Pakistan Cyber Force: CIA spying tools

Top stories

Pakistan Cyber Force [Official]

Showing posts with label CIA spying tools. Show all posts
Showing posts with label CIA spying tools. Show all posts

Thursday, September 19, 2013

NSA Introduces Undetectable Chip-Embedded Hardware Trojans

Print Friendly and PDF

Is it so outlandish anymore to consider that an attacker interested in military, political or corporate espionage would be able to infiltrate a supply chain and drop malware onto an integrated circuit? Evidence of hardware-based Trojans is anecdotal at best, and experts believe a change in motherboard circuitry or wiring, for example, would be detectable either via visual inspection or in comparison to a gold copy of the hardware in question.

However, given that documents leaked by NSA whistleblower Edward Snowden intimate the U.S. spy agency was working with chipmakers and placing backdoors into hardware bound for foreign targets, the once-outlandish doesn’t seem so outrageous anymore.

And now, an international team of researchers may have upped the ante on hardware-based attacks. In a recently published paper, they describe how they are able to modify a circuit with malware and yet, to detection mechanisms,  the circuit appears to be pristine.

“Instead of adding additional circuitry to the target design, we insert our hardware Trojans by changing the dopant polarity of existing transistors. Since the modified circuit appears legitimate on all wiring layers (including all metal and polysilicon), our family of Trojans is resistant to most detection techniques, including fine-grain optical inspection and checking against ‘golden chips,’” the team—Georg T. Becker, Francesco Rgazzoni, Christof Paar and Wayne P. Burleson—wrote in its paper.

Dopant is a material that is added to semiconductor material that enables it to be electrically conductive. The researchers tested their stealthy Trojan on Intel’s random number generator design used in Ivy Bridge processors, as well as in a side-channel resistant SBox implementation.

While there is relatively little research available on hardware Trojans, the team dove into its research understanding that a jump in outsourcing—circuits are often designed in one location, likely built offshore, and then packed and distributed by more external parties—damages trust in the security of circuits.

“Even if chips are manufactured in a trusted [fabrication], there is the risk that chips with hardware Trojans could be introduced into the supply chain,” the researchers wrote. “The discovery of counterfeit chips in industrial and military products over the last years has made this threat much more conceivable.”

Some existing work on hardware Trojans, done mostly in academic settings, introduce malware at the hardware layer. This generally happens in a foundry setting where an attacker would have access only to layout masks; this limited access makes these types of attacks impractical because additional space is required for the malicious circuit and connections and would be easy to detect.

Attacks using dopant have also been tried before where the concentration of dopant is changed to age the circuit, eventually causing it to fail. However, the researchers point out that approach is impractical because it’s impossible to predict when the circuit would fail and cause a denial-of-service condition.

The researchers said their approach is more realistic because it is done by modifying the polarity of the dopant, which can be done at a foundry setting, and still resist optical inspection and go undetected.

“A dedicated setup could eventually allow one to identify the dopant polarity. However, doing so in a large design comprising millions of transistors implemented with small technologies seems impractical and represents an interesting future research direction,” the paper said. “We exploit this limitation to make our Trojans resistant against optical reverse-engineering.”

“To the best of our knowledge, our dopant-based Trojans are the first proposed, implemented, tested, and evaluated layout-level hardware Trojans that can do more than act as denial-of-service Trojans based on aging effects.”

The paper explains in great detail how the researchers attacked the Intel Ivy Bridge processors and pulled off a side channel attack that leaked secret keys from the hardware.

Ivy Bridge generates unpredictable 128-bit random numbers for the security of transactions. The researchers were able to get their Trojan onto the processor at the sub-transistor level to compromise the security of the keys generated with its random number generator.

“Our Trojan is capable of reducing the security of the produced random number from 128 bits to n bits, where n can be chosen,” the researchers wrote. “Despite these changes, the modified Trojan RNG passes not only the Built-In-Self-Test (BIST) but also generates random numbers that pass the NIST test suite for random numbers.”

As for the side-channel Trojan, it demonstrates flexibility of the dopant Trojan by attacking weaknesses that enable side-channel attacks in iMDPL, or improved Masked Dual Rail Logic.

“Rather than modifying logic behavior of a design, dopant Trjoan establishes a hidden side-channel attack that leaks secret keys,” the researchers wrote. “The dopant Trojan can be used to compromise the security of a meaningful real-world target while avoiding detection by functional testing as well as Trojan detection mechanisms.”
Pakistan Cyber Force

Sunday, June 9, 2013

Boundless Informant: NSA’s complex tool for spying & collecting global intelligence

Print Friendly and PDF


The top-secret documents released by the Guardian shed light on the National Security Agency’s data-mining tool being used for counting and categorizing metadata gathered and stored in numerous databases around the world.   Known as Boundless Informant, the software provides its operator a graphical insight on how many records were collected for a specific “organizational unit” or country, what type of data was collected and what type of collection was used. The program also allows determining trends in data collection for both strategic and tactical decision making, according to the slides.


