Sunday, November 13, 2011

"Yes, we have no Bananaman. We have no Bananaman, today."

A young Russian woman at the centre of a sex and spying scandal in Britain asked her German diplomat lover to pass on Nato secrets, intelligence sources have claimed.

It is believed Katia Zatuliveter made several attempts to get him to divulge information, including details of a top-secret Nato paper.

Miss Zatuliveter, 26, is facing deportation over claims she was working for Russian intelligence while having an affair with Liberal Democrat MP Mike Hancock. (more)

Tune in next week for the exciting conclusion...

WWI mystery spycatcher family discovered

BBC - More has been discovered about the life and curious times of a World War I "unknown heroine", whose spycatching exploits were found in the archives of the Royal Society of Chemistry.

In 1915, Mabel Elliott helped to uncover a German spy plot - but little was known about her background. An appeal for more information has found her surviving family - and a possible link to a German connection. But it also raises more questions about her role in this real-life spy story.

This unsung heroine, who spoke German and Dutch, had worked as a censor during the First World War and in 1915 had found a letter being sent to Holland with secret messages in invisible ink.

The discovery of these messages, written with lemon juice and formalin, detailing military movements, prompted the arrest of a suspected German spy, Anton Kuepferle. But before his trial had been concluded, the accused spy was found hanged in his cell, after apparently using a silk scarf to kill himself. He was said to have left a message admitting that he was a German officer. (Suicide. Silk scarf. Confession?!?! Are you buying this?) (more)

Could Facial Recognition Become the Next Emergency Broadcast System

The Emergency Broadcast System (EBS), a communications system which allows the government to commandeer radio and television broadcasting outlets to distribute emergency messages quickly, was tested this past week. The EBS started in 1963, and was preceded by a similar service called, CONELRAD. Electronic eminent domain has been around a long time. Hold that thought.

Today, The New York Times reports Face Recognition Makes the Leap From Sci-Fi.

"SceneTap, a new app for smart phones, uses cameras with facial detection software to scout bar scenes. Without identifying specific bar patrons, it posts information like the average age of a crowd and the ratio of men to women, helping bar-hoppers decide where to go. More than 50 bars in Chicago participate... The spread of such technology — essentially, the democratization of surveillance — may herald the end of anonymity. 

Those endeavors pale next to the photo-tagging suggestion tool introduced by Facebook this year... “Millions of people are using it to add hundreds of millions of tags,” says Simon Axten, a Facebook spokesman. Other well-known programs like Picasa, the photo editing software from Google, and third-party apps like PhotoTagger, from face.com, work similarly. 

And this technology is spreading. Immersive Labs, a company in Manhattan, has developed software for digital billboards using cameras to gauge the age range, sex and attention level of a passer-by.

Using off-the-shelf facial recognition software, researchers at Carnegie Mellon University were recently able to identify about a third of college students who had volunteered to be photographed for a study — just by comparing photos of those anonymous students to images publicly available on Facebook."
Have you connected the dots yet? 

Here is another clue...  
CALEA, a law passed in 1994, "To amend title 18, United States Code, to make clear a telecommunications carrier's duty to cooperate in the interception of communications for Law Enforcement purposes, and for other purposes." Telecommunications yet another type of mass communications device which may now be commandeered by government.

Internet connected, facial recognition systems are rapidly becoming mainstream mass communications technology, just like radio, TV and telephones. It only makes sense that this too will be commandeered. The question is, will it be commandeered like EBS to broadcast emergency messages, or will it be commandeered like CALEA to be used for surveillance? Both, perhaps?

So far, the benefits of letting government commandeer mass communications (verses the abuse potential) make the gambit worthwhile. For this, we thank our legal system. It is time for them to walk the high wire again. Please, get us through this technical conundrum with grace and balance one more time.

The noose tightens... "You can run, but you can't hide." 

Should this all come to pass (it will), there may be some interesting social outcomes. Just as mass communications pulls society closer together, mass surveillance capabilities like CALEA, license plate readers, and the multitude of facial recognition surveillance systems may push people apart. Imagine a world where the density of: commercial video billboards and kiosks; business surveillance cameras; and government street/toll booth cameras, in urban areas, squeezes criminals into the suburbs and beyond.

How best to take advantage of the changes in our brave new world? 
I have a career tip for you.

