Pakistan Cyber Force: Internet software plugins used for spying

Top stories

Pakistan Cyber Force [Official]

Showing posts with label Internet software plugins used for spying. Show all posts
Showing posts with label Internet software plugins used for spying. Show all posts

Wednesday, February 6, 2013

Malware Attacks Hit News Websites – Foretelling Cyber False Flag?

Print Friendly and PDF




Malware alerts struck the web last night and this morning, in a preview of what Internet users have to look forward to once the real cyber false flag hits the Net.  Real and fake malware will create chaos, as users get blocked from their favorite websites.

Regular visitors to BIN may have noticed that we had some of those cute red screens courtesy of your browsers (Safari, Chrome and Firefox) on our site last night and this morning alerting you that "you'd better not go there".

The Google Chrome malware warning from BIN late last night.  Firefox and Safair had similar dire warnings for these sites.

Outages were reported at many popular sites, including ZD Net, CNET, Glenn Reynold's popular Instapundit, etc.  Here's a report from ZD Net that covered their end of things.  Facebook is running behind, they are still showing warnings for some sites, including BIN.  The BIN site is completely clean at this time, according to Google.
 
Here's a screen grab from Instapundit:

Has anyone else noticed what's happened to the internet?  Sites with edgy alternative content or conservative points of view get hacked more often, and in this case not hacked, but effectively taken down by scary looking warning messages.  This type of censorship has been going on for years with email.  If you want to keep a lid on the news, you just signup for a site's email, then send it to one of the 50 self appointed "spam police" sites and they'll blacklist a site.  It usually takes a day or two for things to return to normal and get off the blacklist and by then the damage is done.  The same thing is now happening to web sites.

There's only one way around this, a new way to communicate and get news and information using the internet.  We've been developing it for a year and it's going to be what we think is a very good alternative to insecure email and chat programs, as well as providing a way to view web content without surfing around for it.

Before its news

Friday, February 1, 2013

Experts Warn on Wire-tapping of the Cloud

Print Friendly and PDF



Leading privacy expert Caspar Bowden has warned Europeans using US cloud services that their data could be snooped on.

In a report, he highlights how the Foreign Intelligence Surveillance Act Amendment Act (FISAAA) allows US authorities to spy on cloud data.

This includes services such as Amazon Cloud Drive, Apple iCloud and Google Drive.

He told the BBC this heralded a new era of "cloud surveillance".

Foreign policy

Mr Bowden, former chief privacy adviser to Microsoft Europe, made a name for himself as a privacy advocate when the controversial Regulation of Investigatory Powers Act (RIPA) came into force in the UK in 2000.

Parliament accepted some of the amendments proposed by Mr Bowden as the then director of the Foundation for Information Policy Research.

Now he has turned his attention to US legislation and has co-authored the Fighting Cyber Crime and Protecting Privacy in the Cloud report which was recently presented to the European Parliament.

In it he said that FISAAA "expressly permits purely political surveillance", so that anyone with stored information relating to US foreign policy could find themselves of interest to the US authorities.

"Anyone who, for example, belongs to a campaign group which may oppose some aspect of US foreign policy, whether it be the Iraq war or climate change," he said.

The FISAAA was originally drafted in 2008, and was recently renewed until 2017. It was added on to existing legislation to take account of cloud computing, which was just emerging as a means of data storage.

"What's amazing is that nobody really spotted it for four years," said Mr Bowden.

"When FISAAA was extended to cover cloud computing, encrypting data to and from the cloud becomes irrelevant so it is surprising that nobody noticed this," he added.

Tiny supercomputer

Adam Mitton, a partner at law firm Harbottle & Lewis, agreed that the FISAAA could be a threat to privacy but questioned how much it was used.

 

"In theory there is a clear threat to the privacy of European citizens, but in reality the fact that it is obscure suggests that the threat isn't as great as it might be perceived," he said.

"If it was being used by an authority and having an impact on individual citizens, I think that the source of the information would come to light. The legislation is now five years old and I'm not aware of any case that has relied on it," he added.

Storing data in the cloud is becoming hugely popular not just for consumers who use it to keep photographs and other personal data safe but for businesses which are increasingly using cloud services to offer back-end processing power.

Under the FISAAA, US cloud providers can be compelled to release data from any citizen living outside of the US.

