Category: Privacy

Live in Obedient Fear, Citizen

It looks like the Feds are probably responsible for hacking an online anonymity service:

Security researchers tonight are poring over a piece of malicious software that takes advantage of a Firefox security vulnerability to identify some users of the privacy-protecting Tor anonymity network.

The malware showed up Sunday morning on multiple websites hosted by the anonymous hosting company Freedom Hosting. That would normally be considered a blatantly criminal “drive-by” hack attack, but nobody’s calling in the FBI this time. The FBI is the prime suspect.

“It just sends identifying information to some IP in Reston, Virginia,” says reverse-engineer Vlad Tsyrklevich. “It’s pretty clear that it’s FBI or it’s some other law enforcement agency that’s U.S.-based.”

If Tsrklevich and other researchers are right, the code is likely the first sample captured in the wild of the FBI’s “computer and internet protocol address verifier,” or CIPAV, the law enforcement spyware first reported by WIRED in 2007.

………

By midday Sunday, the code was being circulated and dissected all over the net. Mozilla confirmed the code exploits a critical memory management vulnerability in Firefox that was publicly reported on June 25, and is fixed in the latest version of the browser.

Though many older revisions of Firefox are vulnerable to that bug, the malware only targets Firefox 17 ESR, the version of Firefox that forms the basis of the Tor Browser Bundle – the easiest, most user-friendly package for using the Tor anonymity network.

“The malware payload could be trying to exploit potential bugs in Firefox 17 ESR, on which our Tor Browser is based,” the non-profit Tor Project wrote in a blog post Sunday. “We’re investigating these bugs and will fix them if we can.”

The inevitable conclusion is that the malware is designed specifically to attack the Tor browser. The strongest clue that the culprit is the FBI, beyond the circumstantial timing of Marques’ arrest, is that the malware does nothing but identify the target.

Anyone want to guess who is behind this?

Whoever is ultimately behind this, it’s been farmed out to a contractor, “According to Domaintools, the malware’s command-and-control IP address in Virginia is allocated to Science Applications International Corporation. Based in McLean, Virginia, SAIC is a major technology contractor for defense and intelligence agencies, including the FBI.” (SAIC refused comment)

SAIC isn’t doing this on its own.  Someone in the government is paying them to do this.

As  to whether or not there is a court order authorizing the FBI to plant malware on thousands of people’s machines, possibly, but we will never know, since it is almost certainly been finessed through the FISA court somehow..

Linkage

Three men deny Oompa Loompas attack The Guardian (I feel bad for laughing)
NSA Director Heckled at Blackhat computer hacker conference. Forbes
Ted Cruz Still Needs to Be Ditched: The Rude Pundit (Must read)
New York Times editors cut Obama a new one over secrecy. (I think that the persecution prosecution of James Risen may have pissed them off)
Obama Starting to Lose It Over Snowden Naked Capitalism (also must read)
Bubble Alert!! Morgan Stanley predicts buy-to-rent boom (HousingWire)

Pic H/t Police the Police

Linkage

Libertarian Paradise:

We Lose

The House has narrowly rejected an amendment to the Defense Authorization Bill to restrict NSA spying on Americans:

U.S. lawmakers angry about domestic telephone record-collection lost an effort to curtail funding for the intelligence-gathering tools revealed by fugitive U.S. security contractor Edward Snowden.

On a vote of 205-217, the House rejected an amendment that would have limited the National Security Agency’s ability to collect communications records.

Implementation of the amendment could have created a new burden on telephone and Internet companies to retain bulk data, in addition to ending the NSA’s blanket collection of phone records. Those possibilities led the White House, Republicans leaders and many congressional Democrats to oppose the proposals, pitting them against lawmakers from both parties who champion civil liberties and privacy.

The by-party tally is Democrats  (111-83), and Republicans (94-134), a 5 vote margin, and it is almost certainly only because Obama started seriously twisting arms on the Dem side of the aisle in the past 48 hours or so.  (My rep, John Sarbanes, voted yes).

Hopefully, this is only the start of the fight, and the next time, the good guys will pick up a few more votes, and win.

Obama Continues to Spy on Ordinary Americans

They just got a 3 month extension of its data drift net of Verizon, and one would assume everyone else too:

The National Security Agency has been allowed to extend its dragnet of the telephone records of millions of US customers of Verizon through a court order issued by the secret court that oversees surveillance.