~ Kevin

Saturday, November 12, 2011

This Week in World Spy News

Spy Day Celebrations In Russia - In Russia, every November 5th is "Spy Day," and celebrates a century of Russian espionage. This special day is not a leftover from the Soviet Union. Spy Day was established in 2000, by Vladimir Putin, the recently elected president of Russia, whose professional experience was as a Soviet era spy. But this was not an effort to regain some respect for Soviet era spies (many of whom were out of work after the Soviet Union dissolved in 1991). Rather, Putin was bringing attention to peace time spying. Like China, Russia has been very active in stealing foreign technology, and needs skilled spies to do it. (more)

Murdoch apologises for spying on parliament members - News Corp executive James Murdoch said on Thursday that staff within his company had ordered private investigators to follow and investigate members of the parliamentary committee investigating the phone hacking scandal. (more) 

EDF fined €1.5m for spying on Greenpeace - The energy company's former security chief was sentenced to three years in prison for employing a firm to hack into the energy watchdog's computers. (more) 

Facebook Chief: We're Not the Only Ones Spying On You - The complaint that Facebook prioritizes its own revenue targets above user security is hardly new. However, there is something fresh about Facebook CEO Mark Zuckerberg's recent attempt to distract users by pointing a finger at other tech companies -- most notably Microsoft, Google and Yahoo -- accusing them of being far less privacy conscious than Facebook. (more) 

WIFE SPYING ON HUBBY SPARKS A BOMB SCARE - A JEALOUS wife sparked a bomb scare when she had a tracking device fitted to her husband’s £40,000 sports car. Diletta Bianchini had private investigators install a GPS tracker to William Sachiti’s Lexus SC430. But when he found the gizmo he thought it was a bomb and rushed to the police. (more) 
 
Canada’s top spy watchdog resigns following National Post revelations - Arthur Porter, the chair of Canada’s spy review board, resigned on Thursday amid revelations of his business dealings with a notorious international lobbyist and his own close ties to the president of Sierra Leone. (more) 

Nixon Warned Grand Jury on Pentagon Spy Ring - Newly unsealed grand jury testimony by ex-President Richard Nixon shows he warned prosecutors and grand jurors not to probe an episode from 1971, when he discovered that the Joint Chiefs of Staff had been spying on him and national security adviser Henry Kissinger.  “Don’t open that can of worms,” Nixon told his interrogators in June 1975... (more) 

Nixon Peabody sued by tech firm over spy-ring claims - Nixon Peabody and two of its attorneys have been sued by an Illinois technology firm claiming that the lawyers were part of a scheme to paint company executives as part of a international spy ring. (more)

What did you expect? Spies steal stuff - Debutante plagiarist Q.R. Markham's temporarily-lauded spy thriller, Assassin of Secrets, is in fact a string of passages lifted from other books in the genre. No-one noticed until it was released, at which time readers noticed at once. The book's been recalled by publisher Little, Brown, whose president, Michael Pietsch, apologized in a prepared statement... (more)

Thursday, November 10, 2011

The Sign Said Office - The Guts Said SpyCam

Features
Color video and audio recording
Motion detection mode
Still image mode
Audio detection mode
Audio only recording mode
Time/date stamp

Technical Specs
Audio detection level: 60db
Power supply: Internal Li-Ion
Battery life: 2 hours recording time, up to 150 hours standby
Charging time: 2.5-3 hours
Still image resolution: 1600 x 1200
Video resolution: 640 x 480 @ 25FPS
File size: 40MB per minute
Weight 55g
Dimensions: 180 x 90 x 11mm
Storage: Micro SD Cards up to 16GB

Includes
1 Office sign
1 Software disc
1 Instruction booklet
1 USB Charging/Video out cable

Why do I mention it? So you will know what you're up against.

Wednesday, November 9, 2011

Today, a reporter asked me about corporate espionage...

Protect Your Assets - counterespionage.com
Q. Would you say that in addition to legitimate competitive intelligence gathering, that most major [industry deleted] manufacturers engage in industrial espionage of some kind as well? Or would this be exaggerating things?

A. If you use the term espionage broadly, I would say all. Everyone keeps an eye on the competition to some extent. Many of the tactics are legal, such as 'open source competitive intelligence'.

If you mean unethical espionage, I would say most. But, take into account that "unethical" means different things in different cultures. Eliciting information from a competitor's employee under a pretext may be viewed as unethical by some cultures, other cultures view it as a patriotic act …and, if that competitor has not taken steps to protect their valuables, then it is the competitor's business ethics which are questionable.