"The fibre-optic cable that carries the data is split and a miniature supercomputer scans all the data in real-time with any material of possible interest being instantly copied to the NSA [National Security Agency]," said Mr Bowden.

The court order is made in secret and remains secret - meaning it would not show up in things such as Google's transparency reports, which aim to document data requests from governments around the world.

"We have long known that the Americans can spy on foreign data but FISAAA extends this to reach inside the data centre. It allows the authorities to enact surveillance on a mass scale because it is wired into the infrastructure," Mr Bowden said.

A hearing on the European Parliament's findings of the report is due next month.

Saturday, October 13, 2012

Google accused of spying on Gmail users

Print Friendly and PDF



Google isn’t exactly a stranger to allegations that they invade the privacy of their customers, but now the search engine is being asked to explain itself in court over accusations that they snoop through messages sent through its Gmail service. Representatives from Google are asking a federal judge to dismiss a lawsuit waged at the company’s Gmail platform because the plaintiffs in the case cannot explicitly prove that their correspondence is being unlawfully monitored by the email service.

Brad Scott and Todd Harrington are the lead plaintiffs in a case that attempts to call-out the Silicon Valley search engine company as being in violation of California’s Invasion of Privacy Act (CIPA) because they believe Gmail conducts clandestine scans of emails for words and content, intentionally intercepting private communiqué as a result without obtaining the user’s permission. Google, on the other hand, maintains that only computers complete all the legwork and that no humans actually have their eyes on any emails, also insisting that neither Mr. Scott nor Mr. Harrington can back up their claims that any action from Gmail has led to injury.

Google condemned the case this week, Courthouse News reports, arguing by way of a 25-page motion that Gmail scans data sent over its servers using its "fully automated processes involve no human review of any kind" that they insist exists to screen out viruses and spam "for the protection of its users." Now they are asking US District Judge Lucy Koh to dismiss the complaint with prejudice. The plaintiffs say that Google’s actions are enough to land them in court because that conduct constitutes wiretapping and eavesdropping in their eyes, a claim which Google says is “contorting” state law "in ways the California Legislature never intended.”

"In the context of emails, multiple courts have recognized that no one can reasonably expect that the emails they send to others will be free from the automated processing that is normally associated with delivering emails," Google responds to the case with this week’s motion. "Plaintiffs fail to articulate a single concrete injury stemming from the automated processing of emails sent to Gmail users," Google adds. "Plaintiffs instead rely on conclusory allegations that their privacy rights were infringed in the abstract."
Additionally, Google charges that no state statues being called into question applies to the plaintiffs’ allegations, writing in their motion that the terms "electronic communication," "email," "Internet" and "computer" are not included.

"Even if the court were to accept plaintiffs' invitation to judicially rewrite the statute to reach electronic communications, choice of law rules would still preclude applying CIPA to this case," Google’s motion states. "CIPA makes clear on its face that it is intended to protect California residents and not to regulate California businesses," Google adds.

Judge Koh is now expected to hear the motion on March 21, 2013. Meanwhile, congressional Republicans wrote to the White House this week to attack a planned cybersecurity executive order that would allow third-party companies, such as Google, to openly share customer-inputted information with the federal government.

“An executive order exerting influence over critical infrastructure is not just a step in the wrong substantive direction,” the letter reads. “It will almost certainly be exploited by other nations to justify their efforts to regulate the Internet. This is a most critical time, and we cannot afford a hasty, unilateral action that will only serve to bolster the efforts of less democratic nations to stifle the very free exchange of ideas and expression that has allowed the Internet to flourish across the globe. For these reasons, we urge you to rethink the wisdom of an executive order.”

The letter to US President Barack Obama was signed by 11 GOP members of Congress, including US Rep. Fred Upton (R-Michigan), Senator Kelly Ayotte (R-New Hampshire), Senator Marco Rubio (R-Florida) and Senator Mike Lee (R-Utah).


RT

Pakistan Cyber Force

Tuesday, September 18, 2012

VOIP Spying Apps "Made In Israel": Viber, Fring, Jajah, Spikko and Iskoot

Print Friendly and PDF

Viber is a famous VOIP application among others including Fring that are used widely all around the world. Viber Media, Inc., is an "Israeli"-based company that has developed this smartphone application that allows users to talk and text for free. It was founded by Talmon Marco who served for four years in the Israel Defense Forces and held the position of CIO of the central command. He graduated Cum Laude from the Tel-Aviv University with a degree in Computer Science and Management.

