Category: Privacy

There is No Evidence that Mass Surveillance Makes Us Safe

This is not an exaggeration/

Pro Publica examined almost a decade of mass surveillance, and could not any meaningful benefit derived from drinking from the data fire hose:

Current and former government officials have been pointing to the terror attacks in Paris as justification for mass surveillance programs. CIA Director John Brennan accused privacy advocates of “hand-wringing” that has made “our ability collectively internationally to find these terrorists much more challenging.” Former National Security Agency and CIA director Michael Hayden said, “In the wake of Paris, a big stack of metadata doesn’t seem to be the scariest thing in the room.”

Ultimately, it’s impossible to know just how successful sweeping surveillance has been, since much of the work is secret. But what has been disclosed so far suggests the programs have been of limited value. Here’s a roundup of what we know.

An internal review of the Bush administration’s warrantless program – called Stellarwind – found it resulted in few useful leads from 2001–2004, and none after that. New York Times reporter Charlie Savage obtained the findings through a Freedom of Information Act lawsuit and published them in his new book, Power Wars: Inside Obama’s Post–9/11 Presidency:

[The FBI general counsel] defined as useful those [leads] that made a substantive contribution to identifying a terrorist, or identifying a potential confidential informant. Just 1.2 percent of them fit that category. In 2006, she conducted a comprehensive study of all the leads generated from the content basket of Stellarwind between March 2004 and January 2006 and discovered that zero of those had been useful.

In an endnote, Savage then added:

The program was generating numerous tips to the FBI about suspicious phone numbers and e-mail addresses, and it was the job of the FBI field offices to pursue those leads and scrutinize the people behind them. (The tips were so frequent and such a waste of time that the field offices reported back, in frustration, “You’re sending us garbage.”)

This isn’t security, it’s security theater, and the victories it achieves are in battles between for budget money from Congress. 

Makes More Sense than a Mysterious Breakthrough in Mathematics

There have been a number of reports, some of which appear to have come from the NSA itself, that the secretive organization can decrypt what should be unbreakable codes.

It now appears that this is not some sort of mathematics breakthrough. Instead,a recent paper suggests the basic algorithm used for key exchange appear to be flawed.

They further suggest, and I agree, that the NSA is to some degree responsible for the ubiquity of this security flaw:

There have been rumors for years that the NSA can decrypt a significant fraction of encrypted Internet traffic. In 2012, James Bamford published an article quoting anonymous former NSA officials stating that the agency had achieved a “computing breakthrough” that gave them “the ability to crack current public encryption.” The Snowden documents also hint at some extraordinary capabilities: they show that NSA has built extensive infrastructure to intercept and decrypt VPN traffic and suggest that the agency can decrypt at least some HTTPS and SSH connections on demand.

However, the documents do not explain how these breakthroughs work, and speculation about possible backdoors or broken algorithms has been rampant in the technical community. Yesterday at ACM CCS, one of the leading security research venues, we and twelve coauthors presented a paper that we think solves this technical mystery.

The key is, somewhat ironically, Diffie-Hellman key exchange, an algorithm that we and many others have advocated as a defense against mass surveillance. Diffie-Hellman is a cornerstone of modern cryptography used for VPNs, HTTPS websites, email, and many other protocols. Our paper shows that, through a confluence of number theory and bad implementation choices, many real-world users of Diffie-Hellman are likely vulnerable to state-level attackers.

For the nerds in the audience, here’s what’s wrong: If a client and server are speaking Diffie-Hellman, they first need to agree on a large prime number with a particular form. There seemed to be no reason why everyone couldn’t just use the same prime, and, in fact, many applications tend to use standardized or hard-coded primes. But there was a very important detail that got lost in translation between the mathematicians and the practitioners: an adversary can perform a single enormous computation to “crack” a particular prime, then easily break any individual connection that uses that prime.

………

Based on the evidence we have, we can’t prove for certain that NSA is doing this. However, our proposed Diffie-Hellman break fits the known technical details about their large-scale decryption capabilities better than any competing explanation. For instance, the Snowden documents show that NSA’s VPN decryption infrastructure involves intercepting encrypted connections and passing certain data to supercomputers, which return the key. The design of the system goes to great lengths to collect particular data that would be necessary for an attack on Diffie-Hellman but not for alternative explanations, like a break in AES or other symmetric crypto. While the documents make it clear that NSA uses other attack techniques, like software and hardware “implants,” to break crypto on specific targets, these don’t explain the ability to passively eavesdrop on VPN traffic at a large scale.

Since weak use of Diffie-Hellman is widespread in standards and implementations, it will be many years before the problems go away, even given existing security recommendations and our new findings. In the meantime, other large governments potentially can implement similar attacks, if they haven’t already.