If you mean illegal espionage, then I would say probably most, but it is impossible to know for certain. Like all espionage, if conducted correctly, it is not found out. The cases of illegal espionage that we read about in the papers, and wind up in the courts, are the failures. They constitute the tip of the 'spyberg'.  

My feeling from being in the corporate counterespionage business for over three decades is that everyone engages in some form of espionage. And, over time, most of them have stepped into the last two categories (unethical and illegal) to some extent. These transgressions can range from occasionally accepting information without questioning how it was obtained, to the few who ruthlessly plot and snatch from the unsuspecting, like monkeys in a Buddhist temple.

Q. Is there a fine line between legitimate competitive intelligence gathering and spying - or is it very clear cut? (eg. As a journalist I have sometimes posed as someone working in industry when trying to find things out from a company switchboard in order to gain some information when they won't take calls from reporters etc.)

A. We actually call it a grey line. As I mentioned in the last question, there are varying shades of grey. In fact, you may want to interview Andrew Brown, the author of a revealing new book called, The Grey Line: Modern Corporate Espionage and Counter Intelligence. In the book he explains exactly how corporate espionage is conducted.

Q. If a major firm wants to find out what its biggest rival is up to, will it typically employ a third party specialist or attempt to gather the information in-house?  If they do seek out a specialist, are there a handful of key firms/individuals that are well-known in the trade or is it a much more fragmented industry?!

A. Business consultants and their minions (or "cutouts" as we call them) are the prime conduits of business intelligence. Most companies want 'the goods' but don't want to know how they were obtained, or get their hands and reputations dirty if the operation is exposed. That being said, it is known that some companies have dedicated in-house personnel, for better control. 

Also take into consideration that the government intelligence agencies of just about all countries (except the U.S.) actively collect and present business intelligence information to businesses in their homelands.

There are also people who occasionally pop up and try to sell information on a free-lance basis, or on-spec. My feeling is that they are looked upon with suspicion by potential buyers, as we hear about buyers alerting the victimized competitor to their offers. Makes sense. One never knows when one is being set-up.

Auto Speed Cam Tickets Everyone in Real Time

The Cordon multi-target photo radar system can keep tabs on as many as 32 vehicles moving along on a four lane highway using sensors that measure the speed of cars as they come in and out of the frame and recording their license plate numbers. Built-in infrared radar enables the technology to work 24 hours a day and the system can be networked to stream the data continuously to a central database via 3G, WiMAX or Wi-Fi.

There are currently speed enforcement photo cameras operating in some states, though the radar can’t track more than one vehicle at a time. ...it doesn’t only go after speedsters. The system can catch drivers sneaking into bus lanes or driving the wrong way thanks to integrated GPS technology that monitors a car’s coordinates. (FutureWatch - It will also conduct automated look-ups for outstanding warrants and stolen vehicles.) 

The radar camera system isn’t scheduled to debut in North American streets until 2012, so drivers with a heavy foot do have some time to repent and change their reckless ways. (more)

Answers to last week's spy quiz...

What is the name of this famous spy story town?
The Village. From the 60's TV show "The Prisoner".



What is its real name?
Portmeirion. Located in Wales.
Did I live there for a week?
Yes!
Cool place. 
Visit their webcam.
Better yet, go there for a week.

Can't go? 

Tuesday, November 8, 2011

Visual Surveillance Snags Smartphone Texts

Last month, there was news from video provider Qumu of their discomforting survey that at least half of Americans would use smartphones to secretly spy on others. 

Now there is rattling news that spy software can easily do that kind of job. The software can reveal what others are texting in their personal emails or text messages sent forth on their smartphones just by the snooper using a smartphone camera or advanced camera like a digital SLR that shoots HD video, which could read a screen up to 60 metres away.

Researchers from the University of North Carolina Chapel Hill have used iSpy, the program, as proof that keying a private email message or text message in public, whether on a near-empty train or at the far end of a park bench away from everyone else, is still risky business.

They successfully were able to compromise the privacy of users typing on virtual keyboards with iSpy. They say iSpy can identify all the text typed on a smartphone display using video footage of the screen. (more)

Security Director Alert: How Spies Convince Someone They Work in Your Building

Re-framed, this article makes an excellent social engineering warning for your employees. The unknown person who fits this profile is exactly the person you want them to challenge...