One of the slides contains a part of the Informant’s user interface showing a world map with countries color-coded ranging from green to red depending on the amount of records collected there. While Iran, Pakistan and other some other states are predictably “hottest” according to the map, the agency collected almost 3 billion intelligence pieces in the US in March 2013 alone.

The insight on the software being used by the NSA comes amid the agency spokesperson Judith Emmel’s claims that the NSA cannot at the moment determine how many Americans may be accidentally included in its surveillance.

“Current technology simply does not permit us to positively identify all of the persons or locations associated with a given communication,” Emmel said Saturday adding that “it is harder to know the ultimate source or destination, or more particularly the identity of the person represented by the TO:, FROM: or CC: field of an e-mail address or the abstraction of an IP address.” 

NSA data sources 
Another slide from the internal NSA presentation redacted by the Guardian editors details the data gathering methods used in the NSA global surveillance program. 
The first method suggests interception of data from “fiber cables and infrastructure as data flows past” under the FISA Amendments Act (FAA) of 2008, Section 702. The second distinguished method is data collection “directly from the servers of the US service providers.” The presentation encourages analysts to use both methods for better results. 

Google, Facebook negotiated ‘secure portals’ to share data with NSA? 

Meanwhile, a report by the New York Times revealed that Internet giants, including Google and Facebook, have been in negotiations with the US security agency over ‘digital rooms’ for sharing the requested data. The companies still insist there is no “back door” for a direct access to user data on their servers. 
The Internet companies seem more compliant with the spy agencies than they want to appear to their users, and are cooperating on “behind-the-scenes transactions” of the private information, according to a report that cites anonymous sources “briefed on the negotiations.”

According to the report, Google, Microsoft, Yahoo, Facebook, AOL, Apple and Paltalk have “opened discussions with national security officials about developing technical methods to more efficiently and securely share the personal data of foreign users in response to lawful government requests,” sometimes “changing” their computer systems for this purpose.  These methods included a creation of “separate, secure portals” online, through which the government would conveniently request and acquire data from the companies.

Twitter was the only major Internet company mentioned in the report that allegedly declined to facilitate the data transfer to the NSA in a described way. As opposed to a legitimate FISA request, such a move was considered as not “a legal requirement” by Twitter.  The sources claim the negotiations have been actively going in the recent months, referring to a Silicon Valley visit of the chairman of the Joint Chiefs of Staff Martin E. Dempsey. Dempsey is said to have met the executives of Facebook, Microsoft, Google and Intel to secretly discuss their collaboration on the government’s “intelligence-gathering efforts.”

NSA pressured to declassify more PRISM details

In response to the fury over US government’s counterterrorism techniques, Director of National Intelligence James Clapper for the second time in three days revealed some details of the PRISM data-scouring program.  Being one of the “most important tools for the protection of the nation's security” the PRISM is an internal government computer system for collecting “foreign intelligence information from electronic communication service providers under court supervision,” Clapper said.

He also said that PRISM seeks foreign intelligence information concerning foreign targets located outside the US and cannot intentionally target any US citizen or any person known to be in the US. As for “incidentally intercepted” information about a US resident, the dissemination of such data is prohibited unless it is “evidence of a crime”, “indicates” a serious threat, or is needed to “understand foreign intelligence or assess its importance.”  Clapper also stressed that the agency operates with a court authority and that it does not unilaterally obtain information from the servers of US telecoms and Internet giants without their knowledge and a FISA Court judge approval.

(RT)


Pakistan Cyber Force

Monday, February 4, 2013

The Black Hornet – Tiny Spy Drone that can follow Enemy Targets

Print Friendly and PDF



It fits easily into the palm of your hand and looks to the world like a child’s toy helicopter.

But this tiny, remote-controlled aircraft is, in fact, British forces’ latest weapon against the Taliban.

Codenamed Black Hornet, the eight-inch long plastic moulded drone has three cameras hidden inside its nose, yet weighs just 15 grams, or just over half an ounce.

Black Hornet, which has a smooth grey body and twin black rotors, stays airborne thanks to a small rechargeable battery.

Like a child’s toy helicopter: The tiny, remote-controlled aircraft codenamed Black Hornet is, in fact, British forces’ latest weapon against the Taliban

Soldiers can either pilot it directly or program it to fly to a given set of co-ordinates on the battlefield using GPS, then return to base after spying on enemy positions.

The Mail on Sunday was last week given an exclusive demonstration of Black Hornet in Camp Bastion by soldiers from the Brigade Reconnaissance Force (BRF).

The ‘recce’ soldiers, who operate the tiny drone from  a safe distance, and their commander, Major Adam Foden, explained how they had used Black Hornet with great success on recent missions into Taliban territory.

