Thursday, May 31, 2018

Fred Kovaleski, International Tennis-Playing CIA Spy Dies

Just coincidence?

Fred Kovaleski, whose international tennis-playing career became his cover in the 1950s while he was working as a spy for the C.I.A., died on Friday at his home in Manhattan. He was 93.

Mr. Kovaleski was well into his career on the tennis circuit, having played at Wimbledon and in tournaments abroad and in the United States, when he joined the C.I.A. in 1951 and began training in spycraft at Camp Peary, near Williamsburg, Va.

Within three years, his ability to play tennis and his Russian-language training with the C.I.A. became essential when Yuri Rastvorov, a K.G.B. lieutenant colonel and avid tennis player, defected to the United States. more

Wednesday, May 30, 2018

Randy Tanning Salon Spycam'er Nailed

WI - A man was arrested here Wednesday, May 23, after police discovered he had used a “spy camera” to view clients undressing in a tanning salon.

Randy J. Schamberger, 42, was being held in the Barron County Jail on a misdemeanor charge and a felony charge, according to a press release.

Police know of eight victims caught on camera at Sunshine Fitness and Tanning Salon in Cumberland. There could be more victims, as Schamberger admitted to viewing and deleting up to 70 other files, police said.

On April 5, a client noticed what she thought was a USB phone charger plugged into one of the wall outlets in the tanning room. When she looked closely, she realized it was actually a covert digital video camera with a memory card inside.

She turned it over to police, who found 67 video files showing numerous persons undressing and in stages of full or partial nudity inside the tanning room.

Police discovered Schamberger had used his wife’s customer key fob to gain access to the room. He admitted to buying the spy camera from Amazon in October. more
Fight back!

Drones: For Criminals and Corporate Spies, the Sky’s the Limit

Switzerland - A rogue drone found on Credit Suisse HQ’s roof; fears of acid drops into data centres: drones are the latest security threat for businesses...

Besides carrying missiles or capturing images on powerful cameras, drones are now known to carry sophisticated computers too. These can be used to hack into mobile devices – and wi-fi networks...
Up in Zurich, alarms were raised at Credit Suisse’s HQ because of a rogue drone that was found lying on the office’s rooftop 12 months ago, a source tells Spear’s. The episode was presented as a potential security breach in a confidential conference at the bank, when the drone’s hacking abilities were revealed to some of its employees worldwide. The Swiss multinational declined to comment.


As well as stealing data potentially worth millions, these drones can drop acid into data centres to achieve a complete system shutdown... more

War-Flying Drone - WiFi Hacking video

Micro HD Video Camera

Just a reminder about how small spycams can be...

Tuesday, May 29, 2018

Amazon Echo/ Google Home/ HomePod spying on you? Fight Back!

The recent incident of a smart speaker secretly recording a couple’s conversation and sending it to one of their contacts has implanted a seed of doubt in every smart speaker’s user. 


While manufacturers assure their customers of protecting their privacy, it often gets tough to believe in their claims.

Following some simple steps can ensure you aren’t spied by your smart speaker.
  • Mute the microphone/camera when not needed...
  • Turn up the volume to the max...
  • Keep it disconnected from the Wi-Fi...
  • Don’t give access to contacts...
  • Turn off calling and messaging...
  • Lastly, don’t buy one, if you are suspicious... more
Need some smartphone security tips?
Check here.

In other news...
Facebook is now delaying the release of its smart speaker, based on widespread fears of eavesdropping and unauthorized audio recording. Those fears appeared in a recent focus group conducted by the social network... or, Because There’s No Way In Hell Any Sane Person Is Buying That Right Now. more

World's First Ultrasound 'Firewall' for Smartphones

Scientists have developed the first ultrasound-firewall that can prevent hackers from eavesdropping on hidden data transmission between smartphones and other mobile devices.

The permanent networking of mobile devices can endanger the privacy of users and lead to new forms of monitoring. New technologies such as Google Nearby and Silverpush use ultrasonic sounds to exchange information between devices via loudspeakers and microphones.

More and more of our devices communicate via this inaudible communication channel. Ultrasonic communication allows devices to be paired and information to be exchanged. It also makes it possible to track users and their behavior over a number of devices, much like cookies on the Web. Almost every device with a microphone and a loudspeaker can send and receive ultrasonic sounds. Users are usually unaware of this inaudible and hidden data transmission.