There are fewer opportunities to put your social engineering skills to the test better than trying to convince someone you work at their establishment. Whether you just want to serve yourself a drink refill at a restaurant or you want to surprise your significant other with a birthday bouquet, here's how to get in unnoticed...

Take Advantage of Human Nature
The best way to get into a building or office that you want access to is to go in behind someone else. Most people call it "tailgating," and it's a serious security issue for offices, apartment complexes, college dorms, anywhere with restricted access, but it's your best friend here. 

Probably not a spy.
Dress the Part
This part requires some familiarity with the place you're going to visit, but no one is going to believe you work in an office where everyone is wearing shirts and ties if you walk in wearing a polo and jeans. Make sure you dress at or slightly above the dress code for the place you're visiting.

Be Ready for Questioning
Ideally, you'll be able to slip into an office and get around to where you need to be without any questioning at all. However, if you're overdressed, underdressed, or just unlucky enough to run into a curious employee, you need to be ready to deal with it.

Remember to Smile
Not always, of course—grinning to yourself will make you stand out—but keeping a relatively upbeat and positive demeanor will make you stand out less than someone who's hunched over, shifty-eyed, and ducking around corners wearing a Mission: Impossible serious-face. People by nature avoid confrontation, and you can use this to your advantage by being confident, being positive, and engaging when appropriate. (more via Alan Henry at lifehacker.com)

Tomorrow, the US Goverment Takes Over the Airwaves

If you have ever wondered about the government’s ability to control the civilian airwaves, you will have your answer on November 9th.

On that day, federal authorities are going to shut off all television and radio communications simultaneously at 2:00PM EST to complete the first ever test of the national Emergency Alert System (EAS).

Only the President has the authority to activate EAS at the national level, and he has delegated that authority to the Director of FEMA. (more)

QR Codes - Taking Candy from Strangers

QR codes, part of popular marketing strategies created to engage mobile device users, have become a vector for malware that hackers could use to remotely access all of the data in a person’s phone and record their every move through pictures and audio, according to cybersecurity researchers. And there’s no way to know once a device is infected.

In an interview on Tuesday with Security Management, Nicholas Percoco, senior vice president and head of Trustwave SpiderLabs, a group of ethical hackers at a data security firm with expertise in investigations, research, and application security, said that most attacks that happen on mobile platforms occur when a user goes to malicious URL or they’re redirected to a Web site containing malicious code. Hackers are using QR codes as a tool to direct mobile phone users to those Web sites and infect mobile devices with malware. (more)

Sunday, November 6, 2011

Foreign Spies Stealing US Economic Secrets Report Released (FREE)

The Office of the National Counterintelligence Executive (ONCIX) Report: "Foreign Spies Stealing US Economic Secrets in Cyberspace - Report to Congress on Foreign Economic Collection and Industrial Espionage, 2009-2011" has been released.
Foreign economic collection and industrial espionage against the United States represent significant and growing threats to the nation's prosperity and security. Cyberspace—where most business activity and development of new ideas now takes place—amplifies these threats by making it possible for malicious actors, whether they are corrupted insiders or foreign intelligence services (FIS), to quickly steal and transfer massive quantities of data while remaining anonymous and hard to detect.

Pervasive Threat from Adversaries and Partners:
Sensitive US economic information and technology are targeted by the intelligence services, private sector companies, academic and research institutions, and citizens of dozens of countries.

• Chinese actors are the world’s most active and persistent perpetrators of economic espionage. US private sector firms and cybersecurity specialists have reported an onslaught of computer network intrusions that have originated in China, but the IC cannot confirm who was responsible.

• Russia’s intelligence services are conducting a range of activities to collect economic information and technology from US targets.

• Some US allies and partners use their broad access to US institutions to acquire sensitive US economic and technology information, primarily through aggressive elicitation and other human intelligence (HUMINT) tactics. Some of these states have advanced cyber capabilities.

Outlook:
Because the United States is a leader in the development of new technologies and a central player in global financial and trade networks, foreign attempts to collect US technological and economic information will continue at a high level and will represent a growing and persistent threat to US economic security. The nature of the cyber threat will evolve with continuing technological advances in the global information environment.