Small wonder: Staff Sergeant Kevin Hough, attached to the Brigade Reconnaissance Force in Helmand, demonstrates the ‘nanocopter’

Major Foden, 34, said: ‘Black Hornet is a game-changing piece of kit. Previously we would have sent soldiers forward to see if there were any enemy fighters hiding inside a set of buildings.

‘Now we are deploying Black Hornet to look inside compounds and to clear a route through enemy-held spaces.

‘It has worked very well and  the pictures it delivers back  to the monitor are really clear. And Black Hornet is so small  and quiet that the locals can’t  see or hear it.’

On most operations the Black Hornet ‘nanocopter’ is controlled by a soldier using a computer game-style joystick. As the  drone hovers near an enemy position, pictures are beamed back to a monitoring station. It delivers high-resolution still and moving images.

Pressing a button, a soldier can zoom silently on to a target and the hum from Black Hornet’s rotors is scarcely audible even from a distance of a few yards.

When Black Hornet is flown inside Taliban compounds it can barely be heard and is difficult to see against the grey mud walls of village compounds.

Enemy fighters, hiding among civilian populations in villages, would be unaware that the drone was watching them.

One BRF soldier said: ‘It’s a cool piece of kit. The pictures are amazingly clear and we can see who is a local civilian and who is a Taliban fighter and whether any weapons are being stored there. We can then make our plans accordingly. It saves a  lot of time and a lot of mistakes. It can zoom right up to somebody’s face and hold that frame for as long as is required without them even knowing it’s there. It makes it possible to identify a high-value target.’

SPECIFICATIONS

LENGTH: 8 inches

WEIGHT: 0.5 ounce

SPEED: 22mph

MAXIMUM FLIGHT: 30 minutes

While Black Hornet is a priceless tool in Afghanistan,  it is unlikely it could be used  on Britain’s streets because of civil liberty concerns.

Before soldiers are allowed to use Black Hornet they are required to go on a training course which teaches them not just the drone’s capabilities but also how it should be deployed.

The whole package, the helicopter, monitor and stick,  fit into a pocket-sized case.

The Black Hornet – properly called a Proxdynamics PD-100 Personal Reconnaissance System – is a joint UK-Norwegian venture and was passed fit for service in Afghanistan after extensive field trials in Cyprus last year.

Friday, February 1, 2013

Experts Warn on Wire-tapping of the Cloud

Print Friendly and PDF



Leading privacy expert Caspar Bowden has warned Europeans using US cloud services that their data could be snooped on.

In a report, he highlights how the Foreign Intelligence Surveillance Act Amendment Act (FISAAA) allows US authorities to spy on cloud data.

This includes services such as Amazon Cloud Drive, Apple iCloud and Google Drive.

He told the BBC this heralded a new era of "cloud surveillance".

Foreign policy

Mr Bowden, former chief privacy adviser to Microsoft Europe, made a name for himself as a privacy advocate when the controversial Regulation of Investigatory Powers Act (RIPA) came into force in the UK in 2000.

Parliament accepted some of the amendments proposed by Mr Bowden as the then director of the Foundation for Information Policy Research.

Now he has turned his attention to US legislation and has co-authored the Fighting Cyber Crime and Protecting Privacy in the Cloud report which was recently presented to the European Parliament.

In it he said that FISAAA "expressly permits purely political surveillance", so that anyone with stored information relating to US foreign policy could find themselves of interest to the US authorities.

"Anyone who, for example, belongs to a campaign group which may oppose some aspect of US foreign policy, whether it be the Iraq war or climate change," he said.

The FISAAA was originally drafted in 2008, and was recently renewed until 2017. It was added on to existing legislation to take account of cloud computing, which was just emerging as a means of data storage.

"What's amazing is that nobody really spotted it for four years," said Mr Bowden.

"When FISAAA was extended to cover cloud computing, encrypting data to and from the cloud becomes irrelevant so it is surprising that nobody noticed this," he added.

Tiny supercomputer

Adam Mitton, a partner at law firm Harbottle & Lewis, agreed that the FISAAA could be a threat to privacy but questioned how much it was used.

 

"In theory there is a clear threat to the privacy of European citizens, but in reality the fact that it is obscure suggests that the threat isn't as great as it might be perceived," he said.

"If it was being used by an authority and having an impact on individual citizens, I think that the source of the information would come to light. The legislation is now five years old and I'm not aware of any case that has relied on it," he added.

Storing data in the cloud is becoming hugely popular not just for consumers who use it to keep photographs and other personal data safe but for businesses which are increasingly using cloud services to offer back-end processing power.

Under the FISAAA, US cloud providers can be compelled to release data from any citizen living outside of the US.

"The fibre-optic cable that carries the data is split and a miniature supercomputer scans all the data in real-time with any material of possible interest being instantly copied to the NSA [National Security Agency]," said Mr Bowden.

