Friday, December 20, 2013

The 2014 Privies - Dubious Achievements in Privacy Law

Recognizing Stupid Privacy Laws 
by Stewart Baker, Former government official now practicing law

It’s time to recognize just how stupid privacy law is getting. And what better way than by acknowledging the most dubious achievements of the year in privacy law? (more)


My favorite - Judge Uncovers Wiretap Plot with 425 Million Co-Conspirators
(Scroll down to Category 3 - "Dumbest Privacy Cases of the Year")

Slack Wiretapping Sentence Imposed for Slack Attack on Slack

WV - A former West Virginia sheriff convicted of hacking his now ex-wife's work computer was sentenced to probation Thursday after she made an emotional plea for leniency.

Former Clay County Sheriff Miles Slack exchanged a long hug with Lisa Slack, his friends, and relatives after U.S. District Judge John T. Copenhaver sentenced him to one to two years' probation and fined him $1,000 for wiretapping...


Federal prosecutors say Slack secretly installed a keystroke logger on a computer in the county magistrate court in April where his wife worked. They were married at the time. Slack admitted he intended to monitor her activity.


Slack could have been sentenced to up to five years in prison. (more)

Thursday, December 19, 2013

Mobile Devices Will Pose The Biggest Risk In 2014, Survey Says

IT professionals are troubled by the risk of data leakage associated with employee smartphones and are focusing on bolstering endpoint security, according to a new study.

Mobile devices will pose the biggest threat in 2014, according to a survey of 676 IT and IT security professionals conducted recently by the Ponemon Institute. About three-quarters of those surveyed cited the risk posed by mobile devices as their biggest concern, up from just 9 percent in 2010.

Meanwhile, targeted attacks, designed with custom malware that can maintain a lengthy presence on corporate systems, is close behind as a troubling trend, the survey found. About 40 percent of those surveyed said their firm was the victim of a targeted attack in the past year, according to the survey, which was commissioned by vulnerability management vendor Lumension Security. (more)

Riga International Airport Officials - "We bought what?!?!"

Latvia - Management officials of Riga International airport were not aware of the fact that they had used budget money to buy a device that had allegedly allowed the airport’s security listen in on employees’ telephone conversations.

Security Police has launched an investigation about this possible crime.

After learning of the possible wiretapping into employees’ telephone conversations, the Board of the airport dismissed the head of its Security Department Raimonds Lazdins and two other employees. Equipment meant for wiretapping was found in the airport. (more)

Tuesday, December 17, 2013

NSA Lawsuit Ruling

Washington – A federal district judge ruled on Monday that the National Security Agency program that is systematically keeping records of all Americans’ phone calls most likely violates the Constitution, describing its technology as “almost Orwellian” and suggesting that James Madison would be “aghast” to learn that the government was encroaching on liberty in such a way.

The judge, Richard J. Leon of Federal District Court for the District of Columbia, ordered the government to stop collecting data on the personal calls of the two plaintiffs in the case and to destroy the records of their calling history. But Judge Leon, appointed to the bench in 2002 by President George W. Bush, stayed his injunction “in light of the significant national security interests at stake in this case and the novelty of the constitutional issues,” allowing the government time to appeal it, which he said could take at least six months.

“I cannot imagine a more ‘indiscriminate’ and ‘arbitrary’ invasion than this systematic and high-tech collection and retention of personal data on virtually every single citizen for purposes of querying and analyzing it without prior judicial approval,” Judge Leon wrote in a 68-page ruling. “Surely, such a program infringes on ‘that degree of privacy’ that the founders enshrined in the Fourth Amendment,” which prohibits unreasonable searches and seizures. (more)

A Flashlight that Follows Your Path... in addition to lighting it.

The Android flashlight app, Brightest Flashlight!

GoldenShores Technologies, LLC, is using the onboard GPS to make money on a free app by selling the anonymized user data it collects. And, the amount is not trivial; over one million people have downloaded the flashlight app.

The reason this information finally surfaced was because the Federal Trade Commission (FTC) became involved, eventually issuing an official complaint against Goldenshores Technologies (PDF)... (more)

Camera Vendor Admits to Police Headquarters Bugging Mistake

Listening devices in Edison police headquarters secretly recorded officers, attorneys, civilians...
 

NJ - Private conversations, including legally protected attorney-client discussions, have been secretly recorded inside Edison police headquarters, prompting calls for state and federal investigations and stoking new tensions in a department long wracked by internal strife.

The conversations were picked up by dozens of audio-enabled surveillance cameras installed throughout the building in January.

At the time, Police Chief Thomas Bryan assured Edison’s mayor and business administrator, along with wary union officials, that microphones on the cameras would be disabled to guard against an invasion of privacy, the officials said. Officers learned otherwise last weekend... (more)

Monday, December 16, 2013

NSA News Flash

* Judge: NSA Phone Spying 'Almost Certainly' Unconstitutional 
* Ruling Deals a Blow to NSA Records-Collection Methods 
* Lengthy Federal Court Process Still Ahead for NSA Spying 
(MORE TO COME)

Saturday, December 14, 2013

Opinion - IT Should Ban Google Glass Before It's Too Late

IT Should Ban Google Glass Before It's Too Late

Google's soon-to-be-publicly-available wearable technology exposes your company to problems ranging from illegal wiretapping and surveillance to a wild spectrum of inappropriate uses.  

Columnist Rob Enderle writes that you should do yourself a favor and ban Google Glass before it is even available to your employees. (more)

Coach with The Bush School Accused of Spycam'ing Female Students

WA - A Seattle private school has put a coach and substitute teacher on administrative leave after he was arrested and charged with voyeurism.