"You're only a stranger here once!" ~Tampa, FL

Do you recall my prediction about Tampa?
FutureWatch (September 2008) - Although facial recognition and tracking didn't catch on the first go-around (the Tampa, Florida experiment), it is ripe for a come-back. 5 years from now, this will be commonplace – along with automatic license plate readers and motion-intention evaluators.

August 2003 - Tampa police have scrapped their controversial security camera system that scanned city streets for criminals, citing its failure over two years to recognize anyone wanted by authorities.

History...
July 2001 - The Tampa City Council took a fully-informed look at Ybor City's controversial high-tech face-scanning software. When the dust settled, the council split down the middle with a 3-3 vote on whether or not to do away with the face-scanning software.

Fast Forward... 2011 - via National Motorists Association...
The request reads like a shopping list for a counter-terrorism strike: low-light cameras to identify people and vehicles at 100 meters, helmet-mounted cameras, cameras for "use around high-risk activities" and cameras that can read license plates across three lanes of traffic.

In reality, it’s part of a plan proposed by Tampa city officials to provide security for next year’s Republican National Convention. Funds to buy or lease the gear are expected to come from federal taxpayers in the form of a $55 million congressional appropriation.

The surveillance will target convention protestors (as many as 10,000, according to convention organizers), but, given the sweeping nature of the plan, many bystanders and motorists are likely to be ensnared as well.

And while police officials admit they may not get all 238 cameras on the original request, critics are already reacting. A spokesperson for the American Civil Liberties Union of Florida likens the approach to "hitting a gnat with a sledgehammer." (To be fair, officials canceled a request for two aerial surveillance drones due to cost concerns.)

FutureWatch - Drones are already in some state and local police toy chests. Tampa will eventually get one, too.

"Anyone who feels they were hacked, please raise your hand."

News Corporation has begun a voluntary program that allows people who believe they have been the victims of phone hacking to apply online for compensation.

A statement issued Friday by the company’s British publishing unit, News International, urged possible victims to take advantage of the settlement plan, calling it a “speedy, cost-effective alternative to litigation.” Charles Gray, a former High Court judge and arbitration specialist, will assess the applications and serve as an independent adjudicator, News International said. There is no limit on how much the company might have to pay. (more)

"Come on, Joey. Halloween is over."

MA - Police arrested a Framingham man at gunpoint yesterday after he chased two women with a sharp lawn-edging tool, a prosecutor said yesterday in Framingham District Court.

Joseph Kenney, 48, is also charged with trying to illegally record police with his cellphone, prosecutor Christopher Baker said during Kenney's arraignment.

Police went to Elm Street yesterday around 1 a.m. to check on a large gathering in the street. There, they found Kenney chasing two women with a lawn edger, Baker said.

"The officers ordered him to drop it, and he didn't until the officers drew their weapons," Baker said.

Kenney complained that "those kids are always in my parking lot" so he confronted them, Baker said.

Police arrested Kenney, who lives at 10 Elm St., and initially charged him with assault with a dangerous weapon and disorderly conduct.

On the way to the police station, the officer noticed Kenney was using his phone, Baker said. Kenney told the officer he was recording him.

The officer said Kenney did not have permission to record his voice, but Kenney refused to stop. As a result, police charged Kenney with illegal wiretapping. (more)

True story. Only the street name has been changed to protect the innocent.

Friday, October 28, 2011

"Wake up, Nguyen. Time to spy on the submarine races."

When foreign spies set their sights on America's secrets, many times they're not looking underground for secret bunkers or in the sky for massive spy blimps, but under the sea at the nation's low-profile underwater drone fleet.

According to some of the military's top counterintelligence analysts, in recent years there has been a significant increase in both old school spying and cyber operations, especially by unnamed East Asian nations, directed at gaining classified information on America's autonomous underwater vehicles (AUVs) in hopes of undercutting the U.S.'s "underseas battlespace dominance." (more)

Must be a Saturday Night Live skit that didn't get used...

Croatian businessman Vladimir Selebaj, who has been jailed over malversations with his production company Core Media, speaks to his parents only in French due to fears of wiretapping.

A French citizen, Selebaj allegedly talks only in French during his parents visits because he thinks he is being targeted by the police chief, Oliver Grbic.  

Grbic is currently in a relationship with Selebaj’s wife, Dijana Culjak.