The court order is made in secret and remains secret - meaning it would not show up in things such as Google's transparency reports, which aim to document data requests from governments around the world.

"We have long known that the Americans can spy on foreign data but FISAAA extends this to reach inside the data centre. It allows the authorities to enact surveillance on a mass scale because it is wired into the infrastructure," Mr Bowden said.

A hearing on the European Parliament's findings of the report is due next month.

Thursday, January 31, 2013

World’s Highest Resolution Surveillance System: 1.8 Gigapixel ARGUS-IS

Print Friendly and PDF




DARPA and the USZ Army have taken the wraps off ARGUS-IS, a 1.8-gigapixel video surveillance platform that can resolve details as small as six inches from an altitude of 20,000 feet (6km). ARGUS is by far the highest-resolution surveillance platform in the world, and probably the highest-resolution camera in the world, period.

ARGUS, which would be attached to some kind of unmanned UAV (such as the Predator) and flown at an altitude of around 20,000 feet, can observe an area of 25 square kilometers (10sqmi) at any one time. If ARGUS was hovering over New York City, it could observe half of Manhattan. Two ARGUS-equipped drones, and the USZ could keep an eye on the entirety of Manhattan, 24/7.

It is the definition of “observe” in this case that will blow your mind, though. With an imaging unit that totals 1.8 billion pixels, ARGUS captures video (12 fps) that is detailed enough to pick out birds flying through the sky, or a lost toddler wandering around. These 1.8 gigapixels are provided via 368 smaller sensors, which DARPA/BAE says are just 5-megapixel smartphone camera sensors. These 368 sensors are focused on the ground via four image-stabilized telescopic lenses.

The end result, as you can see in the (awesome) video above, is a mosaic that can be arbitrarily zoomed. In the video, a BAE engineer zooms in from 17,500 feet to show a man standing in a parking lot doing some exercises. A white speck is a bird flying around. You can’t quite make out facial features or license plates (phew), but I wonder if that would be possible if ARGUS was used at a lower altitude (during a riot, say).

ARGUS’s insane resolution is only half of the story, though. It isn’t all that hard to strap a bunch of sensors together, after all. The hard bit, according to the Lawrence Livermore National Laboratory (LLNL), is the processing of all that image data. 1.8 billion pixels, at 12 fps, generates on the order of 600 gigabits per second. This equates to around 6 petabytes — or 6,000 terabytes — of video data per day. From what we can gather, some of the processing is done within ARGUS (or the drone that carries it), but most of the processing is done on the ground, in near-real-time, using a beefy supercomputer. We’re not entirely sure how such massive amounts of data are transmitted wirelessly, unless DARPA is waiting for its 100Gbps wireless tech to come to fruition.

The software, called Persistics after the concept of persistent ISR — intelligence, surveillance, and reconnaissance — is tasked with identifying objects on the ground, and then tracking them indefinitely. As you can see in the video, Persistics draws a colored box around humans, cars, and other objects of interest. These objects are then tracked by the software — and as you can imagine, tracking thousands of moving objects across a 10-square-mile zone is a fairly intensive task. The end user can view up to 65 tracking windows at one time.

The ARGUS system in its entirety produces one million terabytes per day — all of which is stored by the Army for future use. We’re a bit skeptical about PBS’s crazy figure (a million terabytes is an exabyte), but in theory most of that data is actually meta data — the coordinates and other identifying features of the thousands (millions?) of objects being tracked by ARGUS.

The original goal was to deploy ARGUS in Afghanistan, but that never came to pass. It isn’t entirely clear what ARGUS’s future is; it was meant to be mounted on Boeing’s high-altitude A160 Hummingbird helicopter (pictured right), but the chopper has since been scrapped. If ARGUS is to be deployed, it will most likely be strapped to the underbelly of a Predator drone. Where it will be used, however, with the war in Afghanistan apparently winding down, is another question entirely. Its efficacy in a military setting would be unsurpassed, but it’s easy to imagine how ARGUS could be used here at home in the US, too.

Via ExtremeTech
(Mildly Edited by PCF Web desk)

Friday, January 25, 2013

’Red October’: Global Cyber-Spy Network Uncovered by Russian Experts

Print Friendly and PDF


A sophisticated cyber-espionage network targeting the world’s diplomatic, government and research agencies, as well as gas and oil industries, has been uncovered by experts at Russia’s Kaspersky Lab.

The system’s targets include a wide range of countries, with the primary focus on Eastern Europe, former Soviet republics and Central Asia – although many in Western Europe and North America are also on the list.

“The majority of infections are actually from the embassies of ex-USSR country members located in various regions such as Western Europe and even in North America – in the US we have few infections as well. But most infections are concentrated around Russia,” Vitaly Kamluk, chief malware expert at Kasperky Lab, told RT, adding that in Europe, the hardest-hit countries are apparently Beligum and Switzerland.