Jason Paur, a 43-year-old teacher with The Bush School, was arrested in British Columbia Tuesday while on a school sponsored ski team trip.

Pauer is accused of putting a video camera in a room where female students were staying. Police have also charged him with possessing child porn and breaking and entering. (more)

Fargo - A homespun spycam story.

ND - Police from two separate cities are investigating KVLY-KXJB reporter Mellaney Moore after the station aired her hidden camera story about local school security.

Jerry Lundegaard, town car salesman, upon hearing the news.
According to Moore’s story, she entered three schools, one in West Fargo, one in Fargo and one in Moorhead, MN, to test school security. “She had a hidden camera and was not stopped by any school official.

The Forum of Fargo-Moorhead reports police in Moorhead, MN, and West Fargo are now looking into whether she should face charges. “The concern we had was that they were specifically doing something that wasn’t lawful,” Moorhead police Lt. Tory Jacobson told The Forum. (more)

Business Espionage - "Corn ain't just chicken feed, Bubb"

Two Chinese agricultural scientists face charges after they were caught trying to smuggle a variety of seeds — stolen from a biopharmaceutical plant in Kansas — into China, Reuters reports.

After a tour of agricultural facilities and universities in the Midwest and Arkansas, the two Chinese nationals were caught with the seeds as they boarded a plane for home, the report says. 

(In a separate, but parallel espionage case, "Investigators found ears of corn stashed in an Illinois self-storage unit, dozens of bags of corn kernels stuffed under the seat of a car, and hundreds of pictures of corn fields and production facilities.")

Don’t be fooled because they’re “just” seeds. The unidentified victim of the theft had invested about $75 million in patented technology to create the seeds, the report says. (more)

Friday, December 13, 2013

...thus bringing back traditional spycraft.

Governments around the world may be compelled to wall off their Internet systems as nations and companies move to protect sensitive data amid increasing cybercrime and espionage, Kaspersky Lab Chief Executive Officer Eugene Kaspersky said.

Cybercrime is increasing and secret documents released by former U.S. National Security Agency contractor Edward Snowden have heightened technology company concern about espionage. Some governments and corporations may even scrap information-technology systems in some cases, moving critical data back to paper, Kaspersky said. (more)

Interpretation
  • Hacking is easier than traditional spycraft.  
  • Computerization = low-hanging fruit for the business espionage and criminal crowds. 
  • Throwing security budgets to the IT folks is not effective enough. 
  • Solution... keep your secrets off the web, and out of the computers. 
  • Anticipate... Traditional spycraft (bugging, tapping, intrusions, moles, etc.)
  • Arm yourself... Put a counterespionage consultant on your team.

The Road to Farewellville

A police department in Battle Creek, Michigan is being sued by one former officer and two currently employed cops who say their superiors secretly installed a surveillance camera in the woman’s locker at a local precinct...

According to the claim, Inspector Maria Alonso of the department’s Internal Affairs Division was told in late 2012 that there had been instances of theft occurring in the women’s’ locker room of the Battle Creek Police Department. Upon approval of her superiors, Alonso installed a surveillance camera in the room sometime the following January and used evidence obtained by it to allegedly implicate a plaintiff in the case of robbing co-workers by rifling through their lockers.


Plaintiff Laurie Gillespie was shown the video shortly after and, according to the complaint, was depicted in the clip “going through at least two open lockers” while in uniform... She was ultimately terminated less than two months later. (more)

Thursday, December 12, 2013

Data Security and Breach Notification Act of 2013 & Information Security Tips

American IT departments' decisions could inadvertently put organizations at risk of an information security breach if they don't have sufficient protocols for the disposal of old electronic devices...
Despite the many public wake-up calls, most American organizations continue to be complacent about securing their electronic media and hard drives...


Congress is hoping to hold businesses accountable for the protection of confidential information with the introduction of the Data Security and Breach Notification Act of 2013, which will require organizations that acquire, maintain, store or utilize personal information to protect and secure this data. (q.v.)

Mitigation tips:
  • Think prevention, not reaction.
  • Put portable policies in place for employees with a laptop, tablet or smartphone to minimize the risk of a security compromise while traveling;
  • Protect electronic data. Ensure that obsolete electronic records are protected as well. (Remember, all that data was somewhere else before it became electronic data. Protect that too.)
  • Create a culture of security. Train all employees on information security best practices... Explain why it's important, and conduct regular security audits (including TSCM) of your office to assess security performance. (more)

Santa App Lets You Spy Back

A new app is letting family spy on Santa and his friendly elves. The free app, created by two Michigan entrepreneurs, is called Santa Spy Cam.

What do Elves pass, if not gas?
Santa Spy Cam uses magic only found at the North Pole to help parents get video of St. Nick and his friendly elves when they visit your house.

Now, what's fun about the app is it captures these special moments when kids are asleep.

How does it work? Well, the Santa Spy Cam has a built in sensor that flips on in your own home when Santa or his elves are nearby. 

"Fully approved by The North Pole Clandestine Services Bureau (NPCSB) to capture live-action video of Elves as they visit your home during the holiday season. And of course, the big visit, by the big man on Christmas Eve, Santa Claus." (more)

I just tested it. 
Works remarkable well. 
You get three free scenes; others at 99 cents each. 
~Kevin

Wednesday, December 11, 2013

Hong Kong PI's are Parents Eyes

China - Rich mainland parents are paying thousands of Hong Kong dollars to private investigators to spy on their children studying in Hong Kong, including PhD students and kindergarteners...

Philic Man Hin-nam, founder and director of Global Investigation and Security Consultancy, an all-woman detective agency, said that mainland student cases accounted for about 40 per cent of the more than 100 requests made by parents last summer for information on their children...

