Welcome to the home of the NSA Playset.
In the coming months and beyond, we will release a series of dead simple, easy to use tools to enable the next generation of security researchers. We, the security community have learned a lot in the past couple decades, yet the general public is still ill equipped to deal with real threats that face them every day, and ill informed as to what is possible.
Inspired by the NSA ANT catalog, we hope the NSA Playset will make cutting edge security tools more accessible, easier to understand, and harder to forget. Now you can play along with the NSA! (more)
If you are thinking of contributing a new NSA Playset project, please keep in mind the following requirements:
1. A Silly Name
If your project is similar to an existing NSA ANT project, you can come up with a clever play on that name. For example, if your project is similar to FOXACID, maybe you could call it COYOTEMETH. Of course, if your project doesn't quite line up with anything in the ANT Catalog, you can come up with your own name. If you are feeling less creative, try out the handy name generator found here: http://www.nsanamegenerator.com/ (more)
Sunday, November 23, 2014
This Week in Wiretap News
ID - The former information technology director of a hospital in Blackfoot was sentenced to three years of probation after he was convicted of wiretapping. A Bingham County judge imposed the sentence for 46-year-old Jack York on Friday. York was accused along with three others of recording telephone calls by a former hospital doctor and his staff between June 2009 and August 2010. (more) (more)
Taiwan - An aide to Ko Wen-je was arrested yesterday by Taipei prosecutors looking into alleged wiretapping of the independent Taipei mayoral hopeful's office... (more)
DC - American investigators intercepted a conversation this year in which a Pakistani official suggested that his government was receiving American secrets from a prominent former State Department diplomat, officials said, setting off an espionage investigation that has stunned diplomatic circles here, The New York Times in a report Friday said. That conversation led to months of secret surveillance on the former diplomat, Robin L. Raphel, and an F.B.I. raid last month at her home, where agents discovered classified information, the officials said. (more)
Turkey - More details have surfaced about the Gülenists' wiretapping of the then prime minister Recep Tayyip Erdoğan, after an indictment regarding the investigation was submitted to court. The Gülenists planned every step in detail, according to the indictment. The Ankara chief public prosecutor's office has prepared an indictment on 13 suspects, who are accused of wiretapping then Prime Minister Recep Tayyip Erdoğan, charging the suspects with "political spying" after an investigation into the alleged offenders was completed. (more)
CA - Counsel Timothy Perry discusses how wiretaps are vulnerable to attack, especially in white collar cases. He explains some details of the wiretap statute and discusses how defense attorneys can best address wiretap evidence in a white collar case. (video)
NC - A judge Friday unsealed a trove of court documents that could shed light on a secret cellphone tracking program used by police nationwide. The judge in Charlotte, N.C., acted after a petition from the Charlotte Observer to make the documents public. Included are 529 requests from local Charlotte-Mecklenburg police asking judges to approve the use of a technology known as StingRay, which allows cellphone surveillance. (more)
NYC - Add New York City’s Taxi and Limousine Commission to the list of powerful groups investigating Uber for allegedly spying on its users. The commission, which regulates Uber, is “looking into allegations” that the mobile car-hailing app violated users’ privacy by tracking them without their permission. (more)
Taiwan - An aide to Ko Wen-je was arrested yesterday by Taipei prosecutors looking into alleged wiretapping of the independent Taipei mayoral hopeful's office... (more)
DC - American investigators intercepted a conversation this year in which a Pakistani official suggested that his government was receiving American secrets from a prominent former State Department diplomat, officials said, setting off an espionage investigation that has stunned diplomatic circles here, The New York Times in a report Friday said. That conversation led to months of secret surveillance on the former diplomat, Robin L. Raphel, and an F.B.I. raid last month at her home, where agents discovered classified information, the officials said. (more)
Turkey - More details have surfaced about the Gülenists' wiretapping of the then prime minister Recep Tayyip Erdoğan, after an indictment regarding the investigation was submitted to court. The Gülenists planned every step in detail, according to the indictment. The Ankara chief public prosecutor's office has prepared an indictment on 13 suspects, who are accused of wiretapping then Prime Minister Recep Tayyip Erdoğan, charging the suspects with "political spying" after an investigation into the alleged offenders was completed. (more)