In addition to attacking traditional computer workstations, ‘Rocra’ – an abridgment of ‘Red October,’ the name the Kaspersky team gave the network – can steal data from smartphones, dump network equipment configurations, scan through email databases and local network FTP servers, and snatch files from removable disk drives, including ones that have been erased.

Unlike other well-known and highly automated cyber-espionage campaigns, such as ‘Flame’ and ‘Gauss,’ Rorca’s attacks all appear to be carefully chosen. Each operation is apparently driven by the configuration of the victim’s hardware and software, native language and even document usage habits.

The information extracted from infected networks is often used to gain entry into additional systems. For example, stolen credentials were shown to be compiled in a list for use when attackers needed to guess passwords or phrases.

The hackers behind the network have created more than 60 domain names and several server hosting locations in different countries – the majority of those known being in Germany and Russia – which worked as proxies in order to hide the location of the ‘mothership’ control server.

That malicious server’s location remains unknown, but experts have uncovered over 1,000 modules belonging to 34 different module categories.While Rocra seems to have been designed to execute one-time tasks sent by the hackers’ servers, a number of modules were constantly present in the system executing persistent tasks. This included retrieving information about a phone, its contact list, call history, calendar, SMS messages and even browsing history as soon as an iPhone or a Nokia phone is connected to the system.

The hackers’ primary objective is to gather information and documents that could compromise the security of governments, corporations or other organizations and agencies. In addition to focusing on diplomatic and governmental agencies around the world, the hackers also attacked energy and nuclear groups, and trade and aerospace targets.

No details have been given yet as to the attackers’ identity. However, there is strong technical evidence to indicate that the attackers are of Russophone origins, as Russian words including slang have been used in the source code commentaries. Many of the known attacks have taken place in Russian-speaking countries.

“It is bound to Russian language. We are currently uncertain which country is responsible for creating these malicious applications, but we are most certain the developers picked the Russian language. It is visible from the text links we extracted from the application. Some of them point to Russian origin. For example, the word used inside of the malware the word is ‘zakladka.’ In Russian it means a bookmark, or under cleared functionality it can refer to a backdoor functionality in some legitimate software. So that’s why we believe this work was used by Russian-speaking developers,” Kamluk told RT.

The hackers designed their own authentic and complicated piece of software, which has its own unique modular architecture of malicious extensions, info-stealing modules and backdoor Trojans. The malware includes several extensions and malicious files designed to quickly adjust to different system configurations while remaining able to grab information from infected machines.

These included a ‘resurrection’ module, which allowed hackers to gain access to infected machines using alternative communications channels and an encoded spy module, stealing information from different cryptographic systems such as Acid Cryptofiler, which has reportedly been used since 2011 by organizations such as NATO, the European Parliament and the European Commission.

The first instances of Red October malware were discovered in October 2012, but it has been infecting computers since at least 2007, Kaspersky Lab reported. The firm worked with a number of international organizations while conducting the investigation, including Computer Emergency Readiness Teams from the US, Romania and Belarus.

The EU is attempting to counter the huge rise in cyber-espionage by launching the European Cybercrime Center, which opened on Friday.

Pakistan Cyber Force

Friday, January 4, 2013

CIA being sued over domestic spying collaboration with NYPD

Print Friendly and PDF



The CIA is being sued for withholding information about its cooperation on domestic spying as part of the New York Police Department’s counter-terrorism surveillance program. The Electronic Privacy Information Center (EPIC) filed a lawsuit at the end of December seeking the release of a report by the CIA's inspector general that examined the legality of spying on American soil.  CIA spy activity at home made headlines in 2011 when a series of investigative reports by the Associated Press exposed the CIA’s role in the NYPD’s Intelligence Unit, which kept tabs on New York's Muslim community despite a lack of evidence of any crimes. 

AP's Pulitzer Prize-winning enquiry found that the CIA played a crucial role in instructing the NYPD on its surveillance program, which spied on mosques, student groups and Muslims in general.   The agency’s director general responded to the allegations by launching a self-investigation into the collaboration. In December 2011, the CIA announced that it found "no evidence" its actions had broken the law. The agency also denied that it was directly involved spying inside the country. Soon after, the AP revealed that a CIA operative was being removed from assignment with the NYPD. In March 2012, EPIC filed a Freedom of Information Act request to receive a copy of the inspector general's report, but Langley has so far failed to release it, claiming a “substantial backlog” of such inquiries.  

“As a result of that investigation, they found that there was no wrongdoing, but they never made public the actual investigatory report,” Ginger McCall, director of EPIC's Open Government Program, was quoted as saying by the Huffigton Post. “I can't see what's actually in the report unless I have it in my hand.”