Selebaj has been detained in Zagreb Remetinec prison while the investigation is underway, daily Vecernji List writes. (more)

BlackBerry / India Ink Surveillance Contract - RIM shot

 Remember when India was threatening to shut down BlackBerry service unless it could tap user's communications? Reports have RIM operating a wiretapping facility in Mumbai to help with that.

Back in 2010, the Indian government set multiple deadlines for RIM to provide the government with access to encrypted BlackBerry communication or face a shutdown of BlackBerry services in the country. Those deadlines came and went, with RIM insisting that it has no back door that would let government authorities (or anybody else) decrypt and access communications on its BlackBerry Enterprise services

However, by the beginning of 2011 RIM had been working with the Indian government to provide access to consumer-level BlackBerry Messenger and BlackBerry Internet Services (BIS) email—and now the Wall Street Journal reports RIM is operating a small surveillance facility in Mumbai to process government requests for access to BlackBerry user communications. (more)

Spy Train Tracks Wirey Thieves

Using a thermal camera to track copper cable thieves.
UK - Network Rail said covert spy train patrols to deter metal thieves from the rail network are having an effect.

In the last year the price of copper has doubled and this year alone in the east there have been 72 serious incidents of cable theft, causing delays to more than 2,500 trains and costing the company more than £1m.

Look East joined Network Rail and the British Transport Police on a special spy train as they went on the hunt for thieves in Essex and Hertfordshire. (video)

A Simple Three Question Spy Movie Quiz

Go here
I got 2 of three. 
See what you can do.

Here is one from me...
What is the name of this famous spy story town?
What is its real name?
Did I live there for a week?

Answers later next week.

Enjoy your weekend!
~Kevin

Thursday, October 27, 2011

Security Alert: Easy Bypass of iPad2 Passcode Screen (w/ fix)

PROBLEM...
Apple's Smart Covers are pretty cool--they attach magnetically to your iPad 2, and you can lock your iPad's screen simply by "closing" the cover. Lift the cover off the screen, and your iPad wakes right up. Unfortunately, members of the German forum Apfeltalk ("Apple Talk") discovered a bug in how iOS handles the Smart Cover that makes it possible to bypass the iPad's passcode screen. Yikes.

To trigger this glitch, hold down the power button and wait for the iPad to ask to power off. When that happens, place the smart cover over the tablet. Next, take the cover off again, cancel the power down, and you're in--no passcode required.

SOLUTION...
Apple is aware of the issue and is working on a fix. And for the time being, you can make it so your iPad doesn't automatically unlock when you open your Smart Cover; that way, even if someone uses this bypass trick, they'll only be greeted with the passcode screen. To change this setting, Open the Settings app, tap General, and change the setting for "iPad Cover Lock/Unlock" to "Off". (more)


Wednesday, October 26, 2011

Gang Members Are Coming For Your Info. What's Your Counterespionage Strategy?

The Federal Bureau of Investigation on Friday estimated there are some 1.4 million gang members in the United States and they are turning to white-collar crimes as more lucrative enterprises. 

Gangs like the Bloods and the Crips are engaging in crimes such as identity theft, counterfeiting, selling stolen goods and even bank, credit card and mortgage fraud, said a new FBI gangs threat assessment.

"We've seen it, but we've seen them doing it even more now and we attribute to the fact that the likelihood of being caught is less, the sentences once you are caught are less, and the actual monetary gain is much higher," said Diedre Butler, a unit chief at the National Gang Intelligence Center. (more)

Tuesday, October 25, 2011

Search Engine Encrypts Your Secret Yearnings, Lusts and Thirsts... for Knowledge

Click to enlarge.
Flash - "As of this week, Startpage, by Ixquick, the "world's most private search engine," automatically encrypts ALL searches. Startpage was the first search engine to offer SSL encryption in 2009, and today it again breaks new ground by making SSL encryption the default." (more)

Kevin's Security Scrapbook exclusive! Motion picture footage of the inside of a search engine's encryption kernel.

"Dude, Scientology has an Office of Special Affairs?!?! I didn't know scientists even had affairs!"

The Village Voice is reporting that the Church of Scientology attempted to investigate Parker and Stone after a controversial 2005 episode of “South Park” titled “Trapped in a Closet.” The Emmy-nominated episode, airing on Comedy Central, satirized such figures as Scientology founder L. Ron Hubbard and Scientology member Tom Cruise. 