CA - Counsel Timothy Perry discusses how wiretaps are vulnerable to attack, especially in white collar cases. He explains some details of the wiretap statute and discusses how defense attorneys can best address wiretap evidence in a white collar case. (video)
NC - A judge Friday unsealed a trove of court documents that could shed light on a secret cellphone tracking program used by police nationwide. The judge in Charlotte, N.C., acted after a petition from the Charlotte Observer to make the documents public. Included are 529 requests from local Charlotte-Mecklenburg police asking judges to approve the use of a technology known as StingRay, which allows cellphone surveillance. (more)
NYC - Add New York City’s Taxi and Limousine Commission to the list of powerful groups investigating Uber for allegedly spying on its users. The commission, which regulates Uber, is “looking into allegations” that the mobile car-hailing app violated users’ privacy by tracking them without their permission. (more)
Adequately Protected Trade Secrets Can Keep You Out of Court... and a winner in court.
by Mark L. Krotoski, Esq.
Trade secrets can be among the most valuable assets a company has. According to one study, "Two thirds of enterprises’ information portfolio value comes from the secrets they create."
One trade secret can lead to many products. As a unique form of intellectual property, trade secrets can be vital not only to a company and its employees, but also to other jobs, investments, an industry, the economy and, depending on the trade secrets, even national security.
Two Key Questions for Trade Secret Owners
Given the importance of trade secrets, trade secret owners should ask two key questions:
(1) How many trade secrets do you have?
(2) Are your trade secrets adequately protected?
Many companies have trade secrets which can generate substantial value for the company. Regrettably, experience has shown that large and small companies have not taken the steps necessary to protect them. When the unexpected misappropriation occurs, it is clearly too late...
A culture of protection can establish the tone within the company to safeguard the trade secrets. A layered approach to security has proven effective in past cases to mitigate any misappropriation and to establish the reasonableness of the security measures. An objective assessment of the measures safeguarding the trade secrets can assist in determining the reasonableness u der trade secret law. Most importantly, companies should develop a trade secret protection plan in advance of any misappropriation.
So, as a trade secret owner, how do you answer the two questions? How confident are you that your trade secrets are reasonably protected and will survive court scrutiny if that ever becomes necessary? (more)
If you need help answering these questions, call me. An information security evaluation by an independent outside specialist can help with answers and will count toward fulfilling the adequacy requirement.
Trade secrets can be among the most valuable assets a company has. According to one study, "Two thirds of enterprises’ information portfolio value comes from the secrets they create."
One trade secret can lead to many products. As a unique form of intellectual property, trade secrets can be vital not only to a company and its employees, but also to other jobs, investments, an industry, the economy and, depending on the trade secrets, even national security.
Two Key Questions for Trade Secret Owners
Given the importance of trade secrets, trade secret owners should ask two key questions:
(1) How many trade secrets do you have?
(2) Are your trade secrets adequately protected?
Many companies have trade secrets which can generate substantial value for the company. Regrettably, experience has shown that large and small companies have not taken the steps necessary to protect them. When the unexpected misappropriation occurs, it is clearly too late...
A culture of protection can establish the tone within the company to safeguard the trade secrets. A layered approach to security has proven effective in past cases to mitigate any misappropriation and to establish the reasonableness of the security measures. An objective assessment of the measures safeguarding the trade secrets can assist in determining the reasonableness u der trade secret law. Most importantly, companies should develop a trade secret protection plan in advance of any misappropriation.
So, as a trade secret owner, how do you answer the two questions? How confident are you that your trade secrets are reasonably protected and will survive court scrutiny if that ever becomes necessary? (more)
If you need help answering these questions, call me. An information security evaluation by an independent outside specialist can help with answers and will count toward fulfilling the adequacy requirement.
