Showing posts with label surveillance. Show all posts
Showing posts with label surveillance. Show all posts

Thursday, 15 August 2013

Indian Government buying deep surveillance, monitoring equipment ---> Mobile is spy for Indians

Amid a raging global debate on privacy versus surveillance, monitoring and use of intrusive technologies by governments, the Directorate of Forensic Sciences in the Ministry of Home Affairs (MHA) is set to purchase a range of equipment and software that will allow it to conduct deep search, surveillance and monitoring of voice calls, SMS, email, video, Internet, chat, browsing and Skype sessions on an unprecedented scale.
The shopping list may help the government counter crime and terrorism but civil liberties advocates worry about the misuse of these technologies against ordinary citizens, especially given the absence of strong privacy protection.
The MHA document of July 12, 2013 also lists software-based tool kits for logical level analysis of GSM and CDMA mobile phones — which will comprehensively cover phones and SIMs used by India’s 860 million subscribers across 2G and 3G networks. This will be capable of extracting the phone’s basic information and SIM card data, including in your phonebook and contact list, call logs, caller group information, organizer, notes, live and deleted SMSs, web browser artifacts, multimedia and email messages with attachments, multimedia image audio and video files and details of installed applications, their data, traffic and sessions log. It will allow access to iPhone backup analysis, including those which are password protected. Blackberry, considered safe by unsuspecting users, will also be fair game, since it will support Blackberry IPD backup analysis, even when password protected.

Mobiles and SMS

The specialised hardware on the MHA’s list will be able to extract all data, including call logs, phone books, SMS, email messages along with attachments, MMS, calendars, including passwords and location information. It will be able to read SIM cards and extract SIM-card-related information along with all user information on the SIM card, like phone call register and text messages, even if they have been deleted. The software will be capable of data authentication by hashing algorithms, and will even access deleted phone information by recovering or bypassing passwords. Special forensic kits are being brought in for Chinese mobile phones.

Bypassing passwords

Hardware forensic imaging devices with the capability to acquire data from live systems and content-based images are being procured. The capabilities also include the ability to search for key words in the suspected media and to acquire data over a network. Essentially, this would mean blind, across-the-board search on mass data rather than a targeted search based on an authorised target phone number, email or IP address.
The MHA is also set to acquire software for forensic previewing, for analysis of digital media and smartphones. This can acquire date from various types of storage media including in multi-sessions. It can support Windows, Unix, Linux, Sun, Solaris, Macintosh, Apple’s iOS, Android, Blackberry, HP’s palm OS, Nokia Symbian, Windows Mobile OS, etc. The software will be capable of decrypting volumes, folders and files of suspected media including that which is subject to various types of encryption — including 32 and 64-bit systems.
Software is also being ordered for previewing, image mounting, password cracking and forensic analysis of digital media. This would allow recovering folders, expanding compounded files, saved email data bases, extracting artifacts, time line analysis, and registry log analysis. It will allow the government to auto-detect passwords of protected files and their decryption across a range of encryptions.
The new forensic tool will automatically check for disk encryption, including Truecrypt, PGP, Bitlock and Safeboot. This forensic tool will be capable of collecting and recovering artifacts from live and off-line systems when using cloud artifacts like Dropbox, Carbonite, Skydrive, Googledocs, Google Drive and Flickr. It will link into, and extract data out of, users’ social networking pages like Facebook, Twitter, Bebo Chat, Myspace Chat, Google+ and Linkedin. Similarly, webmail applications like Gmail, Yahoo, Hotmail and instant messenger chat can be targeted through this kit. Instant messenger chat like GoogleTalk chat, Yahoo chat, MSN/Windows Live Messenger, AOL, Skype, ICQ, World of War Craft, Second Life and Trillian, will all be open to collection of artifacts, whether live or offline. The system will also accurately target web browser activity on Internet Explorer, Firefox, Google Chrome, Apple Safari, Opera, Google Maps, etc.
The MHA is one of the nine authorised departments, along with IB and RAW, which is allowed to order surveillance and monitoring of citizens under the Indian law. It has been in the news for being closely involved in the implementation of a nationwide Central Monitoring System covering mobile and Internet users.

Thursday, 20 June 2013

Who helped NSA to build Prism?