Last summer, a group of Muslims filed another case against the NYPD over its domestic spying endeavors across the river – and out of its jurisdiction – in New Jersey.
(RT)

Pakistan Cyber Force

Sunday, November 18, 2012

YES! The FBI & CIA can read your Emails. Here's how

Print Friendly and PDF


“Petraeus-gate,” some U.S. pundits are calling it. How significant is it that even the head of the CIA can have his emails read by an albeit friendly domestic intelligence agency, which can lead to his resignation and global, and very public humiliation? Here’s how. The U.S. government — and likely your own government, for that matter — is either watching your online activity every minute of the day through automated methods and non-human eavesdropping techniques, or has the ability to dip in as and when it deems necessary — sometimes with a warrant, sometimes without. That tin-foil hat really isn’t going to help. Take it off, you look silly.

Gen. David Petraeus, the former head of the U.S. Central Intelligence Agency, resigned over the weekend after he was found to have engaged in an extra-marital affair. What caught Petraeus out was, of all things, his usage of Google’s online email service, Gmail.

This has not only landed the former CIA chief in hot water but has ignited the debate over how, when, and why governments and law enforcement agencies are able to access ordinary citizens’ email accounts, even if they are the head of the most powerful intelligence agency in the world.

If it makes you feel any better, the chances are small that your own or a foreign government will snoop on you. The odds are much greater — at least for the ordinary person (terrorists, hijackers et al: take note) — that your email account will be broken into by a stranger exploiting your weak password, or an ex-lover with a grudge (see “Fatal Attraction“).

Forget ECHELON, or signals intelligence, or the interception of communications by black boxes installed covertly in data centers. Intelligence agencies and law enforcement bodies can access — thanks to the shift towards Web-based email services in the cloud — but it’s not as exciting or as Jack Bauer-esque as one may think or hope for.

The easiest way to access almost anybody’s email nowadays is still through the courts. (Sorry to burst your bubble, but it’s true.)

The ‘save as draft’ trick

Petraeus set up a private account under a pseudonym and composed email messages but never sent them. Instead, they were saved in draft. His lover, Paula Broadwell, would log in under the same account, read the email and reply, all without sending anything. The traffic would not be sent across the networks through Google’s data centers, making it nigh on impossible for the National Security Agency or any other electronic signals eavesdropping agency (such as Britain’s elusive GCHQ) to ‘read’ the traffic while it is in transit.

Saving an email as a draft almost entirely eliminates network traffic, making it nigh on impossible for intelligence agencies to ‘traffic sniff.’

And yes, terrorists and pedophiles have been known to use this ‘trick’, but also sophisticated criminals also use this technique. It eliminates a network trail to a greater or lesser extent, and makes it more difficult to trace.

But surely IP addresses are logged and noted? When emails are sent and received, yes. But the emails were saved in draft and therefore were not sent. However, Google may still have a record of the IP addresses of those who logged into the account.

However, most Internet or broadband providers offer dynamic IP addresses that change over time, and an IP address does not always point to the same computer, let alone the same region or state every time it is assigned to a user. Even then, recent U.S. court cases have found that IP addresses do not specifically point to a computer, meaning even if the authorities were sure that it was Petraeus, for instance — though IP addresses very rarely give the exact house number and street address — it would not stick in court.

As is often the case, human error can land someone in the legal spotlight. 37-year-old Florida resident Jill Kelley, a family friend to the Petraeus’, allegedly received emails from an anonymous account warning Kelley to stay away from the CIA chief.

But when Broadwell sent these messages, it left behind little fragments of data attached to the email — every email you send has this data attached — which first led the FBI on a path that led up to the very door of Petraeus’ office door in Langley, Virginia.

Get a warrant, serve it to Google?

There’s no such thing as a truly ‘anonymous’ email account, and no matter how much you try to encrypt the contents of the email you are sending, little fragments of data are attached by email servers and messaging companies. It’s how email works and it’s entirely unavoidable.

Every email sent and received comes with ‘communications data,’ otherwise known as “metadata” — little fragments of information that carries the recipient and the sender’s address, and routing data such as the IP addresses of the sender and the servers or data center that it’s passed through. Extracting this metadata is not a mystery or difficult, in fact anyone can do it, but if you have the legal tools and law enforcement power to determine where the email was passed through — such as an IP address of one of Google’s data center in the United States.

Email is surprisingly similar to the postal system, especially when it comes to the communication “metadata.”

The system is remarkably similar to the postal system. You can seal the envelope and hide what’s inside, but it contains a postmark of where it came from and where it’s going. It may even have your fingerprints on it. All of this information outside the contents is “metadata.”

That said, even if you use a disposable Gmail account — such as iamananonymousemailsender@gmail.com, for instance — it’s clearly a Gmail account, and Gmail is operated by Google. Sometimes it just takes a smidgen of common knowledge.