Thursday, November 20, 2014
FREE - Enemy-of-the-State Spyware Detection Tool
via eff.org...
"Detekt is an easy-to-use, open source tool that allows users to check their Windows PCs for signs of infection by surveillance malware that we know is being used by government to spy on activists and journalists.
Some of the software used by states against innocent citizens is widely available on the Internet, while more sophisticated alternatives are made and sold by private companies and sold to governments everywhere from the United States and Europe to Ethiopia and Vietnam.
Detekt makes it easy for at-risk users to check their PCs for possible infection by this spyware, which often goes undetected by existing commercial anti-virus products." (more)
"Detekt is an easy-to-use, open source tool that allows users to check their Windows PCs for signs of infection by surveillance malware that we know is being used by government to spy on activists and journalists.
Some of the software used by states against innocent citizens is widely available on the Internet, while more sophisticated alternatives are made and sold by private companies and sold to governments everywhere from the United States and Europe to Ethiopia and Vietnam.
Detekt makes it easy for at-risk users to check their PCs for possible infection by this spyware, which often goes undetected by existing commercial anti-virus products." (more)
Labels:
App,
computer,
counterespionage,
FREE,
government,
privacy,
software
Covert Video Leaves Business Running Around Like a Chicken with its...
TN - Koch Foods on Wednesday denied its Chattanooga processing plant is inhumanely treating chickens by scalding the birds alive and shackling them upside-down before slicing open their throats, wings and chests while still conscious.
The allegations by animal protection group Mercy for Animals...
The Los Angeles-based group released covert video that it said was taken inside the Koch Chattanooga plant and another operation in Mississippi, complaining that workers are also cruelly throwing chickens and hiding cockroaches from federal inspectors.
The video, narrated by The Simpsons co-creator Sam Simon, demanded that Illinois-based Koch adopt new animal welfare standards to prevent future abuse. (more)
P.S. Last year, Tennessee legislators enacted what critics dubbed an “ag-gag” bill they charged was intended to prevent investigations similar to the Mercy for Animals undercover operations as well as one that targeted Tennessee Walking Horse industry abuse.
Republican Gov. Bill Haslam vetoed the bill after getting deluged with complaints, including a plea from country music star Carrie Underwood.
The allegations by animal protection group Mercy for Animals...
The Los Angeles-based group released covert video that it said was taken inside the Koch Chattanooga plant and another operation in Mississippi, complaining that workers are also cruelly throwing chickens and hiding cockroaches from federal inspectors.
The video, narrated by The Simpsons co-creator Sam Simon, demanded that Illinois-based Koch adopt new animal welfare standards to prevent future abuse. (more)
P.S. Last year, Tennessee legislators enacted what critics dubbed an “ag-gag” bill they charged was intended to prevent investigations similar to the Mercy for Animals undercover operations as well as one that targeted Tennessee Walking Horse industry abuse.
Republican Gov. Bill Haslam vetoed the bill after getting deluged with complaints, including a plea from country music star Carrie Underwood.
Memory Stick Voice Recorder - Patiently Listens 24/7, for 25 Days
This Voice-Activated USB drive looks and functions like an ordinary flash drive. Secretly, this storage device conceals hidden a microphone. Hang on a lanyard or slip into a pocket for discreet recording. Use this unit at the office, school, to covertly record voice as a secret shopper or investigator, or to simply record notes and interviews at school or work.
Voice-activation mode. The voice-activation feature allows you to avoid long hours of silent recording and save battery life. This unit can be on standby for up to 25 days waiting to pickup any voices you may hear.
Portable and easy to use. The flash drive needs no cables or batteries, making it perfect for the covert operative on the go. Recording is as simple as a touch of the button. Choose from normal recording or voice activation. ≈$100.00 (more) (user manual)
Why do I mention this?
So you will know what you're up against.
Voice-activation mode. The voice-activation feature allows you to avoid long hours of silent recording and save battery life. This unit can be on standby for up to 25 days waiting to pickup any voices you may hear.