In an unprecedented move prompted by the Guardian’s disclosure in June of the NSA’s indiscriminate collection of Verizon metadata, the Office of the Director of National Intelligence (ODNI) has publicly revealed that the scheme has been extended yet again.

The statement does not mention Verizon by name, nor make clear how long the extension lasts for, but it is likely to span a further three months in line with previous routine orders from the secret Foreign Intelligence Surveillance Court (Fisa).

The announcement flowed, the statement said, from the decision to declassify aspects of the metadata grab “in order to provide the public with a more thorough and balanced understanding of the program”.

According to Democratic senator Dianne Feinstein, the Verizon phone surveillance has been in place – updated every three months – for at least six years, and it is understood to have been applied to other telecoms giants as well.

Not feeling hopey changey here.

Well Duh!

The Washington Post notes that, “Lawmakers say administration’s lack of candor on surveillance weakens oversight.”

Gee, you think?

Lawmakers tasked with overseeing national security policy say a pattern of misleading testimony by senior Obama administration officials has weakened Congress’s ability to rein in government surveillance.

Members of Congress say officials have either denied the existence of a broad program that collects data on millions of Americans or, more commonly, made statements that left some lawmakers with the impression that the government was conducting only narrow, targeted surveillance operations.

The most recent example came on March 12, when James R. Clapper, director of national intelligence, told the Senate Intelligence Committee that the government was not collecting information about millions of Americans. He later acknowledged that the statement was “erroneous” and apologized, citing a misunderstanding.

“Misunderstanding,” my ass.

Clapper was given a day’s notice that the question was going to be asked, and he was given an opportunity to further clarify immediately after the fact.

He simply lied, because he knew that he could.

DuckDuckGo

I’ve used the search engine DuckDuckGo now and again, and now the search engine, which does not record data on its users, has experienced a surge in use following the NSA revelations:

Gabriel Weinberg noticed web traffic building on the night of Thursday 6 June – immediately after the revelations about the “Prism” programme. Through the programme, the US’s National Security Agency claimed to have “direct access” to the servers of companies including, crucially, the web’s biggest search engines – Google, Microsoft and Yahoo.

Within days of the story, while the big companies were still spitting tacks and tight-lipped disclaimers, the search engine Weinberg founded – which pledges not to track or store data about its users – was getting 50% more traffic than ever before. That has gone up and up as more revelations about NSA and GCHQ internet tapping have come in.

“It happened with the release by the Guardian about Prism,” says Weinberg, right, a 33-year-old living in Paoli, a suburb of Philadelphia on the US east coast. “We started seeing an increase right when the story broke, before we were covered in the press.” From serving 1.7m searches a day at the start of June, it hit 3m within a fortnight.

Yet you’ve probably never heard of DuckDuckGo. “If you asked 100 people, 96 would probably think it was a Chinese restaurant,” as the SFGate site observed. (The name comes from the children’s game DuckDuckGoose, a sort of tag involving seated players.) You won’t find it offered as an alternative default search engine on any browser, on desktop or mobile. Using it is very definitely an active choice, whereas using Google is the default option on most browsers. And 95% of people never change the default settings on anything.

But this 20-person business offers what none of the big search engines do: zero tracking. It doesn’t use cookies or store data about its users’ IP addresses, doesn’t offer user logins, and uses an encrypted connection by default. (Google provides an encrypted connection for logged-in users, but not automatically for non-logged in users.) If the NSA demanded data from DuckDuckGo, there would be none to hand over.

Seeing as how Google (full disclosure, they do cut me a check occasionally for the ads they serve on this site) is determined to drop the word “Don’t” from their motto, “Don’t be evil,” I do wish them all the success in the world.

Former FISA Judge Criticizes the Court

Well, now we have a retired FISA Court Judge saying this court has been reduced to a joke and a fraud:

A retired judge who once served on a secretive U.S. intelligence court said on Tuesday it should not be able to approve broad government data-gathering requests without hearing from outside parties who could warn of potential civil liberties concerns.

Currently, the Foreign Intelligence Surveillance Court makes its decisions on government surveillance requests without hearing from anyone but U.S. Justice Department lawyers in its behind-closed-doors proceedings.

