how it is :D



Friday is knife sharpening night.


:o Aww shucks General. I was just joshing witcha. Ass punching is fine. :-\

lapis
18th February 2011, 10:51 PM
:o Aww shucks General. I was just joshing witcha. Ass punching is fine. :-\


Oh no, not on my thread! Take it somewhere else (along with the salad)!

ximmy
18th February 2011, 11:09 PM
tater & GoD after some long hours of ass punching salad...

Neuro
19th February 2011, 02:51 AM
tater & GoD after some long hours of ass punching salad...


LMFAPSO!

Did this thread come to be about Multiple Internet Personality Disorder?

tater
19th February 2011, 06:38 AM
:o :-[
I uhhh...well, you see...dang ximmy how in the world can I invite the fellas at deer camp to check out the forum now. I reckon it's
too late to change my mind on the dick stabbing. If Earl sees this thread it's over for tater. I'll be the butt of his jokes till Kingdom
come. :'(

There's only one thing to do. I'll just have to employ my multiple sockpuppets and their seemingly different personas until this blows
over... tater tot, mashed tater, fried tater, tater salad (y'all might be suspicious of that one) tater log and baked tater for starters.

Before I disappear I would like to take this oppurtunity to lay the entire blame for thread derailment at the feet of the General. ;D

beefsteak
19th February 2011, 06:56 AM
You forgot one.... Mr Tater Head. :D

beefsteak

lapis
19th February 2011, 10:42 AM
tater & GoD after some long hours of ass punching salad...

All is well, because there's a GSUS moderator hovering in the background to make sure they use their safe word when things get...uh...tight.

tater
19th February 2011, 12:40 PM
tater & GoD after some long hours of ass punching salad...

All is well, because there's a GSUS moderator hovering in the background to make sure they use their safe word when things get...uh...tight.


I see I'm going to have to come clean with my personality disorder. This is hard guys...here goes... :-[



I'm a lesbian trapped in a man's body. Whew, I feel better.

|--0--|

Winston Smith
20th February 2011, 09:05 AM
http://gold-silver.us/forum/gallery/894_20_02_11_10_04_57.jpeg

JDRock
20th February 2011, 10:24 AM
always watch for large (relatively) groups joining at approx the same time.....they will post like they believe what we do, only to turn and pressure the mods AS A GROUP to " be reasonable about all this jew bashing" etc. :oo-->

tater
20th February 2011, 12:34 PM
http://gold-silver.us/forum/gallery/894_20_02_11_10_04_57.jpeg


:D That's funny. But how could I have forgotten it, seeings how it's so HUGE and all ;D

Internet huge y'all.

dys
20th February 2011, 03:38 PM
http://www.outlawjournalism.com/forum/viewtopic.php?t=266

"And by their fruits ye shall know them ..."

Twenty-Five Rules of Disinformation

1. Hear no evil, see no evil, speak no evil

2. Become incredulous and indignant

3. Create rumor mongers

4. Use a straw man

5. Sidetrack opponents with name calling, ridicule

6. Hit and Run

7. Question motives

8. Invoke authority

9. Play Dumb

10. Associate opponent charges with old news

11. Establish and rely upon fall-back positions

12. Enigmas have no solution

13. Alice in Wonderland Logic

14. Demand complete solutions

15. Fit the facts to alternate conclusions

16. Vanish evidence and witnesses

17. Change the subject

18. Emotionalize, Antagonize, and Goad

19. Ignore facts, demand impossible proofs

20. False evidence

21. Call a Grand Jury, Special Prosecutor

22. Manufacture a new truth

23. Create bigger distractions

24. Silence critics

25. Vanish

Eight Traits of The Disinformationalist

1. Avoidance

2. Selectivity

3. Coincidental

4. Teamwork

5. Anti-conspiratorial

6. Artificial Emotions

7. Inconsistent

8. Newly Discovered: Time Constant

dys