Portable and easy to use. The flash drive needs no cables or batteries, making it perfect for the covert operative on the go. Recording is as simple as a touch of the button. Choose from normal recording or voice activation. ≈$100.00 (more) (user manual)
Why do I mention this?
So you will know what you're up against.
Speed, Instant Ticket... or, You Can Drive, But You Can't Hide
FutureWatch: Russia - 1200 complexes of photo and video registration will be installed in 381 sections of federal highways and regional roads located in the Moscow region. In particular, new equipment will be installed in almost every district and all major cities of the Moscow region, as well as in the smaller and greater Moscow Ring Road areas...
It is planned that the installation of photo and video registration systems will be conducted at the expense of an investor company, which, in turn, will receive a share of all fines issued for violation of traffic rules detected by cameras...
According to the authors of the idea, cameras will be able to register the majority of traffic violations, including speeding and driving on the oncoming lane. (more)
• Traffic cameras on steroids.
• Becomes operational just before self-driving vehicles, thus making this less necessary.
• Does the government has some other uses in mind? (Duh.)
• Will this surveillance network be adopted by other countries, too? (Duh.)
It is planned that the installation of photo and video registration systems will be conducted at the expense of an investor company, which, in turn, will receive a share of all fines issued for violation of traffic rules detected by cameras...
According to the authors of the idea, cameras will be able to register the majority of traffic violations, including speeding and driving on the oncoming lane. (more)
• Traffic cameras on steroids.
• Becomes operational just before self-driving vehicles, thus making this less necessary.
• Does the government has some other uses in mind? (Duh.)
• Will this surveillance network be adopted by other countries, too? (Duh.)
Wednesday, November 19, 2014
Everything You Wanted to Know About Cell Phone Tracking via Call Detail Records
What is Cellular Data Analysis?
How is Cellular Data Analysis Used?
What about Triangulation?
Is There an Accurate Way to Track a Cell Phone Location?
Is cell tower tracking evidence junk science?
Is there a good use for cellular location evidence?
(answers here)
How is Cellular Data Analysis Used?
What about Triangulation?
Is There an Accurate Way to Track a Cell Phone Location?
Is cell tower tracking evidence junk science?
Is there a good use for cellular location evidence?
(answers here)
Fake Cell Tower Survey on Indiegogo
If there's somethin' strange in your neighborhood
Who ya gonna call (cellbusters)
If it's somethin' weird an it don't look good
Who ya gonna call (cellbusters)
(more) (sing-a-long)
Who ya gonna call (cellbusters)
If it's somethin' weird an it don't look good
Who ya gonna call (cellbusters)
(more) (sing-a-long)
Tuesday, November 18, 2014
Your Email is Hacked - Now What?
The State Department has suspended its unclassified email system in response to a suspected hacking attack.
The unprecedented shutdown on Friday was reportedly applied to give technicians an opportunity to repair possible damage, as well as to apply security improvements. (more)
But, what if it's your email? You don't have "technicians" to turn to. Techlicious to the rescue...
Step #1: Change your password.
Step #2: Reclaim your account.
Step #3: Enable two-factor authentication.
Step #4: Check your email settings.
Step #5: Scan your computer for malware.
Step #6: Find out what else has been compromised.
Step #7: Humbly beg for forgiveness from your friends.
Step #8: Prevent it from happening again.
Full details for each step are outlined here.
The unprecedented shutdown on Friday was reportedly applied to give technicians an opportunity to repair possible damage, as well as to apply security improvements. (more)
But, what if it's your email? You don't have "technicians" to turn to. Techlicious to the rescue...
Step #1: Change your password.
Step #2: Reclaim your account.
Step #3: Enable two-factor authentication.
Step #4: Check your email settings.
Step #5: Scan your computer for malware.
Step #6: Find out what else has been compromised.
Step #7: Humbly beg for forgiveness from your friends.
