Wednesday, October 15, 2014

Chinese Renovation Plan Creates Waldorf-Hysteria

Concerned about potential security risks, the U.S. government is taking a close look at last week's sale of New York's iconic Waldorf Astoria hotel to a Chinese insurance company.

U.S. officials said Monday they are reviewing the Oct. 6 purchase of the Waldorf by the Beijing-based Anbang Insurance Group, which bought the hotel from Hilton Worldwide for $1.95 billion. Terms of the sale allow Hilton to run the hotel for the next 100 years and call for "a major renovation" that officials say has raised eyebrows in Washington, where fears of Chinese eavesdropping and cyber espionage run high. (more)

Rogue Bank Security Department Buys Wiretaps

The accusations read like a pulp thriller: Citigroup employees in Mexico are suspected of pocketing millions of dollars in kickbacks from vendors. And bodyguards for bank executives bought audio recordings of personal phone calls and created shell companies to disguise their fraud...

The security unit’s primary purpose was to protect the Banamex leadership, but at some point, the unit started operating beyond its approved duties, according to the person briefed on the matter who was not authorized to speak publicly because of the criminal investigation. The security unit was also providing protection and security consulting services for people outside the bank, sometimes as a courtesy and at other times for money, the internal investigation found. The conduct spanned more than a decade, the investigation found, extending into last year... 

Citigroup’s outside lawyers have turned over information to law enforcement officials in Mexico and the United States, but there are many things the bank doesn’t know about the rogue security unit. For example, the security team had purchased audio surveillance files from “third parties” that included cellphone and landline conversations of dozens of people — some of a highly personal nature, the person said. The Banamex unit then transcribed many of these files. It was unclear why the security team was amassing records of the personal conversations. The bank’s investigators are still working to determine why the security unit gathered the conversations, involving dozens of people, many of whom had nothing to do with the bank. (more)

Tuesday, October 14, 2014

Aaron's Settles Spy Software Installation Charges

Aaron's Inc., the nation's second-largest chain of rent-to-own appliance and furniture stores,

agreed to pay $28.4 million to settle allegations that it violated California consumer privacy and protection laws by allowing software that secretly monitored consumers to be installed on rental computers, according to regulators.

The Atlanta-based retailer allegedly overcharged customers, left out important contract disclosures and installed software that could track the keystrokes of people who rented computers and even activate webcams or microphones to record users. (more)

Monday, October 13, 2014

Word on the Street: Hertz has cameras in their cars!

...from an anonymous blog entry...
I am a regular renter from Hertz (President's Circle)... I got into a rental car at O'Hare airport. 

I immediately noticed the new NeverLost and I was completely shocked to see a camera built into the device looking at me. The system can't be turned off from what could tell...

I know rental car companies have been tracking the speed and movements of their vehicles for years but putting a camera inside the cabin of the vehicle is taking their need for information a little TOO FAR. I find this to be completely UNACCEPTABLE. In fact, if I get another car from Hertz with a camera in it, I will move our business from Hertz completely. 

I influence car rentals of many others and I don't think anyone would want to be on camera while they are driving around or sitting at a red light. 

Given what Hertz has invested in this system, I wonder how much consumer pressure will make them to pull the plug on this. Business is built one customer at a time and they will no longer have me as a customer. What are your thoughts? (more)

Further investigations revealed...
...the Hertz NeverLost 6 platform will include an ARM Cortex-A9 architecture with quad cores running at 1GHz, a high-res TFT display, Bluetooth and Wi-Fi connectivity and a GPS module that engineers built around SiRFstarIV architecture. Also included are a keypad, camera module, accelerometers and a Gyros sensor board...


Huff Butt Dial Blues

If a person accidentally calls someone from their cell phone, do they have a right to privacy protecting any conversation heard on the other end? The courts don’t think so.

Jim Huff, then chairman of the Kenton County (Kentucky) Airport Board, which manages Cincinnati’s international airport, was at a conference in Italy on October 24, 2013, when he unintentionally dialed airport offices while his phone was in his pocket and reached Carol Spaw. Spaw listened to Huff’s conversation for 90 minutes, even writing down some of his remarks and passing them along to a third party.

Huff claimed Spaw’s actions violated his right to privacy, since he never intended to “pocket dial” her in the first place.

But a federal judge didn’t agree, ruling individuals don’t have a reasonable expectation of privacy due to the common problem of pocket dialing and “butt calls.” (more) (sing-a-long)

In 60 Seconds: Snoopy Books, Malware in Firmware, and an SMS Virus on Android

Nixon Offered To Illegally Wiretap New York Mayor John Lindsay

The disclosure that Nixon offered to wiretap Lindsay comes via the detailed diaries of Dr. W. Kenneth Riland, who was Rockefeller’s osteopath and confidante.

He also treated Nixon and gained his confidence, too. (more)

Chinese Espionage Now Rampant in Taiwan

As relations improve between Beijing and Taipei, military morale still continues to fall as fewer Taiwan military officers see a future in an ever-shrinking armed forces. Many are beginning to cash in on their intimate knowledge of military secrets, including classified information on US military equipment. 

Over the past several years, Taiwan military officers have sold China information on the E-2K Hawkeye airborne early warning aircraft, Patriot Advanced Capability-3 and PAC-2 anti-ballistic missile systems, Hawk air defense missile system, and the Raytheon Palm IR-500 radiometric infrared camera.