"Many mainland students studying in Hong Kong are single children from rich families," Liu of Wan King On Investigations said, "Those parents attach great importance to their children's behavior." (more)

New Android threats could turn some phones into remote bugging devices...

Researchers have recently uncovered two unrelated threats that have the potential to turn some Android devices into remotely controlled bugging and spying devices.

The first risk, according to researchers at antivirus provider Bitdefender, comes in the form of a software framework dubbed Widdit, which developers for more than 1,000 Android apps have used to build revenue-generating advertising capabilities into their wares...

What's more, Widdit uses an unencrypted HTTP channel to download application updates, a design decision that allows attackers on unsecured Wi-Fi networks to replace legitimate updates with malicious files. (more)

'That thing they said they're not doing? They're totally doing" - Jon Stewart

Last week The National Reconnaissance Office launched a new satellite called NROL-39 from Vandenberg Air Force Base in California, and a lot of people noticed a picture of a massive octopus straddling the earth.

"The Daily Show With Jon Stewart" has some fun with the spy logo, the choice of which drew ridicule in light of the many leaks about mass government surveillance from ex-NSA contractor Edward Snowden. 

After playing a game of 'That Thing They Said They're Not Doing? They're Totally Doing" — which involves showing clips of the U.S. government denying spying allegations only to confirm them later — Stewart went after the logo that boasts: "Nothing Is Beyond Our Reach." (more)


In 1955 an octopus taking over Earth was just science fiction. 
Perhaps the logo artist remembered this.

Tuesday, December 10, 2013

GSM A5/1 Encryption Comes to German Cell phones

Deutsche Telekom is the first network operator in Germany to deploy the A5/3 encryption standard for voice transmission in its mobile phone network. This means conversations are better protected against wiretapping, even in the GSM network... The GSM network previously implemented the A5/1 encryption standard, which experts have cracked... Telekom is not limiting rollout of the A5/3 encryption standard to Germany, either: the new technology has already been implemented in Macedonia, Montenegro, Poland and the Czech Republic. More countries will follow. (more)

$15. Girl Tech IM-ME Pager Turned Into - a Spectrum Analyzer; a Police Radio Jammer...

This isn’t something we’d encourage our readers to do, but it’s pretty fascinating that a seemingly innocuous toy has such power. 

The IM-ME is a small electronic toy made by Girl Tech that’s intended to be used as a sort of imitation cell phone, allowing users to send wireless messages to each other. 

Unfortunately, a hacker named Travis Goodspeed discovered that you can use the hardware to roam frequencies freely and even decode the metadata that prefixes radio communications, allowing a listener to identify both parties on the call. 

You can also use the thing as a spectrum analyzer and many other unintended purposes... such as jamming. (more) (video on P25)

Surveillance Cameras a Weapon in Neighborhood Feud

Scott and Terri Gale, of Kemah, Tex., are seeking a restraining order against Natalie Belk, who lives directly across the street from them, according to media reports.

The Gales say Belk’s surveillance cameras point into their master bedroom and bathroom.

The cameras were installed in September 2012, but the neighbors have been feuding since 2008 court records say. (more)


Without laser. With laser.
I guess taking their case to court is more civil than installing a permanently mounted laser pen aimed at the camera's lens. (snicker) (How to Zap a Camera)

Industrial Espionage Gets Caddy

via TechRepublic.com...
With all the recent industrial espionage, it was only a matter of time before malware developers would take a look at Computer-Aided Design (CAD) programs as a way to ex-filtrate proprietary documents and drawings from engineering firms...

The first time I read about an AutoCAD malware was last year when ESET.com reported a strange anomaly on their LiveGrid network. It was strange because the malware attacked AutoCAD, but only in Peru of all places.

After some investigation, it was determined the malware ACAD/Medre.A was a worm programmed to send AutoCAD drawings via email to an account (you guessed it) in China. The experts at ESET had this to say:

ACAD/Medre.A is a serious example of suspected industrial espionage. Every new design created by a victim is sent automatically to the authors of this malware...

Something else that ESET pointed out bothered one of my clients when I told them about ACAD/Medre.A: “The attacker may even go so far as to get patents on the product before the inventor has registered it at the patent office. The inventor may not know of the security breach until his patent claim is denied due to prior art.”


...a new trojan popped up on Trend Micro’s radar—ACM_SHENZ.A, and it was targeting AutoCAD programs. But with a twist, the malware was benign. Like most trojans, its job was to gain a foothold on the victim’s computer.

Once safely entrenched, ACM_SHENZ.A obtains administrative rights which make it simple for the malware to create network shares for all drives. The malware also opens ports: 137, 138, 139, and 445. Doing so allows access to files, printers, and serial ports.

Obtaining administrative rights also allows the attacker to plant additional malware. It’s this additional malware, experts at Trend Micro suspect will be used to steal drawings and engineering documents...


CAD drawings are now a valid attack vector. (more)

Monday, December 9, 2013

On "Free" Security Apps...

I came across a new smartphone security app the other day which caught my eye. It promised...
  • Free and secure phone calls.
  • Send self-destructing messages.
  • Recall or remotely wipe sent messages.
  • Safely share private photos and videos.
  • Photo vault to hide photos and videos.
  • Hide text messages, contacts, call logs.
  • Private vault for documents, notes and diary.
Just load the app on your phone (and the people you want to communicate with), and you're good to go. It sounded like something which my readers would like to know about. I downloaded it with the thought of giving it a try. But then, I thought again.

In my mind, I could hear my father saying, "there is no free lunch, if it looks too good to be true..." The years have always proven him correct.