Researchers from the St Polten University of Applied Sciences in Austria has developed a mobile application that detects acoustic cookies, brings them to the attention of users and if desired, blocks the tracking. The app is, in a sense, the first available ultrasound-firewall for smartphones and tablets... more

Saturday, May 26, 2018

The Great Seal Bug Story - 58 Years Ago Today

In 1946, Soviet school children presented a two foot wooden replica of the Great Seal of the United States to Ambassador Averell Harriman.

May 26, 1960 – Ambassador Henry Cabot Lodge, Jr. displays the Great Seal bug at the United Nations.
The Ambassador hung the seal in his office in Spaso House (Ambassador’s residence). During George F. Kennan’s ambassadorship in 1952, a secret technical surveillance countermeasures (TSCM) inspection discovered that the seal contained a microphone and a resonant cavity which could be stimulated from an outside radio signal.
The cavity resonator ‘bug’ microphone found inside.

On May 26, 1960, U.S. Ambassador to the United Nations Henry Cabot Lodge, Jr. unveiled the Great Seal Bug before the UN Security Council to counter Soviet denunciations of American U-2 espionage. The Soviets had presented a replica of the Great Seal of the United States as a gift to Ambassador Averell Harriman in 1946.

The gift hung in the U.S. Embassy for many years, until in 1952, during George F. Kennan’s ambassadorship, U.S. security personnel discovered the listening device embedded inside the Great Seal.

Lodge’s unveiling of this Great Seal before the Security Council in 1960 provided proof that the Soviets also spied on the Americans, and undercut a Soviet resolution before the Security Council denouncing the United States for its U-2 espionage missions. – U.S. Department of State... 

Read the fascinating full history here.

Thursday, May 24, 2018

Alexa - Busted for Eavesdropping

A Portland family contacted Amazon to investigate after they say a private conversation in their home was recorded by Amazon's Alexa -- the voice-controlled smart speaker -- and that the recorded audio was sent to the phone of a random person in Seattle, who was in the family’s contact list.


"My husband and I would joke and say I'd bet these devices are listening to what we're saying," said Danielle, who did not want us to use her last name.

Every room in her family home was wired with the Amazon devices to control her home's heat, lights and security system.

But Danielle said two weeks ago their love for Alexa changed with an alarming phone call. "The person on the other line said, 'unplug your Alexa devices right now,'" she said. "'You're being hacked.'"

That person was one of her husband's employees, calling from Seattle.

"We unplugged all of them and he proceeded to tell us that he had received audio files of recordings from inside our house," she said. "At first, my husband was, like, 'no you didn't!' And the (recipient of the message) said 'You sat there talking about hardwood floors.' And we said, 'oh gosh, you really did hear us.'" more

General Data Protection Regulation (GDPR), or D-Day for Data

Effective, Friday, May 25, 2018

The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.

It also addresses the export of personal data outside the EU and EEA. The GDPR aims primarily to give control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. more
  • This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.
  • This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.
  • The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. more
GDPR in a nutshell.
GDPR explanation from Mozilla.

How to encrypt your entire life in less than an hour

Quincy Larson has written an excellent article on how to protect your digital privacy. Worth reading. Worth doing. ~Kevin

“Only the paranoid survive.” — Andy Grove

And Grove isn’t the only powerful person urging caution. Even the director of the FBI — the same official who recently paid hackers a million dollars to unlock a shooter’s iPhone — is encouraging everyone to cover their webcams.

But you obey the law. What do you have to worry about? As the motto of the United Kingdom’s surveillance program reminds us, “If you’ve got nothing to hide, you’ve got nothing to fear.”

Well, law-abiding citizens do have reason to fear. They do have reasons to secure their devices, their files, and their communications with loved ones.
“If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged.” — Cardinal Richelieu in 1641
In this article, I will show you how you can protect yourself by leveraging state-of-the-art encryption. In a single sitting, you can make great strides toward securing your privacy. more

Wednesday, May 23, 2018

Dumpster Diving…A Treasure Trove

From the book, What You Don't Know... Your Guide to Achieving "Knowledge Advantage" in the Information Age!

"Valuable Open Source information is thrown away every day, waiting to be collected by the thoughtful researcher. Dubbed “dumpster diving,” or “trash picking” a wastebasket becomes a friend to researchers and a foe of anyone you are collecting on...

How useful dumpster diving is can be readily seen by the fact that a highly-placed US intelligence official was convicted and sentenced to life in prison for working with Moscow operatives. He had thoughtlessly thrown away key clues to his betrayal, not thinking they would end up on a prosecutor’s desk. Expecting anything to be buried forever in a trash heap can be a major mistake...

In the United States the Supreme Court has said that, as a general rule, things left in trash cans curbside are considered “abandoned” and are there for the taking."