James Robertson, a retired federal judge in Washington who served on the court for three years ending in 2005, said that if the court is required to approve broad data-collection programs, the judges should be able to hear from other parties.

Speaking at a public meeting in Washington on privacy and civil liberties, he said the process would work better if some approximation of an adversarial system existed.

“I submit this process needs an adversary,” he said.

Robertson suggested the possible reforms during the public meeting held by the Privacy and Civil Liberties Oversight Board, a bipartisan government entity set up in 2004 to advise the White House on civil liberties concerns raised by intelligence gathering. He said the privacy board itself could possibly be a party in the intelligence court’s proceedings.

The actions of the court have come under new scrutiny following the disclosure of previously secret telephone and internet surveillance programs conducted by the U.S. government.

The British Guardian and the Washington Post newspapers disclosed the details of the data collection in June based on documents provided by Edward Snowden, the fugitive U.S. National Security Agency contractor believed to be holed up in Russia.

Since the U.S. Congress amended the 1978 Foreign Intelligence Surveillance Act (FISA) in 2008, the court “now approves programmatic surveillance,” Robertson said, meaning it was acting more like a government agency than a court.

“That’s not the bailiwick of judges,” he said. “Judges don’t make policy.”

Robertson said that when he served on the court, the judges’ role was to decide whether to grant government requests for individual warrants, he said. Granting approval to entire programs is not a “judicial function,” he said.

(emphasis mine)

While he does say that he is not suggesting the law is being broken, this sort of talk from a judge about his court (with the possible exception of Antonin “Fat Tony” Scalia) is very rare.

Note also that he is not criticizing the judges, he is criticizing the role of the court under new laws.

Understanding just how vehement this seemingly mild speech is a bit like reading Nathanial Hawthorne,* he cannot express his outrage explicitly.  It is a circuitously oblique way to to express his views, but this is as befits a judge.

*The phrase, “Then, all was spoken!” refers to physical passion (probably sex) in The Scarlet Letter.

And in the Further Adventures of Epic Fails: NSA Edition

Chinese artist and dissident Ai Weiwei, talking about the NSA telephone drift net says that the US is behaving like China:

Even though we know governments do all kinds of things I was shocked by the information about the US surveillance operation, Prism. To me, it’s abusively using government powers to interfere in individuals’ privacy. This is an important moment for international society to reconsider and protect individual rights.

I lived in the United States for 12 years. This abuse of state power goes totally against my understanding of what it means to be a civilised society, and it will be shocking for me if American citizens allow this to continue. The US has a great tradition of individualism and privacy and has long been a centre for free thinking and creativity as a result.

In our experience in China, basically there is no privacy at all – that is why China is far behind the world in important respects: even though it has become so rich, it trails behind in terms of passion, imagination and creativity.

Read the rest.

Surrender Your Privacy for the Good of the State Comrade

The good folks at the Orwellian named Department of Homeland security has decided that they can seize and search your electronics without cause:

The Department of Homeland Security’s civil rights watchdog has concluded that travelers along the nation’s borders may have their electronics seized and the contents of those devices examined for any reason whatsoever — all in the name of national security.

The DHS, which secures the nation’s border, in 2009 announced that it would conduct a “Civil Liberties Impact Assessment” of its suspicionless search-and-seizure policy pertaining to electronic devices “within 120 days.” More than three years later, the DHS office of Civil Rights and Civil Liberties published a two-page executive summary of its findings.

“We also conclude that imposing a requirement that officers have reasonable suspicion in order to conduct a border search of an electronic device would be operationally harmful without concomitant civil rights/civil liberties benefits,” the executive summary said.

The memo highlights the friction between today’s reality that electronic devices have become virtual extensions of ourselves housing everything from e-mail to instant-message chats to photos and our papers and effects — juxtaposed against the government’s stated quest for national security.

Civil rights? How September 10th of you.

I do not like what our country is becoming.

Considering the Privacy Agreement They Have for Me

I have no sympathy for all for the bank executives who had their personal data posted online:

Following attacks on U.S. government websites last weekend, Anonymous seems to have made a new “Operation Last Resort” .gov website strike Sunday night.