China uses retired Taiwan military officers to help recruit spies in the armed forces. Retired officers receive all-expense paid trips to China by the United Front Work Department, said a Taiwan security specialist. While there, they are lionized for returning to the “homeland” and given tours of their ancestral homes. Before they return, money is offered to help the “motherland” in the future, and “unfortunately many take it,” he said. (more)

Saturday, October 11, 2014

The Case of the Eavesdropping Corvettes

General Motors may have to take the sting out of its new Stingray. 
The 2015 Corvette offers a personal video recording option that lets owners surreptitiously record video and audio when the car is in the hands of other drivers — like parking attendants. But now the automaker is concerned that the so-called valet mode may run afoul of eavesdropping laws in some states.

The laws in question involve audio recording only, and require that both parties give consent to be recorded. The Corvette’s recorder not only stores video shot through the windshield, but also data on speed and acceleration as well as audio recordings from inside the car. (more)

Inside the Secret World of Corporate Espionage

Numbers on corporate espionage are hard to come by. The Germans recently estimated that they lose around $69 billion to foreign business spies every year, but—at best—that’s basically just a piece of well-informed speculation.

The main problem with getting an exact fix on these figures is that they’re impossible to prove, because the nature of espionage generally relies on keeping stuff secret. It’s difficult to track the exchange of information, for instance, when it involves murmuring something at the sauna, or handing over a USB stick in a multi-level parking garage. And like a rigged sports game or steroid usage, it’s not something we’re in the mood to wake up to until it’s 100 percent, incontrovertibly there—an arsenal of smoking guns right under our noses.


“[Worrying about corporate espionage] very quickly becomes a matter of paranoia,” says Crispin Sturrock, who’s been running WhiteRock—a firm of anti-espionage specialists—for more than 20 years. “There’s a very British tendency to want to shake it off. To say, ‘Oh, I must be being paranoid.’ And, of course, just to be paranoid doesn’t necessarily make you wrong.” (more)

Spy Bits

ISM Bugging Out
The revelation this week that the International Spy Museum would be once again hitting the pavement in search of a new home got us thinking: Where else in the District might work for the popular museum? (more)

ISIS Changing Name
During the premiere episode of the sixth season of Archer, FX’s outrageously funny animated spy series, spy matriarch Malory Archer is seen speaking on the phone with her juvenile, coddled son. In the background, you can see two movers rolling out a large, circular blue ISIS sign... for the past five seasons, ISIS (International Secret Intelligence Service) has been the name for the underground, non-government approved, New York City-based spy organization at the heart of the show. In light of recent events, however, creator Adam Reed along with executive producers Matt Thompson and Casey Willis—made a decision to quietly eliminate the acronym from their show. (more)

HHSC Wants Blimpies
Rep. Michael McCaul, chairman of the House Homeland Security Committee, said Friday that he wants to redeploy U.S. military spy blimps in Afghanistan to America’s southern border. (more) Poop on them if they don't know about this. (more)

Former NSA Head Said 
“Our data’s in there (NSA databases), my data’s in there. If I talk to an Al Qaeda operative, the chances of my data being looked at is really good, so I try not to do that. If you don’t want to you shouldn’t either,” he told MIRcon delegates. (more)

GCHQ Director - Private Companies Snoop More Than Intelligence Agencies

Phone and internet users should be worried about big commercial companies, rather than intelligence agencies obtaining and sharing their private data, Government Communications Headquarters (GCHQ) Director Sir Iain Lobban said in an interview with the Telegraph.

"Look, who has the info on you? It's the commercial companies, not us, who know everything – a massive sharing of data," Lobban was quoted as saying by the newspaper on Friday.

"The other day I bought a watch for my wife. Soon there were lots of pop-up watches advertising themselves on our computer, and she complained," the GCHQ director added. (more)

Tuesday, October 7, 2014

Microsoft's Windows 10 has permission to spy on you!

via Lauren Weinstein...

"Microsoft collects information about you, your devices, applications and networks, and your use of those devices, applications and networks. Examples of data we collect include your name, email address, preferences and interests; browsing, search and file history; phone call and SMS data; device configuration and sensor data; and application usage."

"If you open a file, we may collect information about the file, the application used to open the file, and how long it takes any use [of]it for purposes such as improving performance, or [if you]enter text, we may collect typed characters, we may collect typed characters and use them for purposes such as improving autocomplete and spell check features." (more)

"Such as" implies more than just two examples. 

StealthGenie CEO Arrested

Federal officials announced the arrest of the maker of a popular smartphone app marketed as a tool for catching cheating spouses by eavesdropping on their calls and tracking their locations — a technology critics have dubbed “stalker apps.”

In the first prosecution of its kind, federal officials said that StealthGenie violated the law by offering the ability to secretly monitor phone calls and other communications in almost real time, something typically legal only for law enforcement. The arrest comes as the market for surveillance software has grown so big that Web sites rank such apps on their price, features and even customer service...

The chief executive of the company that makes StealthGenie, Hammad Akbar, 31, of Lahore, Pakistan, was arrested in Los Angeles on Saturday, according to a news release from the Justice Department...
Court filings suggest that Akbar has contended that any legal issues were limited to the users of SmartGenie, not its maker. “When the customer buys the product, they assume all responsibility,” he wrote in a 2011 e-mail, court filings show. “We do not need to describe the legal issues.

Efforts to reach Akbar’s attorney, based in Los Angeles, were not successful. (more)

FutureWatch - Will he pull the "primarily useful" card from the deck? This is what many audio eavesdropping gadget manufacturers used in the past to evade the law. 

"Hey, its a baby monitor."... that can hear through concrete walls.

Thursday, October 2, 2014

The Unpatchable Malware That Infects USBs Is Now on the Loose

...two independent security researchers, who declined to name their employer, say that publicly releasing the USB attack code will allow penetration testers to use the technique, all the better to prove to their clients that USBs are nearly impossible to secure in their current form. And they also argue that making a working exploit available is the only way to pressure USB makers to change the tiny devices’ fundamentally broken security scheme. (more)