Viber requires some sensitive permissions to be granted to the application such as reading and manipulating the contact list of the SIM card (or the phone), and directly call phone numbers and send sms messages, he said adding "The data and information are stored online, so other parties might be able to reach it if they managed to hack Viber's servers: "The copy of your address book (names and phones) is stored on a live database.

As the case is for Viber, Fring also requires sensitive permissions regarding the SIM card.

Concerning the deactivation of an account, it is possible yet the address book will be deleted from Viber's servers after 45 days the deactivation.
The application doesn't seem to save an online copy of the contact list. However it also do not guarantee unauthorized access to their online data in the privacy policies. The online data might be the usernames and passwords registered.

One slight difference, the expert points out, that it is impo
ssible to delete a Fring account.
Jajah too requires sensitive permissions also regarding the SIM card, and does not guarantee unauthorized access to the online data of the user, as says the privacy policy of the website.

These applications are spyware applications because they ask for wide access and permissions. By agreeing their terms of services, a user is giving the application the right to anonymously and automatically collect data about the device and the user himself. It is possible for all these apps to record each and every call done by the users.

For instance, Viber's privacy policy says: "You agree that we may collect and use technical data and related information, including but not limited to technical information about Your mobile device, system and application software, and peripherals, that is gathered periodically to facilitate the provision of software updates, product support and other services to You related to the Licensed Application."

Who Are the Staff Members of Viber, JahJah, Fring?





 


Tuesday, August 14, 2012

Google forced to pay $22million fine for ‘spying on web users’ – but REFUSES to admit they were wrong

Print Friendly and PDF

The Federal Trade Commission has ordered Google to pay $22.5 million for violating user privacy on its Apple's Safari browser. It's the biggest FTC fine ever issued for a commission violation.



The federal agency found that Google had been tracking "cookies" on Google sites for Apple Safari users. It was also sending targeted ads to those users, which violated another settlement between the FTC and the search-engine giant.
Google claimed that a tweak in Apple's browser caused an unintentional violation, but the FTC was not swayed by such an argument.
"A company like Google, which is a steward of information for hundreds of millions of people has to do better," David Vladeck, the FTC director of the Bureau of Consumer Protection, told reporters on a conference call following the announcement.
The potential privacy violation was first detected by Jonathan Mayer, a Standford University graduate student, who realized that Google was still tracking his cookies, even though he had tried to block it.
"This seems to be the kind of thing the company shouldn't be doing," Mayer told ABC News in February.

As a result of this and other violations, a "Do Not Track," or DNT, setting had been added to various browsers, including Mozilla's Firefox, Microsoft's Internet Explorer and Apple's Safari. Still, with this particular violation, the FTC charged that during 2011 and 2012, Google had been tracking Safari users -- on Macs, iPhones and iPads -- who had opted out of such tracking, as a result of default settings in the browser.

Google has not admitted to violating the law. "The complaint is not a finding or ruling that the defendant has actually violated the law. This consent order is for settlement purposes only and does not constitute an admission by the defendant that the law has been violated," the FTC said in a news release.
A Google spokesperson held to that as well. "We set the highest standards of privacy and security for our users. The FTC is focused on a 2009 help center page published more than two years before our consent decree, and a year before Apple changed its cookie-handling policy," the spokesperson told ABC News. "We have now changed that page and taken steps to remove the ad cookies, which collected no personal information, from Apple's browsers."

Saturday, July 14, 2012

Facebook Monitors Your Chats for “Criminal Activity”