Anonymous appears to have published login and private information from over 4,000 American bank executive accounts in the name of its new Operation Last Resort campaign, demanding U.S. computer crime law reform.

A spreadsheet has been published on a .gov website allegedly containing login information and credentials, IP addresses, and contact information of American bank executives.

If true, it could be that Anonymous has released banker information that could be connected to Federal Reserve computers, including contact information and cell phone numbers for U.S. bank Presidents, Vice Presidents, COO’s Branch Managers, VP’s and more.

This has been your moment of schadenfreude.

I wonder what Blankfein’s home phone number is.

Live in Obedient Fear, Citizen

This is why privacy, and innocent until proved guilty are important.

If your entire life is available to the state security apparatus, they will find something, and so you had better not be inconvenient to said state security apparatus, because they already have the means to destroy you.

You do not want them to be inclined to actually do so.

It is depressing that the truth tellers in our society are cartoonists and comedians.


Link

I am adding cartoonist Zach Weiner to my list of, “People I Do Not Want to Piss Off.”

Big Brother is Arlington Hewes*

Verizon has just patented a set top box with cameras that spy on you so that they can serve up targeted ads:

Verizon has filed a patent for a DVR that can watch and listen to the goings-on in your living room. In the application, the company proposes to use the technology to serve targeted ads appropriate to whatever you’re doing in the, uh, privacy of your own home—fighting, cuddling, or hanging out with your cats.

Verizon is far from the first company to think of this unassailably creepy use for a set-top box. Comcast patented similar monitoring technology in 2008 for recommending content based on people it recognizes in the room; Google proposed yet another patent for Google TV that would use audio and video recorders to figure out how many people in a room are watching the current broad

I am appalled by the very concept, and I am also appalled by the fact that the USPTO granted a patent for a television that spies on you, when George Orwell published this idea in his novel Nineteen Eighty-Four published in 1949.

The estate of Eric Arthur Blair should sue.

*The President’s Analyst, James Coburn, Godfrey Cambridge, 1967. Arlington Hewes is the president of The Phone Company, which is involved in an evil conspiracy.

This Should Not be a Surprise

The inestimable Murray Waas uncovers the fact that Wall Street’s “favorite private eye” engaged in a systematic spying and character assassination in support of Alan Stanford’s Ponzi scheme:

In 2006, Allen Stanford had yet to be identified as the mastermind of one of the largest and longest-running Ponzi schemes in U.S. history, but he faced mounting pressure.

Federal securities examiners were pushing for an investigation into his investment operation, which tens of thousands of soon-to-be victims had entrusted with nearly $7 billion. Some of the Texas financier’s own employees were threatening to tell authorities what they knew about his fraud.

Stanford was so concerned that a former senior State Department official named Jonathan Winer might expose his colossal con game that he ordered an investigation into Winer’s private life, according to Stanford’s previously secret records obtained by McClatchy.

Kroll Inc., an international corporate intelligence firm that Stanford had retained for over a decade, obliged. Tom Cash, a Miami-based a managing director of Kroll, soon informed Stanford in an email that he was looking into whether Winer’s ex-wife was a lesbian, according to the internal documents obtained by McClatchy.

………

They looked into the sexual orientation of Winer’s ex-wife, and Stanford used the information collected to blackmail regulators, politicians, and journalists.

What’s more, it worked:

SEC examiners concluded as early as 1997 that Stanford was running a massive Ponzi scheme, agency records show. But Stanford was able to stall the opening of any formal inquiry for a full decade, much like the man behind the only bigger U.S. Ponzi scheme, Bernard Madoff.

The biggest whopper told by Kroll, when a representative says that “its employees had no clue they were helping to conceal the second-biggest Ponzi scheme in U.S. history.”

No, they were told to collect information so that Stanford could blackmail people, and it’s clear from the emails from Stanford that this was what he charged them to do.

Sorry, but that dog don’t hunt.

Even if they did not have specific information about Stanford being a fraud, they had to have known from what he wanted that he intended to use this information for to extort silence from people.

H/t Felix Salmon.

Journalists Who Should Be Working as Pastry Chefs

Declan Mccullagh, everyone’s favorite “Draw by crayon Libertarian,”* has a scoop.  That Senator Pat Leahy had an amendment to the privacy bill in his committee that would allow warrantless access to your electronic communications by a big honking number of federal agencies.