Our findings illuminate the tension between NSA’s two missions, gathering intelligence and defending U.S. computer security. If our hypothesis is correct, the agency has been vigorously exploiting weak Diffie-Hellman, while taking only small steps to help fix the problem. On the defensive side, NSA has recommended that implementors should transition to elliptic curve cryptography, which isn’t known to suffer from this loophole, but such recommendations tend to go unheeded absent explicit justifications or demonstrations. This problem is compounded because the security community is hesitant to take NSA recommendations at face value, following apparent efforts to backdoor cryptographic standards.

My money is on the NSA creating this problem, rather than it merely exploiting it.

Based on what I’ve read, it seems more consistent with the social norms of that organization.

Not a Surprise

Speaking of things that are now “Inoperative”, it appears that the it is no longer the policy of Her Majesty’s Secret Service to not spy on members of Parliament:

The Investigatory Powers Tribunal (IPT), the UK body that hears complaints about intelligence agencies, has ruled that the communications of MPs and peers are not protected by the Wilson Doctrine, which was thought to exempt them from surveillance by GCHQ and other intelligence agencies. Back in July, the UK government had already admitted that the Wilson Doctrine “cannot work sensibly” when mass surveillance is taking place, but today’s decision goes further by explicitly rejecting the idea of any formal immunity from spying.

As The Guardian explains: “The [Wilson] convention is named after former prime minister Harold Wilson, who pledged in 1966 that MPs’ and peers’ phones would not be tapped. In December 1997, the then prime minister Tony Blair said the doctrine extended to electronic communication, including emails.” In its judgment, the IPT wrote: “We are satisfied that the Wilson Doctrine is not enforceable in English law by the Claimants or other MPs or peers by way of legitimate expectation.” The IPT agreed it was “a political statement in a political context, encompassing the ambiguity that is sometimes to be found in political statements.”

………

One of the two Green party politicians who had brought the complaint to the IPT, MP Caroline Lucas, said after the ruling: “This judgement is a body blow for parliamentary democracy. My constituents have a right to know that their communications with me aren’t subject to blanket surveillance—yet this ruling suggests that they have no such protection. Parliamentarians must be a trusted source for whistleblowers and those wishing to challenge the actions of the Government.” She went on to call for new legislation providing protection to MPs, peers, Members of the Scottish Parliament, Welsh Assembly Members, and MEPs from extra-judicial spying.

Live in obedient fear, citizen.

Good News

Of course, if Europeans on the the TTIP trade deal, then the privacy ruling of the European High Court would go away:

Europe’s top court, the Court of Justice of the European Union (CJEU), has struck down the 15-year-old Safe Harbour agreement that allowed the free flow of information between the US and EU. The most significant repercussion of this ruling is that American companies, such as Facebook, Google, and Twitter, may not be allowed to send user data from Europe back to the US.

It’s important to note that the CJEU’s ruling (PDF) will not immediately prevent US companies from sending data back to the motherland. Rather, the courts in each EU member state can now rule that the Safe Harbour agreement is illegal in their country. It is is very unlikely, however, that a national court would countermand the CJEU’s ruling in this case.

The case was originally sent to the CJEU by the High Court of Ireland, after the Irish data protection authority rejected a complaint from Maximillian Schrems, an Austrian citizen. He had argued that in light of Snowden’s revelations about the NSA, the data he provided to Facebook that was transferred from the company’s Irish subsidiary to the US under the Safe Harbour scheme was not, in fact, safely harboured. Advocate General Yves Bot of the CJEU agreed with Schrems that the EU-US Safe Harbour system did not meet the requirements of the Data Protection Directive, because of NSA access to EU personal data.

According to an earlier CJEU statement (PDF), “the access enjoyed by the United States intelligence services to the transferred data constitutes an interference with the right to respect for private life and the right to protection of personal data, which are guaranteed by the [Charter of Fundamental Rights of the EU].” Another issue, according to the Advocate General, was “the inability of citizens of the EU to be heard on the question of the surveillance and interception of their data in the United States,” which therefore amounts to “an interference with the right of EU citizens to an effective remedy, protected by the Charter.”

Because the CJEU was ruling on an issue in Ireland, the Irish court is expected to make its own judgement shortly. It is likely that the Irish court will side with the CJEU. When that happens, one of two things will need to happen: Facebook, and many other US companies with Irish subsidiaries, will need to keep European data within the EU; or the US will need to provide real privacy protection for EU data when it flows back to the US. As the latter is unlikely due to pressure from the NSA and other intelligence agencies, we suspect most US companies will opt for the former.

If the TTIP, the trans-Atlantic version of the TPP, is adopted, all of these protections go away, because profits trump people under these deals.

In Addition to Being a True Patriot, Edward Snowden Is Wicked Cool

He just showed up in robot form on Neil Degrasse Tyson’s podcast to explain why we have not been contacted by aliens:

Whistle-blower Edward Snowden has some strong opinions on communications — even when those communications are coming from aliens.

The former intelligence-agency contractor turned fugitive was an unexpected guest on famous astrophysicist Neil deGrasse Tyson’s StarTalk podcast on September 18. And, inevitably, the two got to talking about extraterrestrials.