The app's web site had a foreign country URL. Not a big issue. Perhaps it was the only place where the site's name was available. A little more digging and I came up with a company address here in the United States; a residential address. Again, not a big issue. The company is just over a year old, they have no other products, and software development from home is common. Both the Chairman and CEO of the company have names normally associated with a foreign country. I am still not phased. The United States is the world's melting pot.

A question on their FAQ page was the first red flag. "Why do you need my cell phone number to activate the service?" The answer, "we need the number so we can send you the activation code." My question is, why does a free encryption product need an activation code? It sounds like a ploy to identify users. Apparently, enough people felt this was an invasion of their privacy. The next part of the company's answer was that the code would no longer be needed after version x.xx.

The next FAQ was, "Why do you upload my contact book to your servers?" The answer smelled like more dung. Apparently, everything the app does goes through their servers.

On to the fine print. 

The product is specifically not guaranteed: not the encryption, not the self-destruction of the messages, photos or videos, nothing. They accept no liability. The are held harmless in the event transmissions are decrypted, deleted, copied, hacked, or intercepted.

Apps cost money to develop. Even allowing for ads, as these folks do, that is not enough money to justify an app this fancy (assuming it fulfills all its claims). There must be another payoff. What's worth money here? 

Information. 

People who use encryption are a select group; easy to target. For whatever reason, they feel their information is valuable. Hummm, a free security app could be great espionage tool. Let's see what information the company admits to collecting...

"We have the right to monitor..." Boom! What!?!? 

And, they collect: IP addresses, email addresses, phone numbers, address books, mobile device ID numbers, device names, OS names and versions. They can know who you are, where you are, and information about everyone you know. Even if you never use this app, if you are in the address book of someone who does, you're now coin of their realm.

"Photos and videos are cashed on servers..." and you can't delete them. They claim they will do this for you after, "a period of time."

Throughout all of this, the user's fire-of-fear is dowsed with, don't worry, it's all encrypted, no one but you can see it, trust me. Right... how about a little trust, but verify. Other security software companies allow vetting. I saw no claims that their code was independently vetted for bugs, back doors, or spyware. And, what about that "We have the right to monitor..." clause? How is that accomplished without a back door?

They, "May collect statistics about the behavior of users and transmit it to employees, contractors and affiliated organizations outside your home country." Yikes. Who are you affiliated with anyway? Please don't tell me, "if I tell you, I will have to kill you."

Here's another kicker. If they sell the company, "user information is one of the assets which would be transferred or acquired by the third party."

This may be a perfectly legitimate app. Maybe I'm paranoid. But, money, power, politics, espionage and blackmail all come to mind. Any government intelligence service, business espionage agent, or organized crime boss could have come up with this as a ruse. 

Which brings me to the moral of this story...

Before you trust any security service, vet it thoroughly. 
If your OTHBD needle starts to tremble, don't rationalize, move on. ~Kevin

Yet Another Step Closer to Eavesdropping on the Brain

Science fiction has long speculated what it would be like to peek inside a person's mind and find out what they are thinking.

Now scientists are one step closer to such technology after forging a new brain monitoring technique that could lead to the development of 'mind-reading' applications.

The breakthrough comes from a Stanford University School of Medicine study that was able to 'eavesdrop' on a person's brain activity as they performed normal functions by utilizing a series of electrodes attached to certain portions of the brain.

The process, called 'intracranial recording', was tested... (more)

How Does Santa Know?


Friday, December 6, 2013

Spy bugs found in Australia and Asia

An Australian surveillance executive whose firm was contracted by several clients to sweep for hidden mobile interceptors and other spying devices in Australia and Asia has found dozens of them.

Les Goldsmith, chief executive of ESD Group, told Fairfax Media his company found about 20 physical bugs when conducting sweeps in Australian business and local government offices, and another 68 in Asia between 2005 and 2011...

"All governments are falling victim to surveillance and some governments are falling victim to it but not saying anything," he said...


Mr Goldsmith’s remarks come as officers from Australia’s domestic spy agency ASIO raided the office of a lawyer who claimed spies bugged the cabinet room of East Timor’s government during negotiations over oil and gas deposits. It also follows news that Ecuador found a bug in its London embassy, where Julian Assange is (sic) staying...

Michael Dever, of Dever Clark + Associates, which conducts bug sweeps for government agencies, said Mr Goldsmith’s numbers were not surprising.

"Australia’s culture is pretty naive about these matters," Mr Dever said. "There’s a prevailing attitude ... among businesses that this is Australia, that this sort of stuff only happens elsewhere. But that’s not the case at all." (can be applied to most businesses in the free world)

Despite this, Mr Dever revealed that his firm had not found any bugs in Australia "in years", but said that this was likely because areas he swept were "generally secure" government or private sector facilities.

"That doesn’t mean that we’re incompetent," Mr Dever said.

"It just means that the types of places [where] we do this work ... are already low-risk anyway because of their security." (more)


A good security recipe has bug detection inspections (TSCM) as a key ingredient. Not only is TSCM a proven deterrent, it is also checks the freshness and effectiveness the other security ingredients. Cook this up right, and like Mr Dever said, your risk will be low.

Wednesday, December 4, 2013

World's Smallest Night Vision HD DV Digital Camera for under $50.00

For the PI on your shopping list who has everything...