One small problem though, he got his hands on an out of date draft that had never been seriously considered, and was not put forward by Leahy:

This would be particularly disturbing in the wake of the scandal surrounding Generals Petraeus and Allen, whose emails were exposed during a wide-ranging and questionable FBI investigation and have brought the discussion of limits on the surveillance state to the fore. But when reached by phone, Patrick Leahy’s spokesperson David Carle bluntly said the article was “wrong.”

The version of the bill that Declan McCullagh excerpts in his report appears to be one of many that have been drafted and passed around, but is not a version that would be considered seriously at a hearing to review the bill next week.

“Senator Leahy does not support broad carve outs for warrantless searches of email content,” says a Senate Judiciary aide. “He remains committed to upholding privacy laws and updating the outdated Electronic Privacy Communications Act.”

A person who has been privy to conversations about the impending bill intended to update privacy protections around digital communications for the modern age said that this was a “snapshot of a discussion point” and that it’s inaccurate to say it’s the version being pushed forward. This particular draft of the bill incorporates amendments suggested by Senator Chuck Grassley who has expressed concern that too much privacy protection for our email could negatively impact safety tasks.

OK, That’s a bit of an oops.

So, he accused Pat Leahy of trying to take away our privacy rights on the basis of a draft from Charles Grassley. ……… Oops.

What is Mccullagh’s response to all of this? He claims that his story forced Leahy to change his bill:

Sen. Patrick Leahy has abandoned his controversial proposal that would grant government agencies more surveillance power — including warrantless access to Americans’ e-mail accounts — than they possess under current law.

The Vermont Democrat said today on Twitter that he would “not support such an exception” for warrantless access. The remarks came a few hours after a CNET article was published this morning that disclosed the existence of the measure.

Not even a mention of reports that it was never a real amendment, and that Chuck Grassley was the author of the draft.

So, he took a draft from a Republican, one that is consistent with that Senator’s history, and ascribed it to a Democrat, because, you know, Democrats are evil!

Not surprising.

Declan McCullagh was one of the chief promoters of the “Al Gore invented the Internet meme.”

His editors need to smack him upside the head with a clue-by-four, and tell him to get the facts straight.

*Not my bon mot. It’s from the always entertaining Andrew Orlowski of The Register.

We Look Like Scared, Fearful, Losers Because We Are Scared, Fearful, Losers.

I cannot believe that I am quoting Iraq War booster Fareed Zakaria, but his take on the new invasive US state security apparatus:

While we will leave the battlefields of the greater Middle East, we are firmly committed to the war on terror at home. What do I mean by that? Well, look at the expansion of federal bureaucracies to tackle this war.

Since September 11, 2001, the U.S. government has created or reconfigured at least 263 organizations to tackle some aspect of the war on terror. Thirty-three new building complexes have been built for the intelligence bureaucracies alone, occupying 17 million square feet – the equivalent of 22 U.S. Capitols or three Pentagons. The largest bureaucracy after the Pentagon and the Department of Veterans Affairs is now the Department of Homeland Security, which has a workforce of 230,000 people.

The rise of this national security state has entailed a vast expansion in the government’s powers that now touch every aspect of American life, even when seemingly unrelated to terrorism. Some 30,000 people, for example, are now employed exclusively to listen in on phone conversations and other communications within the United States.

In the past, the U.S. government has built up for wars, assumed emergency authority and sometimes abused that power, yet always demobilized after the war. But this is, of course, a war without end.

………

We don’t look like people who have won a war. We look like scared, fearful, losers.

(emphasis mine)

Osama bin Laden did not win, he’s dead, but we lost, and we did it to ourselves.

I’m Cynical as to the Motives Here

So, after expressing concerns about the Cyber Intelligence Sharing and Protection Act (CISPA), the White House has now threatened a veto:

The White House has said that the Cyber Intelligence Sharing and Protection Act (CISPA), currently before the US House of Representatives, lacks enough privacy protections in its current form and will probably be vetoed if passed.

A statement from the White House Office of Management and Budget said that, while the importance of protecting the national infrastructure from online attacks is paramount, it “strongly opposes” the bill because it lacks proper oversight, could seriously damage individuals’ privacy and hands over responsibility for domestic cybersecurity to the NSA, rather than to a civilian body.