Ultimately, only Google had access to the emails. Because it’s a private company, it does not fall under the scope of the Fourth Amendment. If the U.S. government or one of its law enforcement agencies wanted to access the private Petraeus email account, it would have to serve up a warrant.

In this case, however, the Foreign Intelligence Services Act (FISA) would not apply. Even the Patriot Act would not necessarily apply in this case, even though it does allow the FBI and other authorized agencies to search email. However, in this case, above all else, the Stored Communications Act does apply — part of the Electronic Communications Privacy Act.

The act allows for any electronic data to be read if it has been stored for less than 180 days. In this case, the law was specifically designed — albeit quite some time before email became a mainstream communications medium — to allow server- or computer-stored data to be accessed by law enforcement.

However, a court order must be issued after the 180 days, and in this case it was. Reporting from London, the BBC News’ Mark Ward summed it up in a single sentence:

Once it knew Ms. Broadwell was the sender of the threatening messages, the FBI got a warrant that gave it covert access to the anonymous email account.

And that’s how they do it. No matter which way you look at it, no matter how much the government or its law enforcement agencies want the data or the proof of wrongdoing, they must almost always get a court order.

And Petraeus is no different from any other U.S. citizen, U.K. citizen, or European citizen — and further afield for that matter. What it always boils down to is a court order, and it’s as simple as that. It’s not ECHELON or an episode of “24“ using hacking or cracking techniques; it’s an afternoon in a fusty courtroom with a semi-switched on (and preferably sober) judge.

That said, it doesn’t grant unfettered or unrestricted access to a user’s inbox or email account, but when an alleged crime has been committed or law enforcement starts digging around, it allows a fairly wide berth of powers to request access to electronically stored data.

Former assistant secretary to the U.S. Department of Homeland Security Stewart Baker told the Associated Press:

The government can’t just wander through your emails just because they’d like to know what you’re thinking or doing. But if the government is investigating a crime, it has a lot of authority to review people’s emails.

So there it is. A court order is all you need to access a person’s inbox, but sufficient evidence is often required in order to do this — particularly through the Stored Communications Act, or the Electronic Communications Privacy Act.

It sounds obvious, of course, that’s because it is.

That said, if there is reasonable suspicion albeit lacking evidence, or a U.S. law enforcement agency is dealing with a foreign national outside of the United States, that normally requires a secret FISA court order to be granted in order to proceed with the interception of data or warranted access to an email account, for example.

Outside the U.S.: Is it still ‘just’ a court order?

A simple court order is all it takes and it can apply to anyone in public office or the man on the street holding a sign warning that “the end is nigh.”

But it’s OK; you’re in Europe, or Australia, or Asia. The U.S. can’t use their laws against you in a foreign country because, well, you’re outside of its jurisdiction. Again, sorry to burst your privacy bubble but that excuse didn’t wash with the European Parliament, it shouldn’t with you either.

If you’re a European citizen with a Microsoft, Google, Yahoo or Apple account — or any email offered in the cloud by a U.S. company — which is most consumer email services nowadays — it is accessible to the U.S. courts and other nations through various acts of law, such as the Foreign Intelligence Surveillance Act (FISA) or the PATRIOT Act, in which the latter amended much of what the former had implemented in the first place.

(“Oh great, he’s talking about the Patriot Act again,” says everybody.)

It’s worth noting a common few misconceptions. Since first reporting this some years ago (and subsequently sparking a trans-Atlantic diplomatic row, whoops) analysts and experts alike, some who are under the thumb of the cloud companies themselves, claim that the Patriot Act — to use the umbrella, common term — does not allow the U.S. government or its law enforcement agencies the powers that others (*cough* including me) claim.

Let’s just run through a few examples of false claims on top of false claims:

Myth Fact
The Patriot Act is the magic wand that allows the U.S. government unrestricted access to any data, anywhere, anytime. Untrue.
The Patriot Act gives the U.S. government unprecedented access to data hosted by U.S. companies anywhere in the world. Untrue.
All countries have similar legislation that gives the authorities a means to requisition data on cloud services, to investigate and prevent acts of terrorism. Unt… actually, quite true.
It doesn’t give “unrestricted” or “unprecedented” access to date outside the U.S., because for the most part these warrants must go through a special FISA court. The trouble is even though there is some level of accountability via the FISA courts, these sessions are held in secret and there are no public minutes or record to go from, so swings and roundabouts.

Only in exceptional cases where warrants are not issued is when there is an immediate threat to life. But because these courts are secret, there’s no definitive and ultimate way to know for an absolute fact that the U.S. authorities don’t just bypass the FISA courts and skip ahead with their investigations anyway. (You only really have my word — and my sources in the U.S. government, such as legal counsels and spokespeople, to go on.)

Pretty much every country around the world has ‘Patriot Act’-like legislation. It’s just where to look for it.

