Showing posts with label surveillance. Show all posts
Showing posts with label surveillance. Show all posts

Friday, 27 September 2013

NSA: Surveillance court says no upper limit on phone records collection

A U.S. surveillance court has given the National Security Agency no limit on the number of U.S. telephone records it collects in the name of fighting terrorism, the NSA director said Thursday.

The NSA intends to collect all U.S. telephone records and put them in a searchable “lock box” in the interest of national security, General Keith Alexander, the NSA’s director, told U.S. senators.

“There is no upper limit” on NSA telephone-records collection, Alexander said. “I believe it is in the nation’s best interest to put all the phone records into a lock box that we can search when the nation needs to do it.”

The NSA would need to notify the U.S. Foreign Intelligence Surveillance Court and Congress before collecting some other types of U.S. communications, including mobile-phone location information, Alexander told senators. The NSA doesn't currently have plans to collect mobile-phone location information, he said.

Alexander, other intelligence officials and several members of the Senate Select Committee on Intelligence defended the NSA’s data collection and surveillance efforts during a committee hearing.

The NSA collection of U.S. phone records, disclosed by former NSA contractor Edward Snowden earlier this year, are “lawful, effective and constitutional,” said Senator Dianne Feinstein, a California Democrat and chairwoman of the committee.

Nevertheless, Feinstein said she's working on a bill that would add transparency to the data collection process at the NSA and the surveillance court. Some of the provisions she described would reinforce current NSA practices, but the bill would also give the NSA new authority to continue to conduct surveillance on foreign suspects who enter the U.S. while the agency seeks court-ordered warrants.

Feinstein, chairwoman of the committee that's supposed to oversee the NSA surveillance programs, at one point interrupted witness Tim Edgar, a former director of privacy and civil liberties for the White House, when he talked about the NSA's unauthorized collection of some U.S. communications. Feinstein defended the NSA, saying the agency immediately reported the mistake to the surveillance court.

"I really believe the NSA is extraordinarily careful in what they do," she said. "I have great faith in the NSA."

Alexander, Director of National Intelligence James Clapper, and some committee members blamed what they called inaccurate media reports on the Snowden leaks for creating an environment of mistrust in the NSA by the general public.

Some media organizations are feeding “raw meat to people who refuse to look at the facts” that the NSA’s data collections are legal and protect privacy, said Senator Dan Coats, an Indiana Republican.

“It’s very frustrating to know that we have programs that comply with the law, that have been approved by the Congress, that have been approved by the president of the United States, that are saving Americans’ lives, and there are efforts to compromise those programs to convince a nontrusting public,” Coats said. “Had we not had these programs in place, I’d hate to think of what we’d be talking about” at the hearing.

Clapper agreed with Coats. Intelligence officials are frustrated in their efforts to “counter the popular narrative” about the surveillance programs, he said.

But Senator Ron Wyden, an Oregon Democrat and critic of the NSA programs, pointed his finger back at U.S. intelligence officials. Abuses alleged in the NSA programs were bound to be made public, said Wyden, who introduced legislation Wednesday that would prohibit bulk collection of phone records by the NSA.

“I believe that any government official who thought that the intrusive, constitutionally flawed surveillance system would never be disclosed was ignoring history,” Wyden said. “The leadership of your agencies built an intelligence collection system that repeatedly deceived the American people. Time and time again, the American people were told one thing about domestic surveillance in public forums, while government agencies did something else in private.”

Updated at 3:25 p.m. PT with additional information about mobile-phone location data collection.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

Monday, 9 September 2013

Are password managers safe from the NSA surveillance?

The NSA is decrypting all things. You might have your passwords stored with a password management tool, such as the popular LastPass or 1Password apps. Should you be worried? Yes and no.

148186-hp_090403

This question was posed on Quora: Is it reasonable to assume that developers of popular password management software (LastPass,...) are/will be forced by law enforcement to install backdoors in their encryption algorithms?

Two employees of AgileBits, the developers of 1Password, chimed in to say they do not have your data nor your master password, and so they don't have the ability to intercept or decrypt your 1Password file. AgileBits posted this blog post when all internet security/privacy hell broke loose.