Print Friendly and PDF

Facebook and other social platforms are watching users’ chats for criminal activity and notifying police if any suspicious behaviour is detected, according to a report.
The screening process begins with scanning software that monitors chats for words or phrases that signal something might be amiss, such as an exchange of personal information or vulgar language.
The software pays more attention to chats between users who don’t already have a well-established connection on the site and whose profile data indicate something may be wrong, such as a wide age gap. The scanning program is also “smart” — it’s taught to keep an eye out for certain phrases found in the previously obtained chat records from criminals including sexual predators.
If the scanning software flags a suspicious chat exchange, it notifies Facebook security employees, who can then determine if police should be notified.
Keeping most of the scanned chats out of the eyes of Facebook employees may help Facebook deflect criticism from privacy advocates, but whether the scanned chats are deleted or stored permanently is yet unknown.
The new details about Facebook’s monitoring system came from an interview which the company’s Chief Security Officer Joe Sullivan gave to Reuters. At least one alleged child predator has been brought to trial directly as a result of Facebook’s chat scanning, according to Reuters’ report.
When asked for a comment, Facebook only repeated the remarks given by Sullivan to Reuters: “We’ve never wanted to set up an environment where we have employees looking at private communications, so it’s really important that we use technology that has a very low false-positive rate.”
Facebook works with law enforcement “where appropriate and to the extent required by law to ensure the safety of the people who use Facebook,” according to a page on its site.
“We may disclose information pursuant to subpoenas, court orders, or other requests (including criminal and civil matters) if we have a good faith belief that the response is required by law. This may include respecting requests from jurisdictions outside of the United States where we have a good faith belief that the response is required by law under the local laws in that jurisdiction, apply to users from that jurisdiction, and are consistent with generally accepted international standards.
“We may also share information when we have a good faith belief it is necessary to prevent fraud or other illegal activity, to prevent imminent bodily harm, or to protect ourselves and you from people violating our Statement of Rights and Responsibilities. This may include sharing information with other companies, lawyers, courts or other government entities.”
Indeed, Facebook has cooperated with police investigations in the past. In April, it complied with a police subpoena from the Boston Police Department by sending printouts of wall posts, photos and login/IP data of a murder suspect.

Friday, January 28, 2011

Adobe Flash Player slammed for spying

Print Friendly and PDF


Local Shared Objects, LSO, commonly called Flash cookies are collections of cookie-like data stored as a file on a user computer. Used by Flash-based applications to store preferences, cache files or save state and temp data, all methods of improving user experience. The sole purpose of this technology is to trace user movements around the Internet and it has the ability to store a lot of information about you, which is around 100 Kilobyte for each cookie whereas, normal HTTP cookies can store only about 4 Kilobyte. The bad news is that you can't locate them in your browser. They are not shown in the list of cookies that you can see when you take a look at the cookies that are currently saved in your web browser. All use them employ Web ad companies like Quantcast, Specificmedia, and Clearspring to deliver Flash ads, and all of those ads store Flash cookies on your hard drive. The bizarre thing is that they can be used to recreate tracking cookies you've deleted.

Adobe Flash Player
In other words, if you've told an advertiser you don't want to be followed around the Web by deleting its tracking cookie, that advertiser can use Flash to reproduce that deleted cookie and continue to track you in secret. This clearly breaks international laws against computer intrusion and surveillance for which several famous companies have been alleged including Disney, Warner Bros. Records, Ustream, Youtube, Google Videos, Columbia Pictures,  and others. They have installed illegal codes on millions of computers with the purpose of tracking the online activity of its users.


This is exactly what the companies referred to collectively as "Clearspring Flash Cookie Affiliates". The defendants are Clearspring Technologies, the company developing Flash-based technologies and its customers, which include Walt Disney Internet Group, Demand Media, Project Playlist, Soapnet, SodaHead, Ustream and Warner Bros. Records. The complaint read, "Defendants Clearspring Flash Cookie Affiliates acted with Defendant Clearspring, independently of one another, and hacked the computers of millions of consumers' computers to plant rogue, cookie-like tracking code on users' computers. With this tracking code, Defendants circumvented users' browser controls for managing web privacy and security."



According to the complaint, the collected information could have been used to determine "users' video viewing choices and personal characteristics such as gender, age, race, number of children, education level, geographic location, and household income, what the web user looked at and what he/she bought, the materials he/she read, details about his/her financial situation, his/her name, home address, e-mail address and telephone number, and even more specific information like health conditions, such as depression." The company developing Flash, has condemned the practice of using Local Storage for backing up or restoring cookies without express user consent.

Getting rid of the perilous danger

You just need to use Adobe's Flash Player Settings Manager. The Website Storage Settings display all Flash cookies that are currently saved on your computer. You can delete flash cookies from individual sites or all at once.



It is also possible to increase or decrease the Kilobyte size of all information that are stored on your computer. No Flash Cookies will be saved if you go into Global Storage Settings and disable the option “Allow third-party Flash content to store data on your computer”. Just follow the instructions and you're good to go.

Surf the internet safely.

Written by: Sarah Ssmq
Edited by: Enticing Fury

Related Posts Plugin for WordPress, Blogger...