………

But Tyson scored an interview with him in New York City. How? Snowden rigged a robot that he can control from Russia, and rolled right into Tyson’s office at the Hayden Planetarium in New York with his face displayed on the screen.

The conversation turned to encryption and cybersecurity, but here’s where an astrophysicist differs from a journalist: Tyson’s line of questioning quickly turned to how encryption relates to communication with … aliens.

Tyson asked Snowden if a highly intelligent alien civilization might be communicating with encrypted messages. And Snowden had an unsettling answer.
First, Snowden said, let’s assume that most advanced societies eventually realize that they need to encrypt their communication in order to protect it. This could also be the reason why we’ve never heard from other civilizations — their messages may have just been melding into the background static of the universe.
Here’s Snowden’s full answer, from the StarTalk podcast:

So if you have an alien civilization trying to listen for other civilizations, or our civilization trying to listen for aliens, there’s only one small period in the development of their society when all of their communication will be sent via the most primitive and most unprotected means.
So when we think about everything that we’re hearing through our satellites or everything that they’re hearing from our civilization (if there are indeed aliens out there), all of their communications are encrypted by default.
So what we are hearing, that’s actually an alien television show or, you know, a phone call … is indistinguishable to us from cosmic microwave background radiation.

So it could be possible there are alien messages constantly hitting our satellites, and we just don’t recognize them because they’re so heavily encrypted. (The cosmic microwave background radiation that Snowden mentions is thermal radiation throughout the universe left over from the Big Bang. It basically looks and sounds like static to us puny humans.)

(emphasis original)

This is way cooler than I will ever be.

The Good Guy’s Win

A few days ago, I noted how law enforcement came down on a New Hampshire library for operating a TOR node.

Today, we earn that the West Lebanon library told the US state security apparatus to go pound sand:

The Kilton Public Library in West Lebanon will reactivate its piece of the anonymous internet browsing network Tor, despite law enforcement’s concerns that the network might be used for criminal activities.

The Lebanon Library Board of Trustees let stand its unanimous June decision to devote some of the library’s excess bandwidth to a node, or “relay,” for Tor, after a full room of about 50 residents and other interested members of the public expressed their support for Lebanon’s participation in the system at a meeting Tuesday night.

“With any freedom there is risk,” library board Chairman Francis Oscadal said. “It came to me that I could vote in favor of the good . . . or I could vote against the bad.

“I’d rather vote for the good because there is value to this.”

I haz a happy.

Live in Obedient Fear, Citizen

A small library in Lebanon, New Hampshire decided set up TOR on its network.

This was just shut down as a result of threats from the Department of Homeland Security:

Since Edward Snowden exposed the extent of online surveillance by the U.S. government, there has been a surge of initiatives to protect users’ privacy.

But it hasn’t taken long for one of these efforts — a project to equip local libraries with technology supporting anonymous Internet surfing — to run up against opposition from law enforcement.

In July, the Kilton Public Library in Lebanon, New Hampshire, was the first library in the country to become part of the anonymous Web surfing service Tor. The library allowed Tor users around the world to bounce their Internet traffic through the library, thus masking users’ locations.

Soon after state authorities received an email about it from an agent at the Department of Homeland Security.

“The Department of Homeland Security got in touch with our Police Department,” said Sean Fleming, the library director of the Lebanon Public Libraries.

After a meeting at which local police and city officials discussed how Tor could be exploited by criminals, the library pulled the plug on the project.

“Right now we’re on pause,” said Fleming. “We really weren’t anticipating that there would be any controversy at all.”

………

After Macrina conducted a privacy training session at the Kilton library in May, she talked to the librarian about also setting up a Tor relay, the mechanism by which users across the Internet can hide their identity.

The library board of trustees unanimously approved the plan at its meeting in June, and the relay was set up in July. But after ArsTechnica wrote about the pilot project and Macrina’s plan to install Tor relays in libraries across the nation, law enforcement got involved.

A special agent in a Boston DHS office forwarded the article to the New Hampshire police, who forwarded it to a sergeant at the Lebanon Police Department.

DHS spokesman Shawn Neudauer said the agent was simply providing “visibility/situational awareness,” and did not have any direct contact with the Lebanon police or library. “The use of a Tor browser is not, in [or] of itself, illegal and there are legitimate purposes for its use,” Neudauer said, “However, the protections that Tor offers can be attractive to criminal enterprises or actors and HSI [Homeland Security Investigations] will continue to pursue those individuals who seek to use the anonymizing technology to further their illicit activity.”

When the DHS inquiry was brought to his attention, Lt. Matthew Isham of the Lebanon Police Department was concerned. “For all the good that a Tor may allow as far as speech, there is also the criminal side that would take advantage of that as well,” Isham said. “We felt we needed to make the city aware of it.”

For those who don’t speak the language of law enforcement threats, “Needed to make the city aware of it,” means, “Threatening to link public officials to child porn.”

The action taken by the library is legal, and is very much in the tradition of libraries promoting the free exchange of information, but the US state security apparatus cannot tolerate this, even though the US government is the largest single funder of this network.