However, the issue goes a bit beyond whether the government can get at your data. Given the craziness with Lavabit shutting down due to government pressure, it's not outside the realm of reason that the government could compel developers to weaken their systems. Jeffrey Goldberg offers on Quora, however, a few reassurances:

So here are a few things to keep in mind:

We have developers in four different countries. (CA, US, UK, NL). It would be difficult to gag all of us. Lavabit has set a precedent in how to respond. I like to think that we would take the legal and financial consequences of refusing to comply, but of course that is an easy thing to say now. Nobody really knows what kind of pressure governments could put on us or how we would personally respond. We are very open about our data design and security architecture. That should make it harder to deliberately weaken it without detection.Password managers are not, in general, communication tools. Perhaps that would make us of less interest. If the NSA/FBI/TLA is seriously after a particular 1Password user it would probably be easier (and less likely to be detected) to attack the targets operating system than to force us to change 1Password's design. That is, it is easier to go around 1Password instead of through it. 

Still I remain cautiously optimistic that we will never be confronted with such a request, largely because of increased public awareness. The risks of the TLAs getting caught doing something like that and there being a public outcry is very substantial. They lost the Crypto Wars back in the 90s. They are not off to a good start in Crypto Wars II.

So could they compel us to sabotage our product and cheat our customers? Not with out a very high risk to that becoming public. Would they try it? I still don't think so.

If you use the cloud sync option (storing the 1Password file on Dropbox so you can use it on different devices), it's more risky, since that data can be easily obtained by US government.

Like 1Password, LastPass also doesn't have your encryption key, but it might be more risky because the (encrypted) data travels back and forth between your computer and LastPass's servers.

And there's that whole thing about the NSA circumventing or cracking encryption. From Pro Publica:

The National Security Agency is winning its long-running secret war on encryption, using supercomputers, technical trickery, court orders and behind-the-scenes persuasion to undermine the major tools protecting the privacy of everyday communications in the Internet age, according to newly disclosed documents.

The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.

For those concerned, the safest password manager—whether we're talking about the government or hackers--is one that stores your encrypted data locally, bypassing the cloud. KeePass, for example. However, this comes with a convenience cost when you want to keep your data in sync.


View the original article here

Thursday, 5 September 2013

Most Internet users take steps to avoid surveillance

IDG News Service - A majority of U.S. Internet users polled in a recent survey report taking steps to remove or mask their digital footprints online, according to a report from the Pew Research Center's Internet Project and Carnegie Mellon University.

While 86 percent of the Internet users polled said they made some attempt hide what they do online, more than half of the Web users also said they have taken steps to avoid observation by organizations, specific people or the government, according to the survey.

The survey's findings are based on telephone interviews among a sample of 1,002 adults, age 18 or older in July, with 792 Internet users among the respondents.

People use a variety of measures to decrease their online visibility, the study showed. The most popular one is clearing cookie and browser history, which 64 percent of Internet users polled said they did. Forty-one percent said they deleted or edited something they had posted in the past and 41 percent said they disabled or turned off their browsers' use of cookies, Pew said.

Other measures taken to cloak online activity were not using websites that asked to disclose a user's real name (36 percent of users polled), using a temporary user name or email address (26 percent), posting comments without revealing who you are (25 percent). Twenty-one percent of the Internet users polled said they had asked others to remove something that was posted about them.

Some Internet users also use public computers to browse and give inaccurate information about themselves, while 14 percent said they at times encrypt email and 14 percent said they use services like virtual networks or proxy servers such as Tor anonymity software, which allow them to browse without being tied to a specific IP address, the survey found.

Beyond general measures taken to go online more or less anonymously, the majority of Internet users polled (55 percent) have tried to avoid observation by specific people or groups. "Hackers, criminals and advertisers are at the top of the list of groups people wish to avoid," Pew said.

But a minority of Web users said they tried to hide their online activities from certain friends, people form their past, family members or partners as well as their employers, coworkers, supervisors, companies, people that might want payment for downloaded files and to a lesser extent the government (5 percent) and law enforcement (4 percent).

