Showing posts with label Government. Show all posts
Showing posts with label Government. Show all posts

Thursday, May 8, 2014

Security & Hacking: DEFCON 20 "Can You Track Me Now?"



DEFCON 20: Can You Track Me Now? Government And Corporate Surveillance Of Mobile Geo-Location Data

This was posted on Youtube November 22, 2012, so was well before Snowden release of information in May of 2013.

Main emphasis of this talk was tracking of cell phones.

But Christopher Soghoian briefly covers, at 31:05, that both Android (Google) & iOS (Apple) device encryption can be defeated by Google & Apple respectively.

This is a service they provide for Law Enforcement & other Government agencies.

Google can force a password reset for Android device, they don't require physical access.

Apple appears to use what Soghoian calls a "Master Skeleton key," they require departments to provide actual device (ie physical access).  They then provide unencrypted data on a CD, while device remains encrypted.

I wonder if they might actually need device to decrypt data with way devices since iPhone 4S & iPad 2 have been designed (they have hardware based encryption).

Entire video is worth watching, though it is rather long, they joke about having 3 different audience during the course of the talk.
 



Thursday, April 4, 2013

CNET "Apple's iMessage encryption trips up feds' surveillance"

http://news.cnet.com/8301-13578_3-57577887-38/apples-imessage-encryption-trips-up-feds-surveillance/

They cite a blog post from last August by Matthew Green http://blog.cryptographyengineering.com/2012/08/dear-apple-please-set-imessage-free.html

I follow Green's blog and can recommend it to anyone that is seriously interested in cryptography and/or data privacy.

Blackberry's BBM (Blackberry Messenger) http://en.wikipedia.org/wiki/BlackBerry_Messenger has long been secure as well, though I believe in recent years government pressure has forced some changes in that.

For more on BBM see http://computer.howstuffworks.com/e-mail-messaging/blackberry-messenger.htm

For general info on Blackberry security see http://www.berryreview.com/2010/08/06/faq-what-communication-is-encrypted-on-your-blackberry/

Note there are differences between BES (Enterprise Blackberry) and BIS (Consumer Blackberry), but (AFAIK) in general that doesn't matter for BBM.

According to  http://bgr.com/2013/02/27/blackberry-messenger-security-vulnerability-346634/ it seems that BBM on BIS lacks higher level security options just like email:

"“Although PIN-to-PIN messages are encrypted, they key used is a global cryptographic ‘key’ that is common to every BlackBerry device all over the world,” Public Safety Canada official stated in the memo. “Any BlackBerry device can potentially decrypt all PIN-to-PIN messages sent by any other BlackBerry device.”"

and
"It should be noted that Public Safety Canada has failed to take into account the fact that organizations have the ability to change the encryption key to a unique one, ensuring that only BlackBerry devices using the same BES network can communicate with each other. There are also several ways to encode BBM messages such as S/MIME, which adds another layer of security."

Tuesday, March 19, 2013

Friday, March 15, 2013

Nerd News: "Gagging recipients of National Security Letters found unconstitutional"

http://arstechnica.com/tech-policy/2013/03/gagging-recipients-of-national-security-letters-found-unconstitutional/

A small step forward IMO.

As I have mentioned before, I have a lot in common with research librarians, have several friends that are professional librarians and some that are directors of libraries.

I know they all hate this part of the so called "Patriot Act," since they could be forced to reveal everything people were doing at library.

Fact is, many libraries changed their data collecting practices to limit amount/types of data they kept on patrons, students, and faculty because of the the Patriot Act.

Tuesday, October 16, 2012

Security & Hacking: "Hackers hit small US town, steal tax payer data and $400,000"

http://nakedsecurity.sophos.com/2012/10/15/burlington-hacker/

Online banking isn't safe, though everyone is gradually being forced in that direction, since mailing statements cost time and money.

If you are going to do online banking or other finicail transactions, like stocks or other investments, then use a Live CD or as a distant 2nd choice, use a  iOS device on a private password protected WiFi connection.

For iOS devices were security is concerned you want to use an iPad 2 or newer, iPhone 4S or newer, or 2012 iPod Touch or newer device, because there are hardware related limitations to the security of earlier iOS devices (some security features were add in the hardware, and also some of the more recent software security features require the more powerful CPU & etc of the newer devices).

Here is a Guide to using Live CD by someone who knows what he is talking about, Brian Krebs, http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_non.html 

Link above is older one from when Krebs was still writing for the Washington Post, here is more recent one from the Washington Post (2010) http://voices.washingtonpost.com/securityfix/2009/10/avoid_windows_malware_bank_on.html 

And one from this year, on Live CD from his blog Krebs On Security http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/

I have also suggested to a few people, that having two separate Bank or Credit Unions, and having some of their money split between them, would be helpful if you do get hacked.

Since you might only lose money from one institution, so you would have some money available to pay Rent/Mortgage, buy food, keep paying for Medical & other types of important insurance, and buying medicine.

You might get some money back if this happens to you, but there is no guarantee of that.

Sadly for the city workers hit by this, ones that were getting their paychecks direct deposited, even having two separate accounts might not have helped them at all.


Monday, August 13, 2012

Security & Hacking: "Math Model Identifies Network Source of Rumors, Epidemics"


See http://sciencebusiness.technewslit.com/?p=10795 for full story.

Short version, they use some type of statistical sampling (I believe) to locate probable source of events, this can be used for tracking source of Malware, Spam, Rumors, Epidemics, etc.

While a very useful tool, this also has clear implications for freedoms, it could make SOPA look like nothing, and it is frightening to consider what a truly repressive government could do with such a tool.
 
Excerpt (?) of Paper, authored by  Pedro C. Pinto, Patrick Thiran, and Martin Vetterli, can be seen at (PDF) http://www.pedropinto.org.s3.amazonaws.com/publications/locating_source_diffusion_networks.pdf

Full paper, behind paywall, at Phys. Rev. Lett. 109, 068702 (2012) [5 pages]Locating the Source of Diffusion in Large-Scale Networks

DOI:
10.1103/PhysRevLett.109.068702
PACS:
89.75.Hc, 89.20.Hh, 89.75.Da


According to PDF link:
  • "This work was supported by the ERC Advanced Grant – Support for Frontier Research – SPARSAM Nr: 247006."
  • "[16] See Supplemental Material at [URL will be inserted by pub- lisher] for additional details on proofs, accuracy of approxi- mations, complexity, and parameters of the case study."