Belay that Upgrade to Windows 10

No verification yet, but there has been a semi credible report that Microsoft’s new operating system is literally sending everything you do to the Redmond Borg:

Note: Some readers have commented that the original source for the article is of questionably validity. If anyone can confirm or refute the original author’s finding with actual data, please let me know in the comments, and I’ll update this post accordingly.

Some Czech guy did a traffic analysis of data produced by Windows 10, and released his findings the other day. His primary thesis was that Windows 10 acts more like a terminal than an operating system — because of the extent of the “cloud” integration, a large portion of the OS functions are almost dependent on remote (Microsoft’s) servers. The amount of collected information, even with strict privacy settings, is quite alarming.

Information transmitted

All text typed on the keyboard is stored in temporary files, and sent (once per 30 mins) to:

oca.telemetry.microsoft.com.nsatc.net
pre.footprintpredict.com
reports.wes.df.telemetry.microsoft.com

There isn’t a clear purpose for this, considering there there’s no autocorrect/prediction anywhere in the OS (There is autocorrect in certain text fields, but the supposed purpose for transmitting these keystrokes is to improve autocorrect across devices. Whether a full keylog is necessary for this (as opposed to just corrections) is questionable. Furthermore, this appears to still occur even if the user is not signed in to a Microsoft account, eliminating the “across devices” benefit. Perhaps there is a global autocorrect dictionary that benefits all users, but the privacy implications of an un-disableable always-on keylogger outweigh these potential benefits.). The implications of this are significant: because this is an OS-level keylogger, all the data you’re trying to transmit securely is now sitting on some MS server. This includes passwords and encrypted chats. This also includes the on-screen keyboard, so there is no way to authenticate to a website without MS also getting your password.

………

………In another example, typing the name of any popular movie into your local file search starts a telemetry process that indexes all media files on your computer and transmits them to:  ………

………

It’s hard to imagine any purpose for this other than the obvious piracy crackdown possibilities.

When a webcam is first enabled, ~35mb of data gets immediately transmitted to: 

………

Everything that is said into an enabled microphone is immediately transmitted to: 

………

If this weren’t bad enough, this behaviour still occurs after Cortana is fully disabled/uninstalled. It’s speculated that the purpose of this function to build up a massive voice database, then tie those voices to identities, and eventually be able to identify anyone simply by picking up their voice, whether it be a microphone in a public place or a wiretap on a payphone. 

……… 

While the inital reflex may be to block all of the above servers via HOSTS, it turns out this won’t work: Microsoft has taken the care to hardcode certain IPs, meaning that there is no DNS lookup and no HOSTS consultation. However, if the above servers are blocked via HOSTS, Windows will pretend to be crippled by continuously throwing errors, while still maintaining data collection in the background. Other than an increase in errors, HOSTS blocking did not affect the volume, frequency, or rate of data being transmitted. 

So it appears that Microsoft does key-logging under Win 10, which means that they have your password, they phone home with your media files, meaning that the RIAA and MPAA can go after you for your bootlegs, and they have created a voice profile, so that the NSA can listen to you when they recognize your voice..

Again, this is preliminary, but if half of this is true, my next computer will be a Linux box.

So, We Had 2 Days of NSA Free Phone Calls………

The Senate just passed “the USA Freedom Act”.

It provides some (remarkably tepid) reforms to our overweening security state, and Mitch McConnell fought like hell to prevent these and lost:

Congress just passed NSA reform. Here’s how Mitch McConnell tried—and failed—to thwart it.

The USA Freedom Act, the bill that reforms the Patriot Act and stops the US government’s bulk collection of phone records, finally passed the Senate on Tuesday after the chamber rejected three amendments from GOP Majority Leader Mitch McConnell (R-Ky.) aimed at weakening the bill’s reforms.

McConnell originally supported leaving the Patriot Act with all of its surveillance powers intact, but he faced resistance from both Democrats and Republicans, including die-hards such as Sen. Rand Paul (R-Ky.) who were happy to let bulk collection simply disappear without creating a replacement. So McConnell agreed to proceed with the USA Freedom Act, but proposed four amendments to address what he called the bill’s “serious flaws .” (He withdrew one of them.)

Harley Geiger, chief counsel of the Center for Democracy and Technology, called McConnell’s amendments “unnecessary for national security” and said that they would “erode both privacy and transparency.”

The Senate agreed, rejecting the three amendments that came to a vote on Tuesday afternoon. McConnell’s proposed changes would have:
Delayed the shutdown of bulk collection: The USA Freedom Act calls for bulk collection to shut down within six months of the law’s passage. One of McConnell’s amendments would have stretched that out to a full year.

Kept arguments before the FISA court a one-sided affair: The FISA court reviews—and essentially always approves—requests for surveillance from government agencies. Its business is classified, and the only arguments presented are by government lawyers. The USA Freedom Act establishes a panel of experts to argue privacy concerns before the court, a move that one of McConnell’s amendments would have tried to limit.