Related: Confidential Paperwork Security

Infographic - The History of Privacy

Click to enlarge.


Tuesday, May 22, 2018

How Domestic Abusers Use Smartphones to Spy on Their Partners

There’s more creepy spyware out there than you think — and regulating it is a legal and technological challenge.

More and more people who commit violence against their intimate partners are using technology to make their victims’ lives worse...

News media, academic researchers, and victim advocates have long acknowledged the threat of spyware in domestic abuse situations. But our research (conducted with our students) brings to light the ease with which spyware can be deployed by abusers, and the broad scope of software usable as spyware...

Installing powerful spyware is just a few clicks away. Search on the web for “track my girlfriend” and you’ll find plentiful links to software, how-to guides, and forums all aimed at making it easy for abusers to spy on victims. (Protection advice is also available.) All the tools an abuser needs are present on Google and Apple’s app stores; installation is as simple as grabbing the victim’s device, typing the password (possibly stolen), and downloading an app. Many such apps require a fee, but in some cases, you can spy free of charge.

And our research shows that current anti-malware programs most often don’t identify such software as problematic. (ours does) more

Click the "our research" link above for the research paper. ~Kevin

Secretly Recording a Witness Gets Two Arrested

NH - Two Tolles Street residents were arrested Monday morning, charged with secretly recording a witness’ private conversation from a previous investigation, police said.

The charges stem from Aug. 3, 2017, when members of the Special Investigations Division learned a witness's private conversation from a previous investigation involving Bellino and Madison may have been recorded without the witness's consent.

Zachary Madison, 27, was charged with wiretapping, a Class B felony, Brittney Bellino, 25, was charged with conspiracy to commit wiretapping during their arrest about 9:40 a.m. Both charges are Class B felonies. more

Darwin Award to Another Spycam'er Who Shot Himself


MA - A Taunton man faces allegations that he placed a small recording device in a preschool bathroom with the intent of filming the women who worked there.

Darin McNeil, 48, was arrested at the Learning Experience on Main Street on May 18 by Foxborough Police and charged with possession of a device for wiretapping, attempting to conduct secret sexual surveillance, and unlawful wiretapping...

Police responded to a report of a shiny object found in a hat placed on a shelf across from a toilet in a staff bathroom at the preschool around midday on May 18. Once officers were given the item, it was determined that it was an audio and video recorder with a small USB connection that is designed to look like a pen, according to a police report.

Video from the pen allegedly showed a worker at the Learning Experience in the bathroom and a man placing the device where it was found. The man was identified as McNeil, who was an electrician doing some work at the daycare. more

Security Installer Turned Spycam'er... again

LA - Police are looking for Jules Chauvin, the owner of Telecom Security Solutions in West Monroe.

Chauvin allegedly installed cameras in the victim's business in West Monroe.

According to police, a victim contacted them on May 7th saying she was being watched without her consent by the man who installed her security system. Police say the victim fears that Chauvin may be watching other people as well.

Police ask that anyone who feels that they may be a victim of video voyeurism to contact the police department. more

This isn't the first time a security installer got caught installing spycams...

Largest Ever Women’s Rally Protests Spycam Pornography

Some 12,000 women gathered in Seoul on Saturday to protest against the “discriminatory treatment” of cases involving male and female victims of digital and online sexual violence, including spy-cam pornography. The event was the biggest women’s rights rally in Korea’s recent history...

According to 2016 data from the Korean National Police Agency, some 5,184 sexual harassment cases including those that involved spy-cam footage -- illegally uploaded video footage created using hidden cameras in public spaces such as public toilets -- were reported that year. More than 80 percent of the victims were women.

Furthermore, more than 7,300 requests were made to remove revenge porn that was uploaded by victims’ ex-romantic partners. more

Phone Companies Know Your Location 24/7 - and they're selling it.

via Krebs on Security 
Your mobile phone is giving away your approximate location all day long.

This isn't exactly a secret: It has to share this data with your mobile provider constantly to provide better call quality and to route any emergency 911 calls straight to your location.

But now, the major mobile providers in the United States -- AT&T, Sprint, T-Mobile and Verizon -- are selling this location information to third party companies -- in real time -- without your consent or a court order, and with apparently zero accountability for how this data will be used, stored, shared or protected. 

It may be tough to put a price on one's location privacy, but here's something of which you can be sure: The mobile carriers are selling data about where you are at any time, without your consent, to third-parties for probably far less than you might be willing to pay to secure it. more

Monday, May 21, 2018

"Secure" Cell Phone Spyware Springs a Leak

At least one server used by an app for parents to monitor their teenagers' phone activity has leaked tens of thousands of accounts of both parents and children.