However, despite these precautions 21 percent of the online adults polled said they have had an email or social media account hijacked and 11 percent said they have had vital information like Social Security numbers, bank account data, or credit cards stolen.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Most Internet users take steps to avoid surveillance

IDG News Service - A majority of U.S. Internet users polled in a recent survey report taking steps to remove or mask their digital footprints online, according to a report from the Pew Research Center's Internet Project and Carnegie Mellon University.

While 86 percent of the Internet users polled said they made some attempt hide what they do online, more than half of the Web users also said they have taken steps to avoid observation by organizations, specific people or the government, according to the survey.

The survey's findings are based on telephone interviews among a sample of 1,002 adults, age 18 or older in July, with 792 Internet users among the respondents.

People use a variety of measures to decrease their online visibility, the study showed. The most popular one is clearing cookie and browser history, which 64 percent of Internet users polled said they did. Forty-one percent said they deleted or edited something they had posted in the past and 41 percent said they disabled or turned off their browsers' use of cookies, Pew said.

Other measures taken to cloak online activity were not using websites that asked to disclose a user's real name (36 percent of users polled), using a temporary user name or email address (26 percent), posting comments without revealing who you are (25 percent). Twenty-one percent of the Internet users polled said they had asked others to remove something that was posted about them.

Some Internet users also use public computers to browse and give inaccurate information about themselves, while 14 percent said they at times encrypt email and 14 percent said they use services like virtual networks or proxy servers such as Tor anonymity software, which allow them to browse without being tied to a specific IP address, the survey found.

Beyond general measures taken to go online more or less anonymously, the majority of Internet users polled (55 percent) have tried to avoid observation by specific people or groups. "Hackers, criminals and advertisers are at the top of the list of groups people wish to avoid," Pew said.

But a minority of Web users said they tried to hide their online activities from certain friends, people form their past, family members or partners as well as their employers, coworkers, supervisors, companies, people that might want payment for downloaded files and to a lesser extent the government (5 percent) and law enforcement (4 percent).

However, despite these precautions 21 percent of the online adults polled said they have had an email or social media account hijacked and 11 percent said they have had vital information like Social Security numbers, bank account data, or credit cards stolen.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Survey: Almost 90 percent of Internet users have taken steps to avoid surveillance

A majority of U.S. Internet users polled in a recent survey report taking steps to remove or mask their digital footprints online, according to a report from the Pew Research Center’s Internet Project and Carnegie Mellon University.

While 86 percent of the Internet users polled said they made some attempt hide what they do online, more than half of the Web users also said they have taken steps to avoid observation by organizations, specific people or the government, according to the survey.

The survey’s findings are based on telephone interviews among a sample of 1002 adults, age 18 or older in July, with 792 Internet users among the respondents.

People use a variety of measures to decrease their online visibility, the study showed. The most popular one is clearing cookie and browser history, which 64 percent of Internet users polled said they did. Forty-one percent said they deleted or edited something they had posted in the past and 41 percent said they disabled or turned off their browsers’ use of cookies, Pew said.

Other measures taken to cloak online activity were not using websites that asked to disclose a user’s real name (36 percent of users polled), using a temporary user name or email address (26 percent), posting comments without revealing who you are (25 percent). Twenty-one percent of the Internet users polled said they had asked others to remove something that was posted about them.

Some Internet users also use public computers to browse and give inaccurate information about themselves, while 14 percent said they at times encrypt email and 14 percent said they use services like virtual networks or proxy servers such as Tor anonymity software, which allow them to browse without being tied to a specific IP address, the survey found.

Beyond general measures taken to go online more or less anonymously, the majority of Internet users polled (55 percent) have tried to avoid observation by specific people or groups. “Hackers, criminals and advertisers are at the top of the list of groups people wish to avoid,” Pew said.

But a minority of Web users said they tried to hide their online activities from certain friends, people form their past, family members or partners as well as their employers, coworkers, supervisors, companies, people that might want payment for downloaded files and to a lesser extent the government (5 percent) and law enforcement (4 percent).