Offered a potential backdoor for anti-reform efforts: Under the USA Freedom Act, bulk collection will be replaced by a “query-based” system, in which intelligence agencies would have to ask phone companies for records. That will take place six months after the bill is signed into law, but McConnell wanted to make the attorney general certify one month before the end of bulk collection that the new system would not harm national security. That may have given anti-reform lawmakers a final chance to scuttle the USA Freedom Act if the attorney general’s certification didn’t happen, or even raised any concerns at all.

McConnell got a lose, but I would have preferred that nothing at all got passed, which would have been the best possible outcome.

I guess that I will have to be satisfied by McConnel’s loss.

Thank You Rand Paul*

It turns out that, at least for the next few hours, some significant portions of the Patriot Act have expired:

The Senate failed to pass legislation late Sunday to extend three Patriot Act surveillance measures ahead of their midnight expiration. The National Security Agency’s bulk telephone metadata collection program—first exposed by Edward Snowden in 2013—is the most high profile of the three spy tools whose legal authorization expired.

President Barack Obama was set to sign the bill, the USA Freedom Act, ahead of the midnight Sunday deadline. But Senate lawmakers who convened in a special session at 4pm ET Sunday could not reach an accord. The Senate is to resume debate Monday at noon ET.

As expected, there was much banter back and forth on the Senate floor about whether the Constitution was being gutted or whether the country would come to ruins if the Senate did not quickly adopt the already approved House legislation ahead of the June 1 expiration deadline. (The three Patriot Act provisions that failed to pass the Senate were renewed days ago in the House through 2019.)

“Are we willing to trade liberty for security?” asked Sen. Rand Paul (R-KY), perhaps the most vocal opponent of the legislation. Despite an apparent victory, Paul had no illusions that this fight for privacy would end after these specific extension talks. “The Patriot Act will expire tonight, but it will only be temporary,” he added.

………

The three Patriot Act provisions on the agenda would have been extended until 2019 if approved. The first concerns the so-called “business records” provision that enabled the NSA’s bulk telephone metadata program brought to light by the Snowden disclosures. This provision granted the government the power to seize all types of records—including those surrounding health and banking. The authorities must assert to the secret Foreign Intelligence Surveillance Act Court (FISA Court) that they are “relevant” to a terrorism investigation before getting a warrant. The bulk metadata collection program was altered somewhat under the House and Senate legislation, however.

I expect this victory to be short lived, but even this temporary and largely symbolic setback for the overweening security state heartens me a bit.

*I f%$#ing cannot f%$#ing believe that I f%$#ing just f%$#ing said that non-ironically.

The Program that Edward Snowden Leaked was Ilegal*

A federal appeals court in New York ruled on Thursday that the once-secret National Security Agency program that is systematically collecting Americans’ phone records in bulk is illegal. The decision comes as a fight in Congress is intensifying over whether to end and replace the program, or to extend it without changes.

In a 97-page ruling, a three-judge panel for the United States Court of Appeals for the Second Circuit held that a provision of the U.S.A. Patriot Act, known as Section 215, cannot be legitimately interpreted to allow the bulk collection of domestic calling records.

The provision of the act used to justify the bulk data program is to expire June 1, and the ruling is certain to increase tension that has been building in Congress.

………

The ruling puts new pressure on Senator Mitch McConnell of Kentucky, the majority leader, to make serious changes to the Patriot Act, which he has so far aggressively defended against any alteration, even as recently as Thursday on the Senate floor. Mr. McConnell has pressed to maintain the N.S.A.’s existing program against bipartisan efforts to scale it back, and has proposed simply extending the statute by the June 1 deadline.

But the court’s ruling calls into question whether that statute can still be used to issue new orders to phone companies requiring them to turn over their customers’ records.

Thursday’s ruling is the first time a higher-level court in the regular judicial system has reviewed the N.S.A. phone records program. It did not come with any injunction ordering the program to cease, and it is not clear that anything else will happen in the judicial system before Congress has to make a decision about the expiring law.

The data collection had repeatedly been approved in secret by judges serving on the Foreign Intelligence Surveillance Court, known as the FISA court, which oversees national security surveillance. Those judges, who hear arguments only from the government, were willing to accept an interpretation of Section 215 that the appeals court rejected on Thursday.

………

But the appeals court ruling raises the question of whether Section 215, extended or not, has ever legitimately authorized the program. The statute on its face permits only the collection of records deemed “relevant” to a national security case. The government secretly decided, with the FISA court’s secret approval, that this could be interpreted to mean collection of all records, so long as only those that later turn out to be relevant are scrutinized by analysts.

However, Judge Lynch wrote: “Such expansive development of government repositories of formerly private records would be an unprecedented contraction of the privacy expectations of all Americans. Perhaps such a contraction is required by national security needs in the face of the dangers of contemporary domestic and international terrorism. But we would expect such a momentous decision to be preceded by substantial debate, and expressed in unmistakable language.”

