Wednesday, January 28, 2015

Panama’s Ex-president’s Hunger for Gossip Fueled Tapping

When the United States rejected former Panamanian President Ricardo Martinelli’s request for spying equipment to eavesdrop, U.S. diplomats feared, on his political enemies, the former supermarket baron turned to another source: Israel.

Now scores of Panama’s political and social elite are learning that the eavesdropping program that Martinelli’s security team set in place sprawled into the most private aspects of their lives – including their bedrooms. Rather than national security, what appears to have driven the wiretapping was a surfeit of the seven deadly sins, particularly greed, pride, lust and envy.

Nearly every day, targets of the wiretapping march to the prosecutors’ office to see what their dossiers contain, often emerging in distress. Martinelli, who left office in July, is facing a rising tide of outrage not only over the wiretapping, but also over reports of vast corruption. His personal secretary has left the country. The eavesdropping equipment has vanished.
(more)

Town Supervisor Accused of Eavesdropping on Employees

NY - State Police arrested the Windham Town Supervisor after they say she used video and audio recording devices to eavesdrop on employees.

Stacy Post, 51, put the recording devices in the Windham Town Office Building after being elected to Town Supervisor, according to police.

They say Post eavesdropped on employees and other users of the town offices.

Post has been charged with felony eavesdropping and possessing eavesdropping devices.
(more)

You Only Live Once, or Die Another Day

The former Russian spy Alexander Litvinenko may have survived a previous poisoning attempt before a lethal dose of polonium was slipped into his tea at a London hotel, a long-awaited judicial inquiry into his death was told Tuesday.

The former KGB officer, an outspoken critic of Russian President Vladimir Putin, was living in Britain and doing consultancy work for the British intelligence service MI-6 when he met two Russians for a drink at the Millennium Hotel in November 2006. Weeks later, he suffered an agonizing death, apparently from the effects of radiation poisoning.

The strange case soured relations between Britain and Russia for years. On his deathbed, Litvinenko claimed that he had been poisoned on Putin’s orders.
(more)

Need A Secure Portable 1 or 2TB Hard Drive? (Yeah, you do.)

iStorage diskAshur Pro 1TB review: one of the most secure and encrypted portable hard drives you can buy...

If you use a portable drive for business, there's a very strong case for keeping that data secure with a hardware-encrypted drive. And when customer data is at stake, there's a legal obligation to button it down to keep it confidential in the event of the drive being lost or otherwise compromised.

Even home users may prefer to keep their files and data to themselves. Which is why encrypted portable drives like the iStorage diskAshur Pro can be such a great idea, with their built-in keypads that need a numerical PIN to be entered before they give up their secrets.

The diskAshur Pro follows a line of similar drives sold in this country (UK) by iStorage Limited, which are rebranded and renamed drives designed by and made for Apricorn Inc in the USA. This latest version is called the diskAshur Pro, otherwise known as the Apricorn Aegis Padlock Fortress, and has been given a FIPS 140-2 security rating.
(more)

Tuesday, January 27, 2015

Avoid Video Surveillance Liability

via Eric Pritchard, Esq...
Summary: Here are five keys to limiting your liability when using and deploying video:

1. Understand and obey wiretap laws. Federal wiretap laws prohibit the interception of oral communications with limited exceptions.

2. Obey state laws prohibiting video cameras. Several states prohibit or regulate video surveillance.

3. Obey state laws respecting privacy rights. Every state has law concerning an individual’s privacy rights.

4. (Installers) Use an effective, enforceable contract to allocate the risk of loss. An effective contract for the provision of video-related services and equipment should limit your company’s liability just like it does for other services.

5. (Installers) Installing video without a recurring contract is a missed opportunity. Develop a policy of not selling or installing video cameras without a contract for some form of recurring revenue. 

• Side note: If you are the user, keep the system maintained so you are not accused of providing a false sense of security.

NYC - Spycam Found in Bathroom Used by Top Corporations

The New York City Police Department reported today that a pinhole camera was found in a unisex bathroom at Johnson & Johnson (JNJ)’s corporate offices in NYC last week. A designer with the company discovered the camera, located above the light switch.

Johnson & Johnson ’s building maintenance supervisor reported the camera to the New York Police Department after it was discovered on Jan. 16, 2015. After examination, the camera was found to contain an SD card used for video storage. Johnson & Johnson’s Carol Goodrich said the company had immediately contacted the NYPD after the camera’s discovery...
Spycams are disguised as many things. This one is a USB stick.

“The device was hidden above a light switch in the bathroom next to offices that include Ralph Lauren and Haynes Roberts...” reported the New York Post. “The bathroom with the hidden device is open and accessible to all tenants and guests on the floor. It wasn’t clear whether the potty perv who put it there captured customers or models who do photo shoots nearby in RR Donnelley’s Studio W26. Investigators had yet to review the storage drive recovered with the camera.”...

Today’s story about the pinhole camera is part of what appears to be a trend. * NBC ran a story on March 27, 2014 about numerous reports of cameras being found in public bathrooms...

The NYPD indicates they are investigating the J&J camera as a sex crime and unlawful surveillance, with the added possibility of obscene material involving people under the age of 17.
(more)

*More like pandemic based on news reports and sweep requests received here.
• That USB stick spycam... only $8.76 here.

Economic Espionage - NYC Russian Banker Arrested by FBI

Federal prosecutors arrested a Russian banker in New York on Monday and charged him as a spy, accusing him and two others of secretly gathering information about the New York Stock Exchange, U.S. energy resources and sanctions against Moscow.

Prosecutors described clandestine meetings and coded communications between the banker and his handlers, one of whom worked as a trade representative of the Russian Federation in New York, the other as an attaché to the Permanent Mission of the Russian Federation to the United Nations.