According to the Voice, former Scientology executive Marty Rathbun “revealed at his blog that in 2006, Scientology's Office of Special Affairs — the church's intelligence and covert operations wing — was actively investigating” Parker and Stone.

The Voice reports Monday: “We have more leaked OSA documents which give some idea of the extent of the spying operation on the ‘South Park’ offices and the people who worked there.” (more)

Chat and...ZAP. Your address book is stolen!

If you use Skype on an iPhone or iPod touch, Phil Purviance can steal your device's address book simply by sending you a chat message.

In a video posted over the weekend, the security researcher makes the attack look like child's play. Type some JavaScript commands into the user name of a Skype account, use it to send a chat message to someone using the latest version of Skype on an iPhone or iPod touch, and load a small program onto a webserver. Within minutes, you'll have a fully-searchable copy of the victim's address book. (more)

Your Rotund Guard Can Be Replaced by Rotundus, the 3-D RoboEye

Security Director Alert - Imagine replacing multiple guards, at multiple sites with GroundBots... all reporting to your command center. 

Think of the money you could then devote to more worthwhile security needs - intellectual property protection needs - like, ummmm... TSCM!

You don’t need to read instructions to operate an arcade driving game. It’s intuitive. And that’s how easy it is to steer GroundBot in the manual control mode.

But there’s one big difference: when you’re driving GroundBot the landscape you’re moving through is for real. Streamed in real-time, in 2D or 3D. Operators say that it makes you feel you are actually there, sitting in GroundBot, looking out. 

Guardbot is also amphibious and efficient and can run up to 10 km/h (6 mph) - without making a sound. Moreover, it can operate for 8-16 hours depending on mission profile.

This near-reality experience also makes operators more alert to anyone or anything that shouldn’t be there. GroundBot can even be used to find out where an unauthorized person is going. (more) (video) (c.1968 prototype)

Monday, October 24, 2011

FBI Business Espionage Warning - "If you haven't been a victim yet, it's because you have been and you don't know it, or you will be."

Kexue Huang, a scientist and native of China, pleaded guilty last week in a federal court to swiping millions of dollars worth of trade secrets from Dow Chemical Co. and Cargill Inc. for other people doing research in Germany and China.

A federal jury last month ordered South Korea's Kolon Industries to pay DuPont Co. $920 million for stealing trade secrets regarding synthetic fibers used in such products as Kevlar body armor. A former DuPont engineer hired by Kolon, Michael Mitchell of Virginia, was sentenced in March last year to 18 months in prison for theft of trade secrets for passing on key DuPont data to Kolon.

And area technology companies are likely fooling themselves if they think they're not in the cross-hairs of such spy efforts, according to the Federal Bureau of Investigation."If you haven't been a victim yet, it's because you have been and you don't know it, or you will be," Barry W. Couch, a special agent with FBI's Buffalo division, told a conference room full of area optics industry executives last week. "Don't be blindsided."

The FBI has designated espionage, including economic espionage, its second-highest priority, behind only terrorism. (more)

Bug in the Boardroom - Nasdaq

New details have come out from the ongoing investigation into last year's attack on the Nasdaq stock exchange. 

It appears that when attackers breached the Director's Desk Web application, they not only gained access to data stored in the system, but they managed to install a monitoring software that was able to eavesdrop on "scores" of directors' communications

The application was used by board directors to discuss information relating to the company's financial performance and other intellectual property. (more)

Saturday, October 22, 2011

Security Director Alert: Occupy Wall Street would love to have A Bug in Your Boardroom

The Occupy Wall Street movement is expanding. 

Your company is the target. 

Just like animal rights and other business protest movements, intelligence helps fuel their cause. A bug in your boardroom is the ideal intelligence pipeline. (Don't think they haven't thought of doing it. All they need is a sympathetic insider who believes the boss makes too much.)

I addition to your normal preparations (perimeter security, monitoring social media, etc.) electronic countermeasures inspections (TSCM) must be part of your protection mix. Covert electronic eavesdropping, video voyeurism, data thefts and business espionage attacks are vulnerabilities you can not afford to overlook.

If you have a trusted TSCM provider, great, call them in.
If not, please stop by our web site. Learn all about our economical TSCM security solutions.

But, what if you find a bug?
Imagine... 
It's Monday morning. 
In the offices of Mongo Industries a secretary readies the Boardroom for the weekly strategy meeting. The air conditioning has been off all weekend, and just kicked in. Then...THUNK! 