So, the NSA argued that bulk collection of data is legal because it might be used at some later date for a national security case, and FISA court, which needs to be kept away from toilet paper, because they will sign anything, agreed.

Thankfully, the appellate court rightly called bullsh%$ on this.

Scott Lemieux read the full opinion (it is rather encyclopedic), and gives us these quotes from the opinion:

…the parties have not undertaken to debate whether the records required by the orders in question are relevant to any particular inquiry. The records demanded are all‐encompassing; the government does not even suggest that all of the records sought, or even necessarily any of them, are relevant to any specific defined inquiry…

………

Thus, the government takes the position that the metadata collected – a vast amount of which does not contain directly “relevant” information, as the government concedes – are nevertheless “relevant” because they may allow the NSA, at some unknown time in the future, utilizing its ability to sift through the trove of irrelevant data it has collected up to that point, to identify information that is relevant. We agree with appellants that such an expansive concept of “relevance” is unprecedented and unwarranted.

………

To the extent that § 215 was intended to give the government, as Senator Kyl proposed, the “same kinds of techniques to fight terrorists” that it has available to fight ordinary crimes such as “money laundering or drug dealing,” the analogy is not helpful to the government’s position here. The techniques traditionally used to combat such ordinary crimes have not included the collection, via grand jury subpoena, of a vast trove of records of metadata concerning the financial transactions or telephone calls of ordinary Americans to be held in reserve in a data bank, to be searched if and when at some hypothetical future time the records might become relevant to a criminal investigation.

………

Such expansive development of government repositories of formerly private records would be an unprecedented contraction of the privacy expectations of all Americans. Perhaps such a contraction is required by national security needs in the face of the dangers of contemporary domestic and international terrorism. But we would expect such a momentous decision to be preceded by substantial debate, and expressed in unmistakable language. There is no evidence of such a debate in the legislative history of § 215, and the language of the statute, on its face, is not naturally read as permitting investigative agencies, on the approval of the FISC, to do any more than obtain the sorts of information routinely acquired in the course of criminal investigations of “money laundering [and] drug dealing.”

That’s going to leave a mark.

Given Obama’s record on such privacy and 4th amendment protections, I imagine that is already on the phone with Mitch McConnell in an attempt to expand the NSA’s powers.

*Technically, it might be unlawful, rather than illegal, but that is not the important part here. Besides, I am an engineer, not a lawyer, dammit!

I love it when I get to go all Dr. McCoy!

Quote of the Day

Almost every major terrorist attack on Western soil in the past fifteen years has been committed by people who were already known to law enforcement. One of the gunmen in the attack on Charlie Hebdo, in Paris, had been sent to prison for recruiting jihadist fighters. The other had reportedly studied in Yemen with Umar Farouk Abdulmutallab, the underwear bomber, who was arrested and interrogated by the F.B.I. in 2009. The leader of the 7/7 London suicide bombings, in 2005, had been observed by British intelligence meeting with a suspected terrorist, though MI5 later said that the bombers were “not on our radar.” The men who planned the Mumbai attacks, in 2008, were under electronic surveillance by the United States, the United Kingdom, and India, and one had been an informant for the Drug Enforcement Administration. One of the brothers accused of bombing the Boston Marathon was the subject of an F.B.I. threat assessment and a warning from Russian intelligence.

—Mattathias Schwartz, writing in The New Yorker

That’s just the first paragraph.

The NSA wants to collect everything, but they already are collecting more than they need.

F%$# Uber, Part Infinity

We now have a report of a person who had a job interview with Uber, and was granted the ability to view the complete travel history of any Uber Customer:

………

Now add that all this location data was not held by a battle-hardened company with tons of lawyers and security experts, such as Google. Instead, this data was held by a start-up that was growing with viral exuberance – and with so few privacy protections that it created a “God View” to display the movements of riders in real-time and at least once projected such information on a screen for entertainment at a company party.

And let’s not forget that individual employees could access historical data on the movements of particular people without their permission, as an Uber executive in New York City reportedly did when he pulled the travel records of a Buzzfeed reporter who was working on a story about the company.

………

Then there are the personal travels of government officials and their families. A person who had a job interview in Uber’s Washington office in 2013 said he got the kind of access enjoyed by actual employees for an entire day, even for several hours after the job interview ended. He happily crawled through the database looking up the records of people he knew – including a family member of a prominent politician – before the seemingly magical power disappeared.

“What an Uber employee would have is everything, complete,” said this person, who spoke on the condition of anonymity for fear of retribution from the company.

I can see how the employee would fear retribution.

The CEO is an Ayn Rand loving sociopath, and he, almost any employee at the central office, or an enterprising hacker, can pull up your travel history.

How do you know that some tabloid reporter doesn’t have an Uber employee on their payroll?

What Emptywheel Says

Journalist, and internet deity on privacy and national security, Marcy Wheeler explains whyshe is opposed to the latest attempt to reign in government spying, the USA Freedom Act (USAF).