“Legislation should address core critical infrastructure vulnerabilities without sacrificing the fundamental values of privacy and civil liberties for our citizens, especially at a time our Nation is facing challenges to our economic well-being and national security,” the statement reads.

“The Administration looks forward to continuing to engage with the Congress in a bipartisan, bicameral fashion to enact cybersecurity legislation to address these critical issues. However, for the reasons stated herein, if H.R. 3523 were presented to the President, his senior advisors would recommend that he veto the bill.”

Yea! The White House is standing up for privacy.

Or maybe not:

“The Administration strongly opposes H.R. 3523, the Cyber Intelligence Sharing and Protection Act, in its current form,” the White House said in a statement released Wednesday afternoon. “H.R. 3523 fails to provide authorities to ensure that the nation’s core critical infrastructure is protected while repealing important provisions of electronic surveillance law without instituting corresponding privacy, confidentiality, and civil liberties safeguards.”

CISPA’s sponsors, House Intelligence Chairman Mike Rogers, R-Mich., and ranking member Dutch Ruppersberger, D-Md., dismissed the White House statement.

“The basis for the administration’s view is mostly based on the lack of critical infrastructure regulation, something outside of our jurisdiction,” the pair said in a statement released during the House Rules hearing. In addition, the sponsors pointed out that the White House objects to the bill’s current form, which doesn’t contain the latest changes hammered out with civil liberties groups.

(emphasis mine)

Maybe I’m a bit of a cynic, but I’m thinking that their objection is that it does not grant enough power.

If we look at the Obama administration’s prior behavior, their concerns for civil liberties or transparency have always taken a back seat to expanding executive power. (Basically Dick Cheney with abortion support)

Also, as PC Magazine notes, the Obasa administration made exactly the same sort of statements about the National Defense Authorization Act (NDAA), which allows for indefinite detention of American citizens, but decided to sign it anyway.

In any case, the House just called what is likely his bluff, and they passed CISPA and sent it to the Senate.

I’m not optimistic.

White House Statement after break:

CISPAvetostatement

Orwell Much?

It looks like Samsung has come up with a telescreen that has cameras and microphones that it can use to watch you:

Samsung’s 2012 top-of-the-line plasmas and LED HDTVs offer new features never before available within a television including a built-in, internally wired HD camera, twin microphones, face tracking and speech recognition. While these features give you unprecedented control over an HDTV, the devices themselves, more similar than ever to a personal computer, may allow hackers or even Samsung to see and hear you and your family, and collect extremely personal data.

While Web cameras and Internet connectivity are not new to HDTVs, their complete integration is, and it’s the always connected camera and microphones, combined with the option of third-party apps (not to mention Samsung’s own software) gives us cause for concern regarding the privacy of TV buyers and their friends and families.

Samsung has not released a privacy policy clarifying what data it is collecting and sharing with regard to the new TV sets. And while there is no current evidence of any particular security hole or untoward behavior by Samsung’s app partners, Samsung has only stated that it “assumes no responsibility, and shall not be liable” in the event that a product or service is not “appropriate.”

…………

A Samsung representative showed how, once set up and connected to the Internet, these models will automatically talk to the Samsung cloud and enable viewers to use new and exciting apps.

These Samsung TVs locate and make note of registered viewers via sophisticated face recognition software. This means if you tell the TV whose faces belong to which users in your family, it personalizes the experience to each recognized family member. If you have friends over, it could log these faces as well.

In addition, the TV listens and responds to specific voice commands. To use the feature, the microphone is active. What concerns us is the integration of both an active camera and microphone. A Samsung representative tells us you can deactivate the voice feature; however this is done via software, not a hard switch like the one you use to turn a room light on or off.

Seriously Eric Arthur Blair must be spinning in his grave at sufficient velocity to power all of Totnes on Devon.

Yes, we have a TV that watches you back, just like Big Brother in 1984.

Any bets on how long before the NSA hacks the cloud that this interfaces, so they can spy into people’s homes?  Certainly, the TOS described here would allow it, so perhaps they would not even have to hack into the system.  They just need to twist some arms at Samsung.

Lovely.

H/t Slashdot.