Palantir Technologies is considered the principal company behind the design of software used for PRISM program, think of it as the work of a single company is truly an understatement.

http://securityaffairs.co/wordpress/wp-content/uploads/2013/06/palantir-technologies-300x228.jpg
Palantir Technologies, this is the most popular company name referred when discussing those who have supported the U.S. Government in the development of massive surveillance project Prism. The company, exactly like the principal IT firms involved in the program denied any implication but majority of security analysts are convinced that the truth is different.
Palantir Denies PRISM implication
I wrote on Palantir in a post just after the publication of mail stolen during the hack to Stratfor firm, in one email published Palantir is expressly indicated as a possible financier of Facebook.  The email between two Stratfor’s analysts states:
“I think Palantir is involved in things less clear, including the financing of Facebook.”
The Palantir is a California company that designs platforms for complex information analysis. It was founded in 2004 and currently offers various solutions for integrating, visualizing, and analyzing the world’s information.
palantir software
Palantir was founded by Peter Thiel, Alex Karp, Joe Lonsdale,  Stephen Cohen, and Nathan Gettings, the company received investments for $2 million from the CIA’s venture arm In-Q-Tel and $30 million from Thiel and his firm, Founders Fund.
The name of Palantir appeared for the first time during the hacking of HBGary Federal company, when documents were some stolen detailing the involvement of the Palantir to attack and destroy WikiLeaks.
By coincidence Palantir commercialize a product dubbed PRISM that “that lets you quickly integrate external databases into Palantir. Specifically, it lets you build high-performance Data Engine based providers without writing any code. Instead, you define simple configuration files and then Palantir automatically constructs the data provider and database code for you.”
Palantir Prism is a data mining software for banks, that’s the version provided by legal representatives of the company:
Palantir’s Prism platform is completely unrelated to any US government program of the same name. Prism is Palantir’s name for a data integration technology used in the Palantir Metropolis platform (formerly branded as Palantir Finance). This software has been licensed to banks and hedge funds for quantitative analysis and research,”
Y Combinator partner Garry Tan commented Palantir’s disclaimers with following tweet:
Palantir Denies PRISM implication Reply
It is still not clear how PRISM works, the slides presented could be not accurate enough to explain how PRISM platform access to the data of IT companies, some specialists sustain that the companies provided direct access to their servers others speculate the companies feed a sort of Dropbox-like system that is accessed by PRISM for surveillance purpose.
In this second scenario it could be involved also Amazon as hosting provided for temporary storage for information provided by companies, Amazon Web Services in fact recently announced that it is set to build a massive cloud for the CIA. IBM.
Despite various hypothesis on PRISM architecture, it is still a mystery I suggest you the post proposed by Robert Graham of Errata Security that tried to propose an original idea of the Debated surveillance program.
In reality the complex machine that in a simplistic way was dubbed PRISM is probably fueled by much more information from various sources, not only IT giants are involved, Digital Net Agency Chief Strategy Officer Skip Graham believes the advertising industry is complicit inducing internet users to provide personal information online.
Who and how manage this data?
“How our industry works has absolutely no correlation to the efforts of the government. Or does it? How much of the data the NSA is using is data we convinced people it was safe to have stored? I’m afraid it’s going to turn out to be most of it,” Graham told ZDNet.
It must be also considered that many other data can concur to profile US citizens, let’s think of information related to their medical history, rather any kind of financial information acquired from banking and other financial institutions.
We are all  under continuous control, think of it as the work of a single company is truly an understatement …. how many other Palantir are operating in the US and elsewhere?
What data handling and on behalf of whom?
Pierluigi Paganini