Features:
  • The Night Vision DC DV Smallest Camera
  • Night Vision LEDs
  • Take photo, Record Video and Audio under different conditions
  • Record the special moment at any time
  • Dimensions: 4.5 x 2.8 x 1.7 cm

Specifications:
  • Pinhole 12.0M Lens
  • Image Resolution: 4032 x 3024 pixel
  • Color Video Resolution: 1920 x 1080 pixel
  • FPS: 24 frames per second
  • Image file format: JPEG
  • Video file format: AVI (MJPG)
  • Audio file format: WAV
  • Color Video and Audio
  • Built-in Rechargeable 260mAh Li-ion battery
  • Recording Time: Approx. 60 minutes
  • Memory Card: Support Micro SD/SDHC Card/TF Card
  • Weight: 41 gram
  • Dimensions: 45 x 28 x 17 mm

Package Contents:
  • 1 piece The Night Vision DC DV Smallest Camera
  • 1 piece USB Charging/Data Cable
  • 1 piece Handy Strap (more)

Tuesday, December 3, 2013

A Corporate Espionage Story

A cautionary tale...
Years ago, a restaurant owner told me how he collected the names, addresses, and phone numbers of a local competitor's customers. He had a friend put a box for a free drawing (not related to his restaurant) on the competitor's checkout counter. The contest was completely legitimate (people did win the promised prizes) and the rival gave his permission to place the box. He just didn't know entry forms would be given to the owner of a competing restaurant. With the information from the contest entries, the original restaurant owner could send coupons to many of his competitor's customers.

The individual in this example used a low-tech attack, but the story illustrates the basic concept behind all corporate espionage — gaining a competitive advantage. (more)


Moral—Business espionage is not just IT-based. All the old tricks still work, and are still used. If you are only locking the IT door, expect them to come in through the windows, chimney and sewer pipes. We can help.

The Latest Spy Trick - Infecting Computers... using sound!

Abstract of the Abstract—No network, no wireless, no access, no problem. If the computer has a microphone and speaker, you can sweet talk it into letting you have your way with it.

Abstract—Covert channels can be used to circumvent system and network policies by establishing communications that have not been considered in the design of the computing system. We construct a covert channel between different computing systems that utilizes audio modulation/demodulation to exchange data between the computing systems over the air medium. The underlying network stack is based on a communication system that was originally designed for robust underwater communication. We adapt the communication system to implement covert and stealthy communications by utilizing the near ultrasonic frequency range. We further demonstrate how the scenario of covert acoustical communication over the air medium can be extended to multi-hop communications and even to wireless mesh networks. A covert acoustical mesh network can be conceived as a botnet or malnet that is accessible via nearfield audio communications. Different applications of covert acoustical mesh networks are presented, including the use for remote keylogging over multiple hops. It is shown that the concept of a covert acoustical mesh network renders many conventional security concepts useless, as acoustical communications are usually not considered. Finally, countermeasures against covert acoustical mesh networks are discussed, including the use of lowpass filtering in computing systems and a host-based intrusion detection system for analyzing audio input and output in order to detect any irregularities. (the full paper)

Spy Speak - 21st Century Jargon Glossary

via The Guardian...
The NSA files leaked by Edward Snowden are full of intelligence services jargon. 
Decode the language...

Blackfoot
Name of an operation to bug the French mission to the UN.

Blarney
See Upstream.

Boundless Informant
The National Security Agency's internal analytic tool that allows it to monitor surveillance country by country and program by program.

Bruneau (or Hemlock)
The codenames given to the Italian embassy in Washington by the NSA.

Bluf
Stands for "bottom line up front" – a request from NSA analysts to collect less data from the Muscular program (see below) because it is of no intelligence value.

Bullrun
The NSA's efforts to undermine encryption technology that protects email accounts, banking transactions and official records. The UK has a similar programme, with both codenamed after civil war battles: Bullrun for the NSA and Edgehill for GCHQ.

Cheesy Name
A GCHQ program that selects encryption keys that might be vulnerable to being cracked.

Dishfire
Database that stores text messages, for future use.

DNI (digital network information)
Data sent across computer networks, such as web page requests, emails, voice over IP. (Formally, any information sent as "packets").

DNR (dialled number records)
The metadata around phone calls, including the sending and receiving of phone numbers, call time and duration.

Dropmire
A surveillance method that involves bugging encrypted fax machines. Used to spy on the European Union embassy in New York.

Edgehill
See Bullrun.

FISA court
The foreign intelligence surveillance court, a secret US court which oversees surveillance under the FISA Act.

Fairview
See Upstream.

Five Eyes
Britain, the US, Canada, Australia and New Zealand – the club of English-speaking countries sharing intelligence.

GCHQ
Government Communications Headquarters, the UK intelligence agency focusing on signals and communications intelligence.

Genie
An NSA surveillance project to remotely implant spyware into overseas computers, including those in foreign embassies.

Humint
Short for "human intelligence", refers to information gleaned directly from sources or undercover agents. See also Sigint.

Keyhole
Code for images gathered by satellites.

Klondyke
The mission to snoop on the Greek embassy in Washington.

Mainway
The database where the NSA stores metadata of millions of phone calls for up to a year.

Marina
The database where the NSA stores metadata of millions of internet users for up to a year.

Metadata
The "envelope" of a phone call or email, which could include the time, the duration, the phone numbers or email addresses, and the location of both parties.

Muscular
Program to intercept Google and Yahoo traffic, exposed by the Washington Post.

Noforn
"Not for foreign distribution" – a classification of some of the Snowden slides.

NSA
The National Security Agency, the US agency, responsible for collecting and analysing intelligence, plus cybersecurity.

Oakstar
See Upstream.

Operation Socialist
The name of a GCHQ cyber-attack on Belgium's main telecoms provider, Belgacom.

Perdido
The codename for the bugging of EU missions in New York and Washington.

Polar Breeze
A technique for tapping into nearby computers.

Powell
The operation to snoop on the Greek UN mission.