Basically it comes down to the fact that neither the state security apparatus, who are operating under legal opinions that are classified, nor Barack Obama, who has kept those legal opinions from the public, can be trusted not to take an absolutely maximalist approach to any possible loopholes under any regulatory regime, and this bill is full of loopholes.  Here are her section headings:

  • No one will say how the key phone record provision of the bill will work
  •  USAF negotiates from a weak position and likely moots potentially significant court gains 
  • USAF’s effects in limiting bulk collection are overstated
  • USAF would eliminate any pushback from providers
  • USAF may have the effect of weakening existing minimization procedures
  • USAF’s transparency provisions are bullsh%$
  • Other laudable provisions — like the Advocate — will easily be undercut

Basically, any bill that is not passed over strenuous opposition from the Worst Constitutional Law Professor ever will be meaningless.

If Obama supports it, it will be an expansion of the surveillance state.

Read the whole thing.  It’s worth it.

Well, This is Just Ducky

It appears that some ISPs are stripping the encryption out of their user’s email, even when connecting to outside servers:

Recently, Verizon was caught tampering with its customer’s web requests to inject a tracking super-cookie. Another network-tampering threat to user safety has come to light from other providers: email encryption downgrade attacks. In recent months, researchers have reported ISPs in the US and Thailand intercepting their customers’ data to strip a security flag—called STARTTLS—from email traffic. The STARTTLS flag is an essential security and privacy protection used by an email server to request encryption when talking to another server or client.1

By stripping out this flag, these ISPs prevent the email servers from successfully encrypting their conversation, and by default the servers will proceed to send email unencrypted. Some firewalls, including Cisco’s PIX/ASA firewall do this in order to monitor for spam originating from within their network and prevent it from being sent. Unfortunately, this causes collateral damage: the sending server will proceed to transmit plaintext email over the public Internet, where it is subject to eavesdropping and interception.

This type of STARTTLS stripping attack has mostly gone unnoticed because it tends to be applied to residential networks, where it is uncommon to run an email server2. STARTTLS was also relatively uncommon until late 2013, when EFF started rating companies on whether they used it. Since then, many of the biggest email providers implemented STARTTLS to protect their customers. We continue to strongly encourage all providers to implement STARTTLS for both outbound and inbound email. Google’s Safer email transparency report and starttls.info are good resources for checking whether a particular provider does.

STARTTLS is not a particularly strong, but it does filter out metadata like addresses and subjects.

What was (when discovered, the ISP in question, AIO Wireless, stopped doing this) is all about is an attempt to resell user data, or serve ads to the users.

As the good folks at Golden Frog observe:

Neither the old or the new proposed Internet rules being debated by the FCC would stop wireless providers from blocking encryption technologies. That is very frustrating and one of the key points in our FCC filing. The FCC is a government organization and tasked with protecting national security when it comes to electronic communications. They are part of the same government that surveils its citizens. It’s not unreasonable to think they are getting pressure to curtail encryption.

Furthermore, ISPs have incentive to block privacy technologies like VPNs. They want to profit as much as possible from the way you use the Internet. Privacy services that are independent of their offerings don’t allow them to do that. If they aren’t selling the service to you, they aren’t making money and that frustrates them. However, when they are blocking privacy services, they are dangerously putting businesses’ confidential communications and individual customers’ privacy at risk.

We strongly believe that the same Open Access rules that should apply to wired Internet providers should also apply to mobile Internet providers, especially considering this specific encryption-related incident that affects online privacy.

Unfettered free market capitalism ……… Gotta love it.

H/T naked capitalism.

I Have to Give an A for Inventiveness

The European Union has classified spyware as a restricted item requiring an export license, much like weapons:

Companies which make spyware will have to apply for permission to export the software once new EU regulations come into effect in late December.

Officially referred to as “intrusion software”, the software will now be included on the EU’s list of “dual use” items, defined as “goods, software and technology normally used for civilian purposes but which might have military applications or contribute to the proliferation of weapons of mass destruction.”

The restriction means that companies will have to apply for a licence to export spyware, although it doesn’t affect the sale of the software within the UK. Inclusion on the dual-use list places the technology alongside nuclear reactors, ultra-high-resolution cameras, and rocket fuel.

While the regulation is implemented by the European commission, the British government supports the restriction of spyware. “The UK has made it clear over the last two years that we believe that while these kind of technologies do have legitimate uses, they also pose threats to national security and to human rights and should be subject to export controls,” said a spokesperson for the Department for Business, Innovation and Skills.

Hopefully, this the export of such software to repressive regimes, as FinFisher did with its FinFish spyware, which it probably exported to Egypt, Bahrain, Ethiopia, etc.

Additionally, I hope that it will serve to also restrict the use of such programs by commercial entities.

Things like tracking cookies, and Verizon’s new “super cookies”, should be included in this category.

Worst Constitutional Law Professor, Ever

Note that FBI Director James Comey was specifically chosen by Barack Obama, and the President’s behavior to this point has indicated a strong bias toward the position that, “You don’t need to worry about privacy if you have nothing to hide.”