However, despite these precautions 21 percent of the online adults polled said they have had an email or social media account hijacked and 11 percent said they have had vital information like Social Security numbers, bank account data, or credit cards stolen.

Discovering that many Internet users have tried to conceal their identity or their communications from others was the biggest surprise to the research team, they said in a news release. Not only hackers, but almost everyone has taken some action to avoid surveillance and despite their knowing that anonymity is virtually impossible, most Internet users think they should be able to avoid surveillance online, they said.

Most U.S. citizens would like to be anonymous and untracked online, at least every once in a while, but many think it is not possible to be completely anonymous online, Pew said. “This reinforces the notion that privacy is not an all-or-nothing proposition for internet users. People choose different strategies for different activities, for different content, to mask themselves from different people, at different times in their lives,” the researchers wrote.

One of the most revealing contradictions in the results of the survey is that those who have taken steps to try to avoid observation by others and those who have taken more general steps to be anonymous are more likely than others to have personal information posted online, the researchers said.

Internet users surveyed said they have a photo of themselves online (66 percent), while about half of those polled said their birth date was available online. A minority said that their email address, home address, mobile number or political affiliation was available.

A majority of Web users polled, 66 percent, said they think current privacy laws are not good enough to provide reasonable protections for people’s privacy on their online activities.

“Interestingly, there are not noteworthy differences in answers to this question associated with political or partisan points of view. Tea Party supporters, conservative Republicans, self-described moderates, and liberal Democrats are not statistically significantly different in their answers,” the researchers wrote.

Loek Essers focuses on online privacy, intellectual property, open-source and online payment issues.
More by Loek Essers, IDG News Service


View the original article here

Saturday, 31 August 2013

Microsoft: Talks with U.S. gov't on surveillance transparency break down

Negotiations have broken down between two Internet giants and U.S. government representatives over the companies' requests to publish information on the surveillance requests they receive, a Microsoft executive said Friday.

Microsoft and Google both filed lawsuits in June asking that the companies be allowed to disclose more information about U.S. government surveillance requests they receive. The two companies agreed to extend the government's deadline to respond to the lawsuits during negotiations over recent weeks, but those negotiations have failed, Microsoft General Counsel Brad Smith wrote in a blog post.

[ Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

"We hoped that these discussions would lead to an agreement acceptable to all," Smith wrote. "While we appreciate the good faith and earnest efforts by the capable Government lawyers with whom we negotiated, we are disappointed that these negotiations ended in failure."

The two companies requested that they be allowed to publish data about the number of surveillance requests they receive after former U.S. National Security Agency contractor Edward Snowden leaked information about the agency's widespread surveillance activities.

"We both remain concerned with the Government's continued unwillingness to permit us to publish sufficient data relating to Foreign Intelligence Surveillance Act (FISA) orders," Smith wrote. "We believe we have a clear right under the U.S. Constitution to share more information with the public."

U.S. Director of National Intelligence James Clapper's announcement Thursday that his office would begin to publish the total number of national security requests each year was a "good start," Smith wrote. "But the public deserves and the Constitution guarantees more than this first step."

Microsoft wants to publish information showing the number of national security demands for user content, such as the text of an email, he said. 

Microsoft and Google will move forward with their lawsuits after negotiations have broken down, Smith said. The U.S. Department of Justice has a late Friday deadline to respond to both Google's and Microsoft's lawsuits in the U.S. Foreign Intelligence Surveillance Court.

A DOJ spokesman didn't immediately respond to a request for a comment on Smith's blog post.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.


View the original article here

Microsoft: Talks with U.S. government on surveillance transparency break down

Sorry, I could not read the content fromt this page.

View the original article here

Tuesday, 30 July 2013

Opponents of NSA surveillance aren't giving up after House vote

Privacy and digital rights groups have dug in for a longer fight against massive surveillance programs at the U.S. National Security Agency, even after the House of Representatives voted last week against an amendment to curtail the agency’s data collection.

The House last Wednesday narrowly defeated an amendment to a defense spending bill that would have prohibited the NSA from the bulk collection of phone records from U.S. carriers and cut off funding for the phone records collection program as currently designed, but digital rights groups have said the close vote gives them hope of weakening support for the NSA programs in Congress.