Prism
A programme to collect data from internet companies including Google, Microsoft, Facebook and Apple.

Rampart-T
Spying efforts against leaders of China, Russia and several eastern European states.

Royal Concierge
A GCHQ surveillance project to track foreign diplomats' movements by monitoring the booking systems of high‑class hotels.

Sigint
Short for "signals intelligence", or information gathered through the interception of signals between people or computers. See also Humint.

Snacks
The NSA's Social Network Analysis Collaboration Knowledge Services, which analyses social hierarchies through text messages.

Stormbrew
See Upstream.

Tempora
A GCHQ programme to create a large-scale "internet buffer", storing internet content for three days and metadata for up to 30.

Tor
Free software allowing users to communicate anonymously.

Tracfin
Database storing information from credit card transactions

Turbulence, Turmoil and Tumult
Data analysis tools used by the NSA to sift through the enormous amount of internet traffic that it sees, looking for connections to target.

Upstream
Refers to bulk-intercept programs, codenamed Fairview, Stormbrew, Oakstar and Blarney, to intercept data in huge fibre-optic communications cables.

Verizon
One of America's largest telecoms providers, from which the NSA collects the phone records (metadata) of millions of customers.

Wabash
The codename given to the bugging of the French embassy in Washington.

XKeyscore
An NSA program that allows analysts to search vast databases of emails, online chats and browsing histories of millions of individuals, with no prior authorisation. (more)

Monday, December 2, 2013

Jalta Hotel opens its 1950s anti-nuclear bunker and listening post to the public

If you were a VIP who stayed at Prague’s Jalta Hotel between 1958 and 1989, your room was bugged and your phone was tapped. Behind its attractive 1950s façade, the hotel has been hiding a secret – there was a 24-hour underground spying operation that listened in on guests.

From an anti-nuclear bunker 20 meters below Wenceslas Square, communist officials monitored the hotel’s foreign guests with a large bank of listening equipment that only a select few ever knew existed. None of the hotel staff were allowed to go into or even talk about the basement. And while communism ended in 1989, the bunker remained in the possession of the Ministry of Defense until 1998, when they finally declassified its existence and turned it over, as is, to the hotel.

Anti-nuclear Bunker and Cold War Museum
When: Mon. and Wed. or Tue. and Thu (alternating weeks) 5–8 p.m.
Where: Jalta Hotel, Wenceslas Square 45/818
Reservations required: call 222 822 111 or e-mail concierge@hoteljalta.com
Tickets: 75 Kč or 3 euros

Eavesdropping Helped Win the American Revolution

The ongoing scandal involving the NSA and eavesdropping on phone and email conversations around the globe, of friend and foe alike, might have you thinking the organized espionage business is relatively recent here. Not true.

It’s older than the country itself. It played a major role in winning our independence from Britain and its birth came about because of something that happened in New Jersey... (more)

The Patroits — Still Being Accused of Spying

Houston defensive end Antonio Smith questioned how New England knew what the Texans were going to do on defense after a 34-31 win by the Patriots on Sunday.

Smith told reporters after the game Houston had some new wrinkles in its defense this week and it was “miraculous” how the Patriots changed their offense to key on the defense.

“Either teams are spying on us or scouting us,” he said. “I don’t know what it is.”

The NFL fined New England coach Bill Belichick $500,000 and the team $250,000 and took away a first-round pick in the 2008 draft for videotaping New York Jets signals during a game on Sept. 9, 2007. Belichick said he thought that was allowed and apologized for what he said was a mistake in his interpretation of the rule prohibiting it. (more) (Why Is Sports Crime Different?)

Saturday, November 30, 2013

New Spy Camera Takes 3D Photos in Almost Complete Darkness

Spies operating under the cover of darkness might find that their job is about to get easier as U.S. scientists have developed a camera that can take photographs of objects and people that are only very dimly lit.

 The camera works by reconstructing 3D images from photons reflected from barely visible objects.

The technology could be used in next generation spy cameras... (more)

German Report on Industrial Espionage

EU Takes Aim at Industrial Espionage

Brussels is taking aim at industrial espionage with proposals to tighten laws so businesses can better safeguard their “trade secrets” from prying rivals.

The reforms put forward by Michel Barnier, the EU single market commissioner, aim to bolster defences against unlawful acquisition of information that is commercially valuable and secret but not covered by a patent...


Trade secrets range can range from anything from technical processes for making bathplugs, to innovative marketing strategies, valuable customer lists, or recipes for market-beating cakes or pies.

Unlike a book or trademark or patented technology, the holder of a trade secret has no exclusive right to it. Rivals seeking to close a competitive gap can legally reverse engineer the information. The proposed reforms, unveiled on Thursday, only target methods for obtaining information that are illegal, such as espionage, bribery or theft.

Mr Barnier said: “Cybercrime and industrial espionage are unfortunately part of the reality that businesses in Europe face every day. We have to make sure our laws move with the times and that the strategic assets of our companies are adequately protected against theft and misuse.” (more)

Thursday, November 28, 2013

Columbia Engineers Make World’s Smallest FM Radio Transmitter

A team of Columbia Engineering researchers...

led by Mechanical Engineering Professor James Hone and Electrical Engineering Professor Kenneth Shepard, has taken advantage of graphene’s special properties—its mechanical strength and electrical conduction—and created a nano-mechanical system that can create FM signals, in effect the world’s smallest FM radio transmitter. The study is published online on November 17, in Nature Nanotechnology. (more) (what was transmitted)

Wednesday, November 27, 2013

U.N. - End Excessive Electronic Spying

A U.N. General Assembly committee on Tuesday called for an end to excessive electronic surveillance and expressed concern at the harm such scrutiny, including spying in foreign states and the mass collection of personal data, may have on human rights.