Step #8: Prevent it from happening again.
Full details for each step are outlined here.
Dark Hotel - Cleverly Engineered to Conduct Corporate Espionage
A new advanced persistent threat (APT),
known as DarkHotel, is now targeting C-level executives of major
businesses.
Instead of trying to compromise governments to steal state
secrets, Dark Hotel is cleverly engineered to conduct corporate
espionage, likely for a foreign state-sponsored group, utilizing poor
wireless hotel security - a rather clever technique for when business
leaders are staying in hotels...
Dragnet 2014 - "The IMSI Catcher Caper"
The Wall Street Journal has revealed details of a secret spy program.
The newspaper says the justice department is collecting data from thousands of cell phones at major airports across the country.
The U.S. Marshals Service operates airplanes with a device (IMSI Catcher) on board that tricks your phone into thinking it is a cell tower.
Phones are programmed to connect automatically to the strongest cell tower signal, which is usually this new device at the airport. When it does, it transmits your unique registration information.
The newspaper says the technology is supposed to locate cell phones linked to criminal suspects, but in the process the government is collecting data on thousands of other people as well. (more)
The newspaper says the justice department is collecting data from thousands of cell phones at major airports across the country.
The U.S. Marshals Service operates airplanes with a device (IMSI Catcher) on board that tricks your phone into thinking it is a cell tower.
Phones are programmed to connect automatically to the strongest cell tower signal, which is usually this new device at the airport. When it does, it transmits your unique registration information.
The newspaper says the technology is supposed to locate cell phones linked to criminal suspects, but in the process the government is collecting data on thousands of other people as well. (more)
New App to Detect Fake Cell Phone Towers
This is an Android-based project to detect and avoid fake base stations (IMSI-Catchers) in GSM/UMTS Networks.
Both law enforcement agencies and criminals use IMSI-Catchers, which are false mobile towers acting between the target mobile phone(s) and the service providers real towers. As such it is considered a Man In the Middle (MITM) attack. (more)
Both law enforcement agencies and criminals use IMSI-Catchers, which are false mobile towers acting between the target mobile phone(s) and the service providers real towers. As such it is considered a Man In the Middle (MITM) attack. (more)
From the No Free Lunch Files
An accused perv landlord charged with secretly filming a woman he’d set up in a rent-free Upper West Side pad pleaded not guilty to several felony counts Monday.
Eli Kadoch, 48, was indicted on 10 counts of unlawful surveillance after allegedly setting up spy cameras in the W. 82nd St. apartment of Aksana Kuzmitskaya, where he allegedly watched her in the nude repeatedly for six months beginning in January.
Kuzmitskaya is suing Kadoch and another landlord, Michel Kadoe — who has not been charged criminally — for allegedly taping her most intimate moments after giving her a rent-free apartment while she worked for them as a maid.
Kuzmitskaya says the secret footage included her showering, having sex and using the bathroom. Cameras sent live feeds to Kadoe and Kadoch’s laptops, the lawsuit says. (more)
Eli Kadoch, 48, was indicted on 10 counts of unlawful surveillance after allegedly setting up spy cameras in the W. 82nd St. apartment of Aksana Kuzmitskaya, where he allegedly watched her in the nude repeatedly for six months beginning in January.
Kuzmitskaya is suing Kadoch and another landlord, Michel Kadoe — who has not been charged criminally — for allegedly taping her most intimate moments after giving her a rent-free apartment while she worked for them as a maid.
Kuzmitskaya says the secret footage included her showering, having sex and using the bathroom. Cameras sent live feeds to Kadoe and Kadoch’s laptops, the lawsuit says. (more)
Monday, November 17, 2014
Kevin's Security Scrapbook - iPhone / iPad App - FREE
Get the latest
"Spy News from New York"
on your iPhone or iPad.
The layout is beautiful, and the navigation is intuitive and easy. This is the most convenient way to read Kevin's Security Scrapbook.
Download the app onto your device now.
Subscribe to:
Posts (Atom)