The mobile app, TeenSafe, bills itself as a "secure" monitoring app for iOS and Android, which lets parents view their child's text messages and location, monitor who they're calling and when, access their web browsing history, and find out which apps they have installed.

Although teen monitoring apps are controversial and privacy-invasive, the company says it doesn't require parents to obtain the consent of their children. more

Tuesday, May 15, 2018

IBM Bans Removable Drives and Shows World's Smallest Computer

IBM has allegedly issued a worldwide ban against the the use of removable drives, including Flash, USB, and SD cards, to transfer data.

This new policy is being instituted to prevent confidential and sensitive information from being leaked due to misplaced or unsecured storage devices.

According to a report by TheRegister, IBM's global chief Information security officer Shamla Naidoo issued an advisory stating that the company “is expanding the practice of prohibiting data transfer to all removable portable storage devices (eg: USB, SD card, flash drive).” This advisory further stated that this policy is already in effect for some departments, but will be further enforced throughout the entire company. more

-------

Today, IBM will be showing off the world's smallest computer at its Think 2018 conference. This computer is the size of a grain of salt, contains a million transistors, and only costs .10 to manufacture.

This micro computer is being unveiled as part of IBM's crypto-anchors initiative, which are digital fingerprints that can be embedded in products such as medicine, cell phones, toys, watches, and even wine to detect counterfeit products. With product fraud costing the global economy $600 billion dollars a year, IBM is hoping crypto-anchors can help stem the tide of fraudulent products and counterfeit drugs...

FutureWatch: Within the next five years, cryptographic anchors — such as ink dots or tiny computers smaller than a grain of salt — will be embedded in everyday objects and devices. more

Friday, May 11, 2018

Cell Phone Problems Predicted in 1919

Click to enlarge.
The Pocket Telephone: When Will it Ring?
Published in The Daily Mirror Mar. 5, 1919

Social Meddling on Social Media

The massive trove of Facebook ads House Intelligence Committee Democrats released Tuesday provides a stunning look into the true sophistication of the Russian government’s digital operations during the presidential election. 

...a swath of empirical and visual evidence of Russia’s disinformation campaign, in the form of more than 3,000 incredibly specific and inflammatory ads purchased by an Internet troll farm sponsored by the Kremlin.

The ads clearly show how Russia weaponized social media, the senior Democrat on the panel investigating Moscow’s interference in the presidential election said. more

Beware the Venmo

Nicole found out the guy she was dating was already in a committed relationship. Abby learned that her ex had most likely hooked up with someone new, and Ben discovered that a long-ago casual fling had apparently developed a drug habit.


The sleuthing tool that cracked these relationship mysteries was not a private investigator, but the peer-to-peer payment app Venmo.

The mobile payment service, which processed more than $35 billion in payments last year, is a no-fuss solution for splitting the dinner bill after a night out with friends.

But Venmo users have found it’s also an extremely effective tool for keeping tabs on friends, partners and exes, researching crushes, and in some cases, uncovering infidelity. Some even say Venmo is a better method for watching people than more explicitly public social media platforms like Facebook or Instagram.

Some users seem to forget that their transactions are public by default, and their payment activity provides an unfiltered paper trail of what’s really happening in their lives. more

The Skim Reaper - Detects Credit Card Skimmers

After three years of study, Patrick Traynor and two Florida graduate students invented a device they call the “Skim Reaper,” a credit-card thin gadget that slides into card reader slots and can easily and quickly detect if an ATM or gas pump has been compromised. The New York Police Department is testing the Skim Reaper with some early success in its effort to rid the streets of the pervasive devices...


Most credit card skimmers work by installing an extra “read head” inside or outside a machine. This extra read head allows criminals to make a copy of the card’s information as a consumer swipes it. Skim Reaper was built to detect when more than one read head is present, Traynor said...

The device looks like a long credit card that can be slid into a card slot in a gas pump or ATM. It’s attached by a wire to a cellphone-sized box with a small readout screen that says “possible skimmer!” when multiple read heads are detected...

Right now, it costs about $50 to make each Skim Reaper, Traynor said, but his team is working daily to get that number down...
Nolen Scaife, one of the graduate students who designed the device with Traynor, said the team is working to improve the Skim Reaper’s design so that it is wallet-sized. Then, consumers would be able to carry the device and dip it into a card reader before they get gas or use the ATM to ensure they aren’t being skimmed. more

FontCode: Embed Secret Messages Within Text

Click to enlarge.
Computer scientists have invented FontCode, a way to embed hidden information in ordinary text by imperceptibly changing the shapes of fonts in text. 