The U.N. General Assembly's Third Committee, which deals with human rights issues, adopted the German and Brazilian-drafted resolution by consensus. It is expected to be put to a vote in the 193-member General Assembly next month.
"For the first time in the framework of the United Nations this resolution unequivocally states that the same rights that people have offline must also be protected online," German U.N. Ambassador Peter Wittig told the committee.

The United States, Britain, Australia, Canada and New Zealand - known as the Five Eyes surveillance alliance - supported the draft resolution after language that had initially suggested foreign spying could be a human rights violation was weakened to appease them. (more)

TUMs Solves Wireless Security Headache. Warning: explanation gives headache.

Researchers at the Technische Universität München (TUM) have proven that wireless communications can be made more secure through a novel approach based on information theory."
The method is counter-intuitive and involves information theory and zero capacity channels. "The scheme uses two physical channels – that is, frequency bands in a wireless system – that are inherently useless, each being incapable of securely transmitting a message," says TUM.

Intuitively, combining one zero-capacity with another zero-capacity should result in zero capacity. “But in this case,” Schaefer explains, “it’s as if we’re getting a positive result from adding zero to zero. We find that we are able to ‘super-activate’ the whole system, meaning that combining two useless channels can lead to a positive capacity to transmit confidential messages securely.”

Superactivation is not unknown in quantum theory. It's the combining of zero capacity quantum channels to produce a channel with positive capacity; but is not yet applicable to current technology. But what Boche and Schaefer have achieved "is," says Boche, "the first example of super-activation – where zero plus zero is greater than zero – in classical communication scenarios.”

Huh?

Why Care About the NSA?

Tuesday, November 26, 2013

Protesters Capture Government Surveillance Van

The Security Service of Ukraine, the nation’s intelligence agency, have its white mini-van back, courtesy of the Berkut anti-riot police officers.

Demonstrators seized the van during a protest rally on the evening of Nov. 25, suspecting that it contained sophisticated equipment for eavesdropping on telephone conversations of protest leaders.

The taking of the van prompted clashes last night between police and protesters. After a 30-minute standoff, punctuated by fighting, the demonstrators recovered evidence from the van and the police reclaimed it.

Opposition lawmaker Mykola Kniazhytsky posted a picture of a passport, car tag numbers and what he said were technical listening devices found in the van on his Facebook page. Opposition leaders promised to analyze the recordings and release their findings. 



 

Equipment believed to be listening devices found in the white mini-van that SBU officers were using while parked near European Square.

That left officials trying to explain what the van was doing at the protest site...

 


License plates that protesters say they found inside a van used by SBU officers that was parked near European Square...


According to eyewitnesses, protesters overtook the van, prompting hundreds of riot police to descend on the scene, triggering the violent clashes. An SBU officer in the van eventually escaped with police help, while the leaders of the demonstration took to the stage in triumph after police backed off about 9 p.m. (more) (video footage)

Indonesia Posts Truth About Government Spying

Indonesia's former spy chief has said intelligence agencies tapping the phones of national leaders is "normal", and dismissed as an overreaction Jakarta's furious response to reports Australia spied on the president's calls. (more)

Monday, November 25, 2013

Smart TVs Lie to You

So-called "smart TVs" have hit the marketplace, essentially turning TVs into computers that let watchers search for videos, install applications or interact with ads. But that connectivity may be a two-way street, as manufacturer LG investigates claims that its line of smart TVs is collecting data on its customers. 

According to an LG corporate video, "LG Smart Ad analyses users' favorite programs, online behavior, search keywords and other information to offer relevant ads to target audiences. For example, LG Smart Ad can feature sharp suits to men or alluring cosmetics and fragrances to women." 

But what happens when your online behavior trends just a bit naughtier than clothes or cosmetics? Meghan Lopez talks to RT web producer Andrew Blake about spying smart TVs and other trending tech topics in this week's Tech Report. (more)

In  other news...
LG has admitted it continued collecting data on viewing habits even after users had activated a privacy setting designed to prevent it.

The TV manufacturer has apologized to its customers and said it would issue an update to correct the problem. (more)

DIY Surveillance in India Shows Eye-Popping Growth

India's electronic surveillance market - currently at Rs 10 billion ($160,393,125.35 USD) — is growing at a rate of 25% per year as a growing number of people opt for DIY surveillance. 
Cameras are being installed everywhere — outside buildings to prevent burglaries, in cars to keep track of whether the chauffeur is giving unauthorized lifts, inside homes so that people can keep an eye on everything from nannies to grannies. Even the pet dog has a watchful eye on him, as does the teen. 
When it comes to security, privacy concerns go out the window - the one with the CCTV attached. (more)

Not to be Out-Spooked by the NSA...

The FBI is expected to reveal Thursday that because of the rise of Web-based e-mail and social networks, it's "increasingly unable" to conduct certain types of surveillance that would be possible on cellular and traditional telephones.

FBI general counsel Valerie Caproni will outline what the bureau is calling the "Going Dark" problem, meaning that police can be thwarted when conducting court-authorized eavesdropping because Internet companies aren't required to build in backdoors in advance, or because technology doesn't permit it.

Any solution, according to a copy of Caproni's prepared comments obtained by CNET, should include a way for police armed with wiretap orders to conduct surveillance of "Web-based e-mail, social networking sites, and peer-to-peer communications technology." (more)

Shop Owner Installs Surveillance Cameras to... watch the police!?!?

A Miami convenience store owner is fed up with his employees and customers being allegedly harassed by police. So he installs surveillance video to get evidence against the local cops. (more)

Help The OSS Society Pass a Law (It's easy.)