Lawmakers have introduced several bills to curb the NSA data collection, and privacy advocates may push for another amendment to a bill on the House or Senate floor, said David Segal, executive director at Demand Progress, a digital rights group.

The vote last Wednesday “demonstrated that a majority of rank-and-file members agree with us, while the institutionalists—leadership, committee chairs—disagree,” he said by email. “So it could be difficult to move things through the committee process ... but there’ll be some relevant floor votes in coming months.”

Wednesday’s vote was “unnervingly close,” Sina Khanifar, a digital rights activist and organizer of DefundTheNSA.com, added in an email. “While we lost the vote, the fact that over 200 representatives were in support of the amendment, despite lobbying by the NSA and strong opposition from the White House, sends a really strong message.”

DefundTheNSA.com asks opponents of the NSA surveillance to continue to contact their lawmakers. “This isn’t over yet,” the site said. “The tide is turning against domestic surveillance.”

Members of Congress aren’t tabling the issue, either. The Senate Judiciary Committee will conduct a hearing Wednesday focused on how to strengthen privacy rights and provide more oversight of the NSA programs.

Senator Patrick Leahy, a Vermont Democrat and chairman of the Judiciary Committee, is lead sponsor of a bill that would set a higher standard for the NSA to collect domestic information and would make public more information about surveillance programs.

Testifying at the hearing will be representatives of the NSA, the Federal Bureau of Investigation, as well as surveillance critic the American Civil Liberties Union and Judge James Carr, who formerly served on the U.S. Foreign Intelligence Surveillance Court. Carr has proposed changes to the court’s processes that would allow judges there to appoint lawyers to oppose surveillance requests.

Several other lawmakers have also introduced bills that would limit the NSA’s ability to collect data.

Representative Rush Holt, a New Jersey Democrat, introduced a bill last week that would release the Patriot Act and the FISA Amendments Act, two laws that give the NSA authority to conduct antiterrorism surveillance.

On June 19, Representative Sheila Jackson Lee, a Texas Democrat, introduced the FISA Court in the Sunshine Act, which would require U.S. officials to disclose most orders of the surveillance court that include “significant legal interpretation” of surveillance laws.

And on June 7, Senator Rand Paul, a Kentucky Republican, introduced the Fourth Amendment Restoration Act, which says that the U.S. Constitution shall not be “construed to allow any agency of the United States government to search the phone records of Americans without a warrant based on probable cause.”

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service.
More by Grant Gross, IDG News Service


View the original article here

Tech firms squirm over their role in Prism surveillance

The disclosures about the National Security Agency's massive global surveillance by Edward Snowden, the former information-technology contractor who's now wanted by the U.S. government for treason, is hitting the U.S. high-tech industry hard as it tries to explain its involvement in the NSA data-collection program.

Last week, a gaggle of 22 large U.S. high-tech firms—including Apple, Facebook, Google, Microsoft, and Yahoo which have acknowledged they participate in NSA data-gathering efforts in some form, if not exactly as Snowden and some press reports have described it—begged to be freed from the secrecy about it in their pleading, public letter to President Obama, NSA director Keith Alexander, and a dozen members of Congress.

nsa

The July 18 A letter from America's high-tech powerhouses, which was also signed by almost three dozen nonprofit and trade organizations as well as six venture-capital firms, begged for "greater transparency around national security-related requests by the US government to Internet, telephone, and web-based service providers" in terms of how much information the government demands on high-tech customers and subscriber accounts and how.

The letter begged for the U.S. government to make the amount of requests the government makes related to national security for individual customer information public.

"This information about how and how often the government is using these legal authorities is important to the American people, who are entitled to have an informed public debate about the appropriateness of those authorities and their use, and to international users of US-based service providers who are concerned about the privacy and security of their communications.," the letter to President Obama, Congress, the NSA director and Director of National Intelligence, stated yesterday.