The hidden information persists even when documents or images with perturbed texts are printed or converted to another file type. Method could prevent document tampering, protect copyrights, as well as embed QR codes and other metadata without altering the look or layout of a document.

"While there are obvious applications for espionage, we think FontCode has even more practical uses for companies wanting to prevent document tampering or protect copyrights, and for retailers and artists wanting to embed QR codes and other metadata without altering the look or layout of a document," says Changxi Zheng, associate professor of computer science and the paper's senior author.  more

Thursday, May 10, 2018

Hidden Smart Device Commands: Manchurian Candidate, or "Yes, master."

Many people have grown accustomed to talking to their smart devices, asking them to read a text, play a song or set an alarm. But someone else might be secretly talking to them, too.

Over the past two years, researchers in China and the United States have begun demonstrating that they can send hidden commands that are undetectable to the human ear to Apple’s Siri, Amazon’s Alexa and Google’s Assistant.

Inside university labs, the researchers have been able to secretly activate the artificial intelligence systems on smartphones and smart speakers, making them dial phone numbers or open websites.  

In the wrong hands, the technology could be used to unlock doors, wire money or buy stuff online — simply with music playing over the radio. more

Monday, May 7, 2018

Spycam: Aurora Cop Caught Spying on Ex-wife

An Aurora police officer will not be reinstated after he was fired for spying on his ex-wife through three cameras hidden in her Sugar Grove home, a judge has ruled. 

The decision by Kane County Judge David Akemann also cancels an arbitrator's ruling that would have reinstated Daniel Wagner to the Aurora Police Department this past January...

Wagner's now ex-wife found a hidden camera in her home in September 2016 and called police to investigate. Officers found a total of three cameras.
Records show she had filed for divorce in 2015, and Wagner installed the cameras during the divorce proceedings and reactivated them after it was final. more

Eavesdropping: Former Police Official Charged

A recently retired city police captain is now facing a felony charge of eavesdropping.

Brian Wentland, a former training captain who left the Lockport Police Department in February, was charged Friday, according to Niagara County District Attorney Caroline A. Wojtaszek.

The charges relate to a May 6, 2013 phone call involving his ex-wife and another person.

The timing of the charges was critical in the case.Wentland’s arrest was just two days before the five-year statute of limitations expired on the charge. more

Technical Surveillance Countermeasures (TSCM) and Cell Phone Security Presentation

As part of the New Jersey Association for Justice Boardwalk Seminar, Murray Associates president Kevin D. Murray will present a session entitled, “Technical Surveillance Countermeasures (TSCM) and Cell Phone Security.”

Eavesdropping, wiretapping, snooping, voyeurism, and espionage are covert activities. The victim rarely knows when it happens. Kevin D. Murray explores the world of corporate espionage, explaining how many companies are bleeding profits for lack of a counterespionage strategy. 

Regularly scheduled TSCM inspections narrow the window-of-vulnerability, spot new security loopholes, identify decaying security measures and practices, disrupt the spy’s intelligence collection phase, and keep counterespionage awareness levels elevated.

"Success-to-failure ratios are similar… most airplanes don’t crash; most people don’t drown in their baths; most houses don’t burn to the ground whenever the stove is used… and, most spying goes undiscovered." ~Kevin   more

Thursday, May 3, 2018

Audio Adversarial Examples: Targeted Attacks on Speech-to-Text

We construct targeted audio adversarial examples on automatic speech recognition. 

Given any audio waveform, we can produce another that is over 99.9% similar, but transcribes as any phrase we choose (recognizing up to 50 characters per second of audio).

We apply our white-box iterative optimization-based attack to Mozilla’s implementation DeepSpeech end-to-end, and show it has a 100% success rate.

The feasibility of this attack introduces a new domain to study adversarial examples. more audio examples

From one of our Blue Blaze irregulars... "Audio Adversarialism is the practice of fooling voice-to-text and voice recognition systems by effectively embedding ‘hidden’ commands in audio files which are inaudible to human ears but which are picked up by speakers and mean, in theory, that we might hear the telly saying “Should have gone to Specsavers!” where instead our Amazon Echo is in fact hearing “Alexa, lock all the doors, turn on the gas and start sparking all the bogs in 00:59, 00:58…”. This is...not scary at all, oh no. Hi Siri! Hi Alexa!"