What is The OSS Society?
The Office of Strategic Services Society celebrates the historic accomplishments of the OSS during World War II, the first organized effort by the United States to implement a centralized system of strategic intelligence and the predecessor to the US intelligence and special operations communities. It educates the American public regarding the continuing importance of strategic intelligence and special operations to the preservation of freedom in this country and around the world.

Why pass a law?
The OSS was the World War II predecessor to the U.S. intelligence and special operations communities. It was founded and led by the legendary General William "Wild Bill" Donovan, the only American to receive our nation's four highest military honors, including the Medal of Honor. President Roosevelt called General Donovan his "secret legs."

When General Donovan died in 1959, President Eisenhower said: "What a man! We have lost the last hero."

It's time to honor the "last hero" and all the heroes of the OSS with the Congressional Gold Medal. (more)

Click each link below to show support...
S. 1688 and H.R. 3544: A bill to award the Congressional Gold Medal to the members of the Office of Strategic Services (OSS), collectively, in recognition of their superior service and major contributions during World War II.

Bond Car Submarines at Auction

A car that transformed into a submarine in the James Bond movie "The Spy Who Loved Me" has been sold at a London auction for 550,000 pounds ($865,000).

The sale price was below the auction house's initial estimate price of 650,000 to 950,000 pounds — perhaps because the vehicle (a distinctively-shaped white Lotus Esprit) cannot be driven on the road, although it is said to be a fully operational submarine. (more)

Friday, November 22, 2013

REPORT: Corporate Espionage Against Nonprofit Organizations

How common is corporate espionage against nonprofits?
Most of the cases of corporate espionage we know about in recent years have been uncovered by accident. There has been no comprehensive, systematic effort by federal or state government to determine how much corporate espionage is actually occurring, and what tactics are being used. It is likely that corporate espionage against nonprofits occurs much more often than is known. 

Get the "T"
Who actually conducts the espionage?
When a nonprofit campaign is so successful that it may impair a company’s profits or reputation, companies may employ their own in house espionage capabilities, or they may retain the services of an intermediary with experience in espionage...

The intermediary may hire a private investigations firm that either has multiple espionage capacities or that specializes in the particular kind of intelligence needed – such as human intelligence and the infiltration of nonprofits, or electronic or physical surveillance. These private investigations firms may subcontract out espionage to experienced operatives, which gives corporations access to specialized talent while further increasing the level of plausible deny-ability...

 
Corporations may also hire the services of experienced nonprofit infiltrators who may pose as volunteers, to scout out workplaces and to steal documents left unattended or unguarded. Corporate spies may also plant bugs to obtain and transmit verbal communication. Both offices and homes may be targeted for the gathering of physical intelligence. (more)

Security Directors: FREE Security White Paper - "Surreptitious Workplace Recording ...and what you can do about it."   

Corporate Espionage Infographic

Infographic via David Schilling, Industry Tap.

Recent Technological Innovations Have Completely Changed the Game of Espionage

According to the FBI, competitors criminally seek economic intelligence by aggressively recruiting employees and conduct economic intelligence through bribery, cyber attacks, theft of property, dumpster diving and wiretapping.  

They also establish seemingly-innocent business relationships between foreign companies and U.S. industries to gather economic intelligence, including trade secrets. 

Technologies Used for Espionage

Many of the technologies now used for espionage are just updated versions of previous technology: smaller, lighter and orders of magnitude more powerful.

  • Spying Equipment
  • Spy Cameras
  • Lock Picks
  • Computer Hacking
  • Network Intrusion
  • Video Pen Cameras
  • Miniature Cameras
  • Mobile Phone Spy Gadgets
  • Call Recorders
  • SIM Card Readers
  • Stun Guns Looking Like Cell Phones
  • Telebugs
  • Bionic Ear Boosters
  • Voice Changers
  • Audio Jammers
  • Wireless Video Cameras
  • Pinhole Video Cameras
  • Google Glass type sunglasses, or glasses that record video, pictures and sound
  • Asset Tracking Devices
  • GPS Tracking Devices
Equipment to Protect You from Spies
  • Cellphone Detectors
  • Bug Detectors
  • Thermal Vision
  • Surveillance Cameras (more)
And, of course, us.

Wednesday, November 20, 2013

Audio Surveillance Laws (Party Consent) by State

Click here for statutes.
Click to enlarge.

Mass Surveillance Is Big Business: Corporations Are as Good at Spying as Governments

Data is the currency of surveillance, and it's not just the NSA and GCHQ looking to cash in. As a newly released cache of documents and presentation materials highlights, the private surveillance industry is booming. More shocking is that many firms claim in their own corporate PowerPoints that they've got capabilities that rival that of the government giants.

The document trove, called the Surveillance Industry Index (SII) and released by Privacy International, and contains 1,203 documents from 338 companies in 36 countries, all of which detail surveillance technologies...
 

Of course, that world isn't open to average consumers, which is why SII—and previously, Wikileaks' Spy Files, among others—is eye-opening. What's even more concerning than systems that guarantee "complete data inflow from all networks" is who's buying it. And while all the brochures I've read so far are careful to specify that surveillance tech is only for legal data collection, "legal" is a very fluid term worldwide...

There's a very good reason that the UN High Commissioner called privacy a human right earlier this year: The vast tools available to people with enough money and network access are more capable of accessing private information than ever before...

"There is a culture of impunity permeating across the private surveillance market, given that there are no strict export controls on the sale of this technology, as there on the sale of conventional weapons,"
Matthew Rice, a research consultant with Privacy International, told The Guardian. (more)