Feeds

Is there anything to find on bin Laden's hard drive?

Mining the 'mother lode' of intelligence

Beginner's guide to SSL certificates

US officials are already referring to the trove of computer drives and disks seized from Osama bin Laden's compound as “the mother lode of intelligence.” Such gloating is probably premature.

As reported by Politico and others, the US Navy SEAL team that killed bin Laden on Sunday in Pakistan snatched computers, thumb drives and other electronic equipment. The gear has been sent to a secret location in Afghanistan where hundreds of intelligence officials are examining it.

“They cleaned it out,” one official boasted. “Can you imagine what's on Osama bin Laden's hard drive?”

It wouldn't be surprising for the answer to be: little, or very little.

As the world learned shortly after Sunday's lightning raid, bin Laden took extraordinary steps to hide his tracks from the countless spy agencies that worked day and night for 10 years to track him. He steadfastly shunned devices that left digital footprints. The huge compound where he died had no telephone or internet connection.

Given bin Laden's well-founded paranoia, he probably used encryption to prevent outsiders from reading the contents of his computer. And if that's the case, extracting intelligible data won't be nearly as straightforward as some reports suggest.

Probably the best chance intelligence officials have for recovering the data is exploiting implementation flaws in any encryption program bin Laden may have used. According to a 2007 report from the Middle East Media Research Institute, extremists with the Global Islamic Media Front released what was billed as “the first Islamic computer program for secure exchange [of information] on the Internet.”

It's unknown if bin Laden used “Mujahideen Secrets,” as the program is known, but if he did, that could be a huge boon for intelligence officials. Most successful attacks against encryption programs exploit implementation flaws, such as side channel vulnerabilities, in programs or algorithms that haven't been subjected to rigorous review from researchers.

Screen capture Mujahideen Secrets program

A screen shot of Mujahideen Secrets. The program was released in 2007 and updated the following year.

Mujahideen Secrets may offer 256-bit AES and 2048-bit asymmetrical encryption, but given the program's small and insular user base, it wouldn't be surprising if the software authors made crucial mistakes that even they don't know about.

It's more likely that bin Laden used a more reputable encryption program such as PGP or the open-source GnuPG. These programs, too, may have flaws known to US government spooks, but crypto experts generally say the likelihood they can be broken is smaller because, unlike less widely used programs, they have so far withstood robust scrutiny.

Assuming the encryption protecting bin Laden's secrets is sound, the government's best chance of recovering his data is to use forensics tools to find cleartext hidden in free space on the disks, said Nate Lawson, a cryptographer who is principal of security consultancy Root Labs . As The Reg pointed out in February, flash drives are dangerously hard to purge of data, making thumb drives a good starting point.

Lawson said intelligence personnel also might be able to brute-force the passphrase of bin Laden's encryption key. No one knows just how complex a passphrase the National Security Agency is capable of cracking. We're guessing it's considerable, but even that capability is limited and depending on the complexity of the phrase it could take time.

It will be interesting to learn just how adept bin Laden was at protecting the data stashed on his computer gear. It may turn out he made fatal mistakes encrypting it. Then again, don't be surprised if this intelligence mother lode is mostly filled with Fools Gold. ®

Intelligent flash storage arrays

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Shellshock over SMTP attacks mean you can now ignore your email
'But boss, the Internet Storm Centre says it's dangerous for me to reply to you'
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.