On the third point, other countries do have similar laws and this should be noted. (I personally thought it was relatively common knowledge, forgive my naivety.) The U.K., for instance, has the Regulation of Investigatory Powers Act that can be used to acquire data from a third-country via a U.K.-based firm, just as the Patriot Act can be used on a U.S. firm to access data in a third-country via a local subsidiary.

But in terms of where the major email and cloud providers are based — the United States, notably on the West Coast — it means that U.S. law must apply, in spite of foreign laws that attempt to or successfully counteract the provisions offered in U.S. law. Not many major cloud providers operate solely in the U.K., whereas Microsoft, Google, Apple and Amazon are all U.S. headquartered with a subsidiary in the U.K. and other countries.

The lesson here? We’re all as bad as each other and no legally or financially reasonable place is safe to store data if you’re a massive criminal or looking to stash a bunch of secret or uncouth documents away from the authorities.

As for Petraeus, he may have been careful but in spite of his counter-terrorism knowledge and clever tricks in going under the radar, ultimately there was a weak link in the security chain — and no matter how far you go to try and cover your tracks, often it always falls down to two things: human error, or sex.

Zack Whittaker


(ZD.net)

Pakistan Cyber Force

Friday, October 26, 2012

Facebook turns off automatic facial recognition feature for EU users

Print Friendly and PDF



Facebook has turned off its controversial tag suggestions feature for users in Europe, in a move that campaigners will hail as a victory for privacy.

The social network tool took biometric information provided when users tag friends' faces in photos to make suggestions on the correct tags for future images.

But the company was heavily criticised when it introduced the feature and automatically opted-in all users in Europe last June without formally announcing its arrival on the site.

Privacy campaigners were particularly disturbed since Facebook allows photographs to be published on its site without the express permission - or even knowledge - of those pictured.

With the facial-recognition feature activated on the site, this meant in essence that those uploading photos were handing the personal biometric information of those photographed over to the company.

 The removal of the feature and the forced deletion of all the biometric data will be a blow to the company which is under intense pressure to find new ways to convert its vast hoard users' personal information into cash since it was floated on the stock market earlier this year.

Mark Zuckerberg, Facebook CEO: The decision will be a blow to the company which is under pressure to find new ways to rake in more money.

Responding to the removal of the feature, Nick Pickles, director of privacy campaign group Big Brother Watch, said: 'Users need to be in control of what happens to their data and it’s absolutely right this applies to people’s pictures on Facebook in the same way as their written personal information.

'The wider issue is not just about people opting-in to use the technology, but how you regulate something when often the person in the photo might not be aware their photo has even been uploaded.

'Facial recognition has the potential to undermine people’s privacy far more dramatically than most existing technology, with ever more creative uses finding ways to track us and target us.'

Facebook was forced to carry out a review of the controversial feature's introduction after a wave of anger about potential data protection issues.

It announced last month that it would suspend the feature across Europe and erase all the biometric facial-recognition data it has collected thus far from users on the continent by October 15.

GOOGLE ORDERED TO FIX PRIVACY POLICY 'WITHIN MONTHS'

European regulators have ordered Google to clarify its new privacy policy and make it easier for users to opt out of it.

France’s National Commission on Computing and Freedom led a European investigation into Google’s new unified policy, which replaced 60 individual policies for its search, email and other services and regulates how it uses the personal data it collects.

CNIL's president Isabelle Falque-Pierrotin said the company had 'three or four months' to make the revisions, otherwise 'authorities in several countries can take action against Google'.

Google responded that it is reviewing the commission’s report but that it believes its policy respects European law.

The current row revolves around Google's decision to pool of anonymous user data across Google services. For Google, this is a big advantage when selling online ads.

Google and other large internet groups like Facebook provide free services to consumers and earn money from selling ads that they say are more closely targeted than traditional TV or radio campaigns.

The move followed a review by Facebook Ireland of the degree to which the social networking site had implemented recommendations made in an audit of the social networking site by the Irish Data Protection Commission last December.

That report assessed Facebook Ireland’s compliance with Irish Data Protection law and by extension EU law. The aim is to re-introduce the tag feature in the future, but with new guidelines and different forms of notice and consent.

Billy Hawkes, the Data Protection Commissioner for Ireland, said last month the tool would only return to the site if Facebook agreed with the department on the 'most appropriate means of collecting user consent'.

He praised the multi-billion pound company for 'sending a clear signal of its wish to demonstrate its commitment to best practice in data protection compliance.'

Mr Hawkes says Facebook should make users more aware of what happens to their personal data to increase control over privacy settings.

Mr Pickles added: 'It may be possible in future to find a way to use facial recognition on Facebook in very limited circumstances.

'However, given the challenge of securing consent from both the person uploading the photo and the people in the photo being scanned, it may be practically impossible to secure an adequate level of consent.

'What must not happen is the consent requirement be watered down because it proves difficult.'

Related Posts Plugin for WordPress, Blogger...