Thus I see Comey’s request for sabotaging the security of computers and mobile devices by requiring back doors to be a position explicitly supported by the whole administration, and as the saying goes, the Cossacks work for the Czar:

FBI Director James Comey has launched a new “crypto war” by asking Congress to update a two-decade-old law to make sure officials can access information from people’s cellphones and other communication devices.

The call is expected to trigger a major Capitol Hill fight about whether or not tech companies need to give the government access to their users’ data.

“It’s going to be a tough fight for sure,” Rep. James Sensenbrenner (R-Wis.), the Patriot Act’s original author, told The Hill in a statement.

He argues Apple and other companies are taking the privacy of consumers into their own hands because Congress has failed to pass legislation in response to public anger over the National Security Agency’s surveillance programs.

“While Director Comey says the pendulum has swung too far toward privacy and away from law enforcement, he fails to acknowledge that Congress has yet to pass any significant privacy reforms,” he added. “Because of this failure, businesses have taken matters into their own hands to protect their consumers and their bottom lines.”

“If this becomes the norm, I suggest to you that homicide cases could be stalled, suspects walked free, child exploitation not discovered and prosecuted,” he said last week.

Comey is asking that Congress update the Communications Assistance for Law Enforcement Act (CALEA), a 1994 law that required telephone companies to make it possible for federal officials to wiretap their users’ phone calls.

It’s a back door, much like the infamous Clipper chip, and the greatest effect of such a change would be to allow cyber-criminals to access your data, your machines, and your identity, because if they cripple security in the interest of law enforcement, criminals will avail themselves to the same technology.

On the Way Out the Door, Eric Holder Goes After Our Privacy ……… Again

For the gazillianth time, he’s seeking the crippling of computer security and privacy system with a back door for law enforcement:

Attorney General Eric Holder, the US top law enforcement official, said it is “worrisome” that tech companies are providing default encryption on consumer electronics. Locking the authorities out of being able to physically access the contents of devices puts children at risk, he said.

“It is fully possible to permit law enforcement to do its job while still adequately protecting personal privacy,” Holder said during a Tuesday speech before the Global Alliance Against Child Sexual Abuse Online conference. “When a child is in danger, law enforcement needs to be able to take every legally available step to quickly find and protect the child and to stop those that abuse children. It is worrisome to see companies thwarting our ability to do so.”

Holder’s remarks, while he did not mention any particular company by name, come two weeks after Apple announced its new iPhone 6 models would be equipped with data encryption that prevents authorities from accessing the contents of the phone. At the same time, Google said its upcoming Android operating system will also have default encryption.

The encryption decision by two of the world’s biggest names in tech is a bid to gain the trust of customers in the wake of the Edward Snowden surveillance revelations.

Holder said he wants a backdoor to defeat encryption. He urged the tech sector “to work with us to ensure that law enforcement retains the ability, with court-authorization, to lawfully obtain information in the course of an investigation, such as catching kidnappers and sexual predators.”

Mr. Holder, I need to explain something to you, and I will talk slowly.

A backdoor is a security hole, and once you create a security hole, it can be used by anyone.

You are asking every American citizen to make their systems less secure for your convenience.

This is a very bad idea.

If We Can’t Jail John Brennan, Can We Please Fire Him?


Remember when Congressional staffers accused the CIA?

Remember when John Brennan went on the Sunday shows and categorically denied it?

Rather unsurprisingly, John Brennan was lying through his teeth:

I don’t want to understate how seriously wrong it is that the CIA searched Senate computers. Our constitutional order is seriously out of whack when the executive branch acts with that kind of impunity — to its overseers, no less.

But given everything else that’s been going on lately, the single biggest — and arguably most constructive — thing to focus on is how outrageously CIA Director John Brennan lied to everyone about it.

“As far as the allegations of the CIA hacking into Senate computers, nothing could be further from the truth,” Brennan told NBC’s Andrea Mitchell in March. “We wouldn’t do that. I mean, that’s just beyond the, you know, the scope of reason in terms of what we do.”

Earlier, he had castigated “some members of the Senate” for making “spurious allegations about CIA actions that are wholly unsupported by the facts.” He called for an end to “outbursts that do a disservice to the important relationship that needs to be maintained between intelligence officials and Congressional overseers.”

And what compelled Senate intelligence committee chairwoman Dianne Feinstein to make a dramatic floor speech in the first place, bringing everything out in the open, was that Brennan had responded to her initial concerns not by acknowledging the CIA’s misconduct — but by firing back with an allegation of criminal activity by her own staff.

Not coincidentally, the document the CIA was hunting for, that Senate staffers were accused of purloining, and that Brennan was now lying about, was a big deal precisely because it exposed more lies.

Senator Mark UDall has called for Brennan’s resignation, but seeing as how DNI James Clapper lied under oath to Congress without consequence, I believe that Brennan’s current gig is secure.

As I have noted before, “The Cossacks work for the Czar.”

The fish rots from the head.