The spycraft alleged in the complaint reads like a throwback to the Cold War. Yet the alleged operatives’ target was more modern: economic intelligence... 
The most interesting part...
Mr. Buryakov suggested they ask about the NYSE’s use of exchange-traded funds, potential limits on the use of automated high-frequency trading systems... NYSE spokesman declined to comment.
(more)

• The movie Blackhat illustrates market manipulation, and why it would interest them.
• Classic spycraft is alive and well. It ain't all IT-based.
• Nice job, FBI!

Can You Be Insecure Playing for the NFL? Sure, if you're an app.

The National Football League's official app for both iOS and Android puts users at risk by leaking their usernames, passwords, and e-mail addresses in plaintext to anyone who may be monitoring the traffic, according to a report published just five days before Superbowl XLIX, traditionally one of the world's most popular sporting events. 

(You can stop reading here. Trust me, it just gets worse.)

As Ars has chronicled in the past, large numbers of people use the same password and e-mail address to log into multiple accounts. That means that people who have used the NFL app on public Wi-Fi hotspots or other insecure networks are at risk of account hijackings. The threat doesn't stop there: the exposed credentials allow snoops to log in to users' accounts on http://www.nfl.com, where still more personal data can be accessed, researchers from mobile data gateway Wandera warned. Profile pages, for instance, prompt users to enter their first and last names, full postal address, phone number, occupation, TV provider, date of birth, favorite team, greatest NFL Memory, sex, and links to Facebook, Twitter, and other social networks. Combined with "about me" data, the personal information could prove invaluable to spear phishers, who send e-mails purporting to come from friends or employers in hopes of tricking targets into clicking on malicious links or turning over financial data. Adding to the risk, profile pages are transmitted in unencrypted HTTP, making the data susceptible to still more monitoring over unsecured networks, the researchers reported.

"Wandera's scanning technologies have discovered that after the user securely signs into the app with their NFL.com account, the app leaks their username and password in a secondary, insecure (unencrypted) API call," a report published Tuesday warned. "The app also leaks the user’s username and e-mail address in an unencrypted cookie immediately following login and on subsequent calls by the app to nfl.com domains." The app allows users to make a variety of in-app purchases.
(more)

Corporate Espionage Cartoon


Monday, January 26, 2015

U.S. Spies on Millions of Cars

DEA Uses License-Plate Readers to Build Database for Federal, Local Authorities

The Justice Department has been building a national database to track in real time the movement of vehicles around the U.S., a secret domestic intelligence-gathering program that scans and stores hundreds of millions of records about motorists, according to current and former officials and government documents.

The primary goal of the license-plate tracking program, run by the Drug Enforcement Administration, is to seize cars, cash and other assets to combat drug trafficking, according to one government document. But the database’s use has expanded to hunt for vehicles associated with numerous other potential crimes, from kidnappings to killings to rape suspects, say people familiar with the matter.
(more)

EP Team Alert - Dating Apps Let Snoopers Track Users

Snoopers have spied on massive numbers of amorous singletons by exploiting security flaws in dating apps.

Luckily, the spies were not creepy stalkers or violent perverts, but a group of cybersecurity experts on a mission to make life safer for daters.

They were able to track volunteers' every move in a discovery which should send chills down the spine of anyone using apps to find love...

This weekend, Colby Moore (security researcher at Synack) will present a talk at the tech conference ShmooCon, where he will discuss how he managed to track "tens of thousands" of amorous app users at the same time.

He suggested dating app security holes could even be used to spy on celebs.

"We [will] show just how easy it might be to reveal the identity of and track your favorite athlete, politician, or movie star," Moore wrote.
(more)

Snow Day Project - Make a Sneaky Snake Spycam for <$20.

It's snowing here in the Northeast United States. Tomorrow will be a down day. Need a spy project to combat cabin fever? This guy shows you how...

Tom Cruise Bugged Nicole Kidman's Phone, says Scientology movie

Church of Scientology leaders ordered the wiretapping of Nicole Kidman's telephones

...during her marriage to Tom Cruise as part of a campaign to break up the couple, according to an explosive new documentary.

Marty Rathbun, formerly the religion's second highest-ranking official, told Oscar-winning film-maker Alex Gibney, that his role was to "facilitate the break-up" for church leader David Miscavige.

The church on Monday said that the "accusations made in the film" were "entirely false".
(more) (more)

SpyCam News - Internal Affairs Agent Overly Into His Job

CA - A camera found in the women's bathroom at the Border Patrol compound in San Ysidro has one agent in a lot of trouble. San Diego police told Team 10 that a ranking agent hid the camera and someone found it.

Officers confronted the agent at the Border Patrol administrative offices on West Ash Street in downtown San Diego.

Two separate Team 10 sources confirmed the agent works with internal affairs.
(more with video)

Countering Light Bulb Eavesdropping

Q. "How to prevent light bulbs from being used as pickups for speech?" (meaning, being used as part of an eavesdropping system)

A. The easiest way, of course, is to keep the bulb turned off, however, I know that's not what you mean.

The second best way is to make sure there is no way for the bad guy to see the light bulb. Most attacks require accessing the bulb's variations in light so they can be remotely demodulated. (See Leon Theremin's invention.)

Some bulb attacks are made possible because additional electronics are placed inside the bulb (cameras, transmitters, microphones, etc.). The easiest countermeasure to this is to replace the bulbs with bulbs you purchased from a local Home Depot / Lowe's type store. Mark the bulbs when you install them, then check periodically to make sure they haven't been switched out.

Also, be sure to check the fixtures and wiring paths for attached microphones and modulation circuitry. Cut the power while doing these things.

These are not high-tech countermeasures, but they are effective.

Hope that helps,
Kevin