Startled, she stares under the massive table. Her eyes adjust to the dark. A small dark object with gooey strips of masking tape near the Director's chair stares back.


"What should you do?" (click here)

Friday, October 21, 2011

Flash - Adobe Flash Spy Personality Disorder Fixed

Engineers on Thursday patched a hole in Adobe's ubiquitous Flash Player that allowed website operators to silently eavesdrop on visitors' webcam and microphone feeds without permission.  

To be attacked, visitors needed to do no more than visit a malicious website and click on a handful of buttons like the ones in this live demonstration. Without warning, the visitor's camera and microphone were activated and the video and audio intercepted. (more)

Adobe: "We have resolved the issue with a change to the Flash Player Settings Manager SWF file hosted on the Adobe website. No user action or Flash Player product update are required." (more)

Calling all cars: OTL DIY CSI Taps Over Possible Alibi Die Lie - Be on the Louk-out.

PA - State police are looking for a Washington man who is one of four accused of placing a wiretap in the home of a relative because they did not believe his alibi for the murder of a Buffalo Township woman.

Douglas Edward Louk, 42, whose last known address was 843 Broad St., is wanted on wiretapping and conspiracy charges. He is 5 feet 10 inches tall, weighs 210 pounds and has brown hair and blue eyes.

Anyone with information on Louk's whereabouts is asked to call state police at 724-223-5200. (more) (more)

"Dude, werz my dikshunary?" or... My lawyer can spell illegally, can yours?



CA - Billboards along Southern California freeways are urging motorists to contact lawyer Jeffrey Krinsk if they believe they were “Illegaly [sic] wire-tapped by the LA Times” or to “Report LA Times Fraud.” The San Diego attorney represents a man who is suing Times staffer Michael Hiltzik and claims the columnist secretly recorded telephone conversations. (Hiltzik’s accuser is Robert Silverman, an attorney who represents 1-800-GET-THIN, a company that markets Lap-Band weight-loss surgery.) The Times has published a series of articles and columns detailing the deaths of five patients after having Lap-Band surgery at centers affiliated with 1-800-GET-THIN. On Thursday, the paper told staffers in a memo that “we do not engage in wiretapping and fraud as the billboards allege” and that it’s confident that the lawsuit will be tossed. (more)

Cell Phone SpyWare Goes Legit

Realizing that the huge demand for parental monitoring programs for computers could also apply to phones, Dublin-based mobile web service company Associate Mobile has developed MobileMinder - a smartphone application running on a secure and encrypted network that allows parents to monitor their child's location, contacts, call history, photos, and web use. (more)

Edison Remembered

The real Edison lighthouse.
On Oct. 21, 1879, Thomas Edison invented a workable electric light at his laboratory in Menlo Park, N.J. (more) (The other Edison Lighthouse)

Thursday, October 20, 2011

TSCM - Get the Whole Picture of Your Information Security Health

A security program without TSCM is like a photo that only tells part of the story. 

Seen on the USS Midway this week.
• You might misinterpret, 
• you might be left wondering, 
• or maybe you'll just shrug it off with a laugh. 
All leave you weak and vulnerable.

Get the whole picture. Conduct TSCM inspections in your business. Make sure they incorporate a counterespionage survey. Get the whole picture. Know the truth. Feel confident.

Fun Stuff: Release Your Inner Muse, with Animoog

Alert: This app is available at 99 cents for about 25 more days. Then it goes to $29.99... and it's still a bargain.
This week work took me from New York to San Diego and back; about 10 hours on a plane. Animoog kept me captivated for most of my time in the air. The depth of musical creativity that I pulled from this was astounding. Not musically inclined? No problem, neither am I. I barely know a quarter note from a quarterhorse, yet after the first ten minutes I was making music. Beautiful sounds. Hey, the thing even records your songs for you. 

Bonus... The trips seemed like minutes instead of hours.

Have some fun this weekend. Relax. Make music. Regain your soul. You'll be surprised how good you'll feel afterward.

"Animoog is the first professional synthesizer designed for the iPad. Powered by Moog's new Anisotropic Synthesis Engine, Animoog captures the vast sonic vocabulary of Moog synthesizers and applies it to the modern touch surface paradigm, enabling any user to quickly sculpt incredibly fluid and dynamic sounds that live, breathe, and evolve as you play them." (more)