Wednesday, 28 July 2010

Archive of 100 million Facebook users available on Torrent

This is not technically webtapping, but a gentle reminder on why you should secure the information you make available online.

"A directory containing personal details about more than 100 million Facebook users has surfaced on an Internet file-sharing site. The 2.8GB torrent was compiled by hacker Ron Bowes of Skull Security, who created a web crawler program that harvested data on users contained in Facebook's open access directory, which lists all users who haven't bothered to change their privacy settings to make their pages unavailable to search engines."

(source: Slashdot)

Tuesday, 27 July 2010

UK ISP TalkTalk Caught Monitoring Its Customers

Another reason why you have to use secured protocols. Slashdot reports:
The UK ISP TalkTalk has been caught using a form of Deep Packet Inspection technology to monitor and record the websites that its customers visit, without getting their explicit consent. The system, which is not yet fully in place, ultimately aims to help block malware websites by comparing the URL that a person visits against a list of good and bad sites. Bad sites will then be restricted. TalkTalk claims that its method is totally anonymous and that the only people with visibility of the URL database itself are Chinese firm Huawei, which will no doubt help everybody to feel a lot better (apply sarc mark here) about potentially having their privacy invaded.

Sunday, 28 February 2010

Opening the Internet — with an Axe

Fernando Herrera-Gonzalez has published a great opinion, from the austrian economics and libertarian points of view on the Mises.org web site about the new regulations of the Internet proposed by the FCC.

The whole post is very much worth reading. I'm pasting here the conclusion:
The FCC's policy goal of guaranteeing the openness of the Internet as an engine for innovation and growth might seem appealing.

However, the Internet has played the role of "economic engine" up to this moment without the need of any intervention. The threats depicted by Mr. Genachowski are just not credible. Telecom companies have no incentives to block contents or services, because their business model would suffer even in the face of a possible cannibalization of revenues.

On the contrary, it is the proposed measures that are a serious threat to the Internet. The granting of these legislated rights will only have negative effects for their recipients: If the users demand those rights and they are ready to pay the costs, then there is no need of intervention. If the users do not demand them, then the enforcement of these legally defined rights will lead to the bankruptcy of the operator and thus a lack of service.

Moreover, the obligations of nondiscrimination and transparency will have negative effects on innovation, investment, and prosperity, instead of the positive effects that may be expected from the openness of the Internet.

This is what will happen if the government mandates the openness of the Internet by means of regulatory obligations. If we try to open the Internet with an axe, it is very likely that we will end up destroying it — and investment, innovation, and prosperity with it.

Friday, 5 February 2010

Police Want Law to Provide them with easy access to your Private Data

Another Slashdot report:
"According to this story on CNET, police again are pushing for new laws requiring ISPs and webmail providers to store users' private data for five years and also want a new electronic way of speeding up subpoenas and search warrants via police-only encrypted portals at all ISPs and webmail providers."

Microsoft to auction you're personal information?

Slashdot reports:
"Give Bill Gates your 'pictures, videos, documents, e-mail, instant messages, addresses, calendar dates/scheduling information (e.g., birthdays, anniversaries, appointments), voice mail, phone logs, RSS feeds, subscriptions, bookmarks, mail lists, project management features, computing device data, tasks and location data,' and he'll improve your 'quality of life.' That's the promise behind a patent issued Thursday to Bill Gates and his 20 co-inventors for 'Personal Data Mining', which Microsoft notes 'can include a monetization component' that 'could initiate an auction to sell information to the highest bidder.'"

Sunday, 20 September 2009

Facebook to Shut Down Beacon

Slashdot:
"Facebook has agreed to shut down its much-maligned Beacon advertising system in order to settle a class-action lawsuit. The lawsuit, filed in August of last year, alleged that Facebook and its Beacon affiliates like Blockbuster and Overstock.com violated a series of laws, including the Electronic Communications Privacy Act, the Video Privacy Protection Act, the California Consumer Legal Remedies Act and the California Computer Crime Law. The proposed settlement, announced late on Friday, calls not only for Facebook to discontinue Beacon, but also back the creation of an independent foundation devoted to promoting online privacy, safety and security. The money for the foundation will come from a US$9.5 million settlement fund."

Sunday, 17 May 2009

UK's Expensive Net Spying Plan Proceeds

PCPro:
The Government has dropped plans to create a massive database of all internet communications, following stern criticism from privacy advocates.

Instead the Government wants ISPs and mobile phone companies to retain details of mobile phone calls, emails and internet sites visited.

As with the original scheme, the actual content of the phone calls and messages won't be recorded, just the dates, duration and location/IP address of messages sent. The security services would then have to apply to the ISP or telecoms company to have the data released.

The new proposals would also require ISPs to retain details of communications that originated in other countries but passed over the UK's network, such as instant messages.

ITPro:
The government is set to require all telcos to record data between communications – mobile phones, text message, emails and instant messages, as well as internet browsing sessions to social networking sites such as Facebook.

The details of the Intercept Modernisation Programme were laid out in a consultation document released today. The government will be accepting advice on the plans until July 2009.

Any firm considered a communications service provider (CSP) – such as internet service providers (ISPS) and mobile operators – would be required to hold onto such data in case the government needed it, for anti-terror or policing reasons, for example.

Such CSPs will also be required to collect data from services that are based overseas but use UK networks.

A document from the Home Office stressed the data held would include who, when, where and how communications connections were made – but not the content. For example, the information held on an email would include who sent it, to whom they sent it, and when it was sent, but the content of the email would not be stored.

The Register:
Spy chiefs are already spending hundreds of millions of pounds on a mass internet surveillance system, despite Jacqui Smith's announcement earlier this week that proposals for a central warehouse of communications data had been dumped on privacy grounds.

The system - uncovered today by The Register and The Sunday Times - is being installed under a GCHQ project called Mastering the Internet (MTI). It will include thousands of deep packet inspection probes inside communications providers' networks, as well as massive computing power at the intelligence agency's Cheltenham base, "the concrete doughnut".

Sources with knowledge of the project said contracts have already been awarded to private sector partners.

Thursday, 19 March 2009

UK is considering snooping on all social networking traffic

Yet another attempt by the UK gov to spy on people and deprive them from their privacy. Slashdot reports:
"The UK government, which is becoming increasingly Orwellian, has said that it is considering snooping on all social networking traffic including Facebook, MySpace, and bebo. This supposedly anti-terrorist measure may be proposed as part of the Intercept Modernisation Programme according to minister Vernon Coaker, and is exactly the sort of deep packet inspection web inventor Sir Tim Berners-Lee warned about last week. The measure would get around the inconvenience for the government of not being able to snoop on all UK web traffic."

Monday, 23 February 2009

EU wants to tap your Skype calls

Slashdot reports:
"Suspicious phone conversations on Skype could be targeted for tapping as part of a pan-European crackdown on what law authorities believe is a massive technical loophole in current wiretapping laws, allowing criminals to communicate without fear of being overheard