The revelations last month from Snowden about NSA's extensive involvement in U.S. high-tech firms for purposes of information collection has suddenly put the U.S. high-tech industry on the defensive as they struggle to offer an explanation about all this to their global users while still bound by secrecy under the U.S. Patriot Act. There's no indication yet from the White House or others in government that any change in the NSA spying program, which relies on the participation of U.S.-based firms, will change.

"This should be debated in a public setting," said John Dickson, principal at security firm Denim Group and a former U.S. Air Force officer, about the situation in which NSA's global surveillance is tied so clearly to U.S.-based companies. He noted the U.S. government has actually said little but the media much.

spyware privacy

This is all putting tremendous pressure on the U.S. high-tech industry, especially abroad in Europe where privacy questions may be making U.S. industry seem less competitive. This week Brad Smith, Microsoft general counsel and executive vice president, legal and corporate affairs at Microsoft, A issued a public statement that sought to clarify Microsoft's participation in the U.S. government's content gathering methods.

""Recent leaked documents have focused on the addition of HTTPS encryption to Outlook.com instant messaging, which is designed to make this content more secure as it travels across the Internet," Microsoft counsel Smith wrote. "To be clear, we do not provide any government with the ability to break the encryption, nor do we provide the government with the encryption keys. When we are legally obligated to comply with demands, we pull the specified content from our servers where it sits in an unencrypted state, and then we provide it to the government agency."

Microsoft's SkyDrive and Skype A is handled somewhat similarly in terms of government requests, Smith said. As far as enterprise and document storage for business customers, "we take steps to redirect the government to the customer directly, and we notify the customer unless we are legally prohibited from doing so," Smith stated in his July 16 post. "We have never provided any government with customer data from any of our business or government customers for national security purposes."

Smith added Microsoft got four requests related to law enforcement in 2012. "We do not provide any government with the ability to break the encryption used between our business customers and their data in the cloud, nor do we provide the government with the encryption keys."

In the meantime, it's safe to assume in this NSA leaks debacle that "the bad guys have switched tactics" and probably wouldn't use U.S.-based high-tech services, Dickson points out. And in this atmosphere of rising cyber-nationalism, the possible role of China's government and its own high-tech industry have to be asked, too, he noted.

Former head of the U.S. Central Intelligence Agency and the NSA, Gen. Michael Hayden, recently charged forward on that topic in an interview with The Australian Financial Review.

Hayden said he believes that China-based network vendor Huawei conducted clandestine activities and shared with the Chinese state "intimate and sensitive knowledge of the foreign telecommunications systems it is involved with." According to the published report, Gen. Hayden said the Huawei is a significant security threat to Australia and the U.S., has spied for the Chinese government, and intelligence agencies have evidence of this.

A Huawei spokesman, John Suffolk, Huawei's global cyber security officer, is quoted by the Australian publication yesterday as calling Hayden's remarks "unsubstantiated and defamatory" and that any critics of the company should present any evidence publicly.In an opinion piece on CNN.com today, Gen. Hayden railed openly against Edward Snowden as a national security threat, saying he "fled to China with several computers' worth of data from NSANET, one of the most highly classified and sensitive networks in American intelligence."

Hayden acknowledged that one aspect of the fallout from Snowden's leaks is that "the undeniable economic punishment that will be inflicted on American businesses for simply complying with American law."

Hayden's remarks on CNN also seem to sarcastically criticize the Europeans now complaining about the NSA activities and how they may violate European data-privacy laws. "Others, most notably in Europe, will rend their garments in faux shock and outrage that these firms have done this, all the while ignoring that these very same companies, along with their European counterparts, behave the same way when confronted with the lawful demands of the European states."

Hayden continued: "The real purpose of those complaints is competitive economic advantage, putting added burdens on or even disqualifying American firms competing in Europe for the big data and cloud services that are at the cutting edge of the global IT industry."

As if all this weren't enough, former President Jimmy Carter also spoke out yesterday on NSA global surveillance, suggesting the NSA data collection practices were harming democracy. Former president Carter also said Edward Snowden's revelations didn't really harm national security and and was actually "beneficial" because "they inform the public."

Ellen Messmer is a senior editor at Network World. She covers news and technology trends related to information security.
More by Ellen Messmer


View the original article here