Wednesday, 19 June 2013

NSA Implementing 'Two-Person' Rule To Stop The Next Edward Snowden

http://b-i.forbesimg.com/andygreenberg/files/2013/06/Screen-Shot-2013-06-18-at-12.35.50-PM.pngThe next Edward Snowden may need a partner on the inside.
On Tuesday, National Security Agency Director Keith Alexander told a congressional hearing of the Intelligence Committee that the agency is implementing a “two-person” system to prevent future leaks of classified information like the one pulled off by 29-year-old Booz Allen contractor Edward Snowden, who exfiltrated “thousands” of files according to the Guardian, to whom he has given several of the secret documents.
We have to learn from these mistakes when they occur,” Representative Charlies Ruppersberger said to Alexander in the hearing. “What system are you or the director of national intelligence administration putting into place to make sure that if another person were to turn against his or her country we would have an alarm system that would not put us in this position?”
“Working with the director of national intelligence what we’re doing is working to come up with a two-person rule and oversight for those and ensure we have a way of blocking people from taking information out of our system.”
That “two-person rule,” it would seem, will be something similar to the one implemented in some cases by the military after Army private Bradley Manning was able to write hundreds of thousands of secret files to CDs and leak them to WikiLeaks. The rule required that anyone copying data from a secure network onto portable storage media does so with a second person who ensures he or she isn’t also collecting unauthorized data.
It may come as a surprise that the NSA doesn’t already have that rule in place, especially for young outside contractor employees like Snowden. But Alexander emphasized that Snowden was one of close to a thousand systems administrator–mostly outside contractors–who may have had the ability to set privileges and audit conditions on networks.”This is a very difficult question when that person is a systems administrator,” Alexander responded. “When one of those persons misuses their authority it’s a huge problem.”
Alexander added that the system is still a work in progress, and that the NSA is working with the FBI to collect more facts from the Snowden case and to implement new security measures in other parts of the U.S. intelligence community.
When asked how Snowden had gained such broad access to the NSA’s networks despite only working for Booz Allen for three months, Alexander said that he had in fact held a position at the NSA for the twelve months prior to taking that private contractor job.
The questions about the NSA’s lack of leak protections came in the midst of a conversation that largely focused on the NSA’s justification for the broad surveillance those leaks revealed. In the hearing, Alexander claimed that more than 50 attacks have been foiled with some help from the NSA’s surveillance programs such the collection of millions of Americans’ cell phone records and the collection of foreigners’ Google-, Facebook-, Microsoft- and Apple-held data known as “PRISM,” both disclosed in Snowden’s documents. One newly-revealed bombing plot targeted the New York Stock Exchange, and another involved an American donating money to a Somalian terrorist group.
Of those more than 50 total cases, ten of those plots involved domestic collection of phone records, according to Alexander. But when Representative Jim Himes questioned in how many cases that collection was “essential,” his question went unanswered.
Alexander also fended off criticisms that the Foreign Intelligence Surveillance Act court system, which oversees the NSA’s requests to use data it’s collected–often from Americans–is a “rubber stamp process” that approves nearly all of the NSA’s actions. That court reported  in April that it had received 1,789 applications for electronic surveillance in an annual report to Congress. One request was withdrawn, and forty were approved with some changes. The other 1,748 others were approved without changes.
“I believe the federal judges on that court are superb,” Alexander told Congress. “There is, from my perspective, no rubber stamp.”
But a significant portion of the hearing also focused on the NSA’s security vulnerabilities highlighted by Snowden’s leaks, rather than its surveillance. Representative Michelle Bachmann emphasized that the NSA should answer “how a traitor could do something like this to the American people,” and how to “prevent this from ever happening again.” She asked Alexander how damaging the leaks were to the NSA’s mission, and he responded that they were “significant and irreversible.”
Snowden has taken refuge in Hong Kong, where he conducted a live Q&A on the Guardian’s website Monday. In that conversation, he wrote that “the consent of governed is not consent if it is not informed,” and that “truth is coming, and it cannot be stopped.”
At the hearing, a member of the committee ended with a personal question about that young leaker’s fate: What’s next for Snowden?

FBI deputy director Sean Joyce answered, simply, “Justice.”

Tuesday, 18 June 2013

Google challenges US surveillance court on 1st Amendment grounds

SEATTLE (Reuters) - Google Inc asked the U.S. Foreign Intelligence Surveillance Court on Tuesday to allow it to publish aggregate numbers of national security requests it receives separately from criminal requests, on First Amendment grounds.
In its filing, Google requested the court to allow it to publish the aggregate number of national security requests it receives, including disclosures under the Foreign Intelligence Surveillance Act (FISA), claiming it as part of its First Amendment right to free speech.
"In light of the intense public interest generated by the Guardian's and Post's erroneous articles, and others that have followed them, Google seeks to increase its transparency with users and the public regarding its receipt of national security requests, if any," the Google filing said.
Google's move comes after other tech companies, including Microsoft Corp, Facebook Inc and Apple Inc released limited information about the number of surveillance requests they receive under an agreement they struck with the U.S. government last week.
Under that agreement, the companies were only allowed to disclose aggregate requests for data made by government agencies without showing the split between surveillance and criminal requests, and only for a six-month period.
The companies are scrambling to assert their independence after documents leaked to the Washington Post and the Guardian newspapers suggested they had given the U.S. government "direct access" to their computers as part of a National Security Agency program called Prism.
The disclosures about Prism, and related revelations about broad-based collection of telephone records, have triggered widespread concern and congressional hearings about the scope and extent of the information-gathering.
Google said it asked the U.S. Department of Justice and Federal Bureau of Investigation on June 11 to publish the aggregate number of national security requests, but said it was told such an act would be unlawful.
(Reporting by Bill Rigby; Editing by Richard Chang and Leslie Gevirtz)

NSA director describes surveillance as 'limited, focused' in House hearing

Keith Alexander testifies to Congress that programs revealed by Edward Snowden have stopped 'more than 50' attacks

http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/2013/6/18/1371576558877/Keith-Alexander-testifies-010.jpg

Some of the most senior intelligence and law enforcement officials in the United States strongly defended the National Security Agency's broad surveillance efforts on Tuesday, saying they had disrupted more than 50 terrorist plots around the world.
General Keith Alexander, the director of the NSA, told a rare public hearing of the House intelligence committee in Washington that the programs were "critical" to the ability of the intelligence community to protect the US.
Offering the most extensive defence yet on the efficacy of secret surveillance programs reported by the Guardian and the Washington Post, Alexander said they were "limited, focused and subject to rigorous oversight".
During the hearing, members of Congress criticised the source of the leaks, Edward Snowden, who remains free in Hong Kong. On Tuesday, Iceland said it had received an informal approach from an intermediary claiming that Snowden, a 29-year-old former NSA contractor, wanted to seek asylum there. Asked at the congressional hearing about what was next for Snowden, Alexander said: "justice".
Flanked by senior officials from the FBI, Justice Department and the Office of the Director of National Intelligence, Alexander said that two surveillance programs revealed by the Guardian and the Washington Post had "helped prevent more than 50" terrorist attacks in over 20 countries.
Most of those prevention efforts, Alexander said, came from the NSA's monitoring of foreigners' internet communications under a program known as Prism. He conceded that only 10 related to domestic terror plots.
The Obama administration officials gave more details about four cases in which information taken from the NSA's databases of foreign internet communications and millions of Americans' phone records had contributed to stopping attacks. Two of them have been previously disclosed, especially that of the 2009 arrest of would-be New York subway bomber Najibullah Zazi. That case has been sharply challenged thanks to court records as more attributable to traditional police surveillance.
Referring to the statutory authority for Prism, known as Section 702 of the 2008 Fisa Amendments Act, FBI deputy director Sean Joyce said: "Without the 702 tool, we would not have identified Najibullah Zazi."
Joyce identified two previously unknown cases that he said the surveillance efforts helped unravel. In one, a Kansas City, Missouri, man named Khalid Ouazzani was found communicating with a "known extremist" in Yemen, information that helped detect what Joyce called "nascent plotting" to bomb the New York Stock Exchange. The other, described more vaguely, allowed the US government, using the NSA's phone-records database of Americans, to revisit a case closed shortly after 9/11 for lack of evidence.
Ouazzani, however, was never convicted of plotting to bomb the stock exchange. Andrew Ames, a Justice Department spokesman, later clarified that he was convicted of "sending funds" to al-Qaida. The other case, Joyce said, involved an American who provided "financial support" to extremists in Somalia.
Two members of the Senate intelligence committee, Ron Wyden and Mark Udall, said last week that they had not seen any evidence to show that the "NSA's dragnet collection of Americans' phone records has produced any uniquely valuable intelligence".
The intelligence and law enforcement officials as subject to "checks and balances". But they clarified, in the most detail provided publicly thus far, that most of those checks are internal.
James Cole, the deputy attorney general, said that the NSA needs "reasonable, articulable suspicion" of involvement in terrorism before searching the millions of Americans' phone records that it collects. But, Cole said: "We do not have to get separate court approval for each query."
Instead, the NSA sends an "aggregate number" of times it has searched the database every 30 days to the secret Fisa court that oversees surveillance, while also sending a separate report each time NSA analysts inappropriately search the database. Alexander's deputy, Chris Ingliss, said NSA analysts searched the database 300 times in 2012 in total.
Representative Adam Schiff, Democrat of California, said that "it may be valuable to have court review prospectively".
Alexander pledged to send the House and Senate intelligence committees greater detail on the surveillance programmes' role in preventing the 50-plus plots in secret on Wednesday. But he insisted the NSA took great care internally to balance civil liberties and national security.
"I would much rather today be here to debate this point than try to explain why we failed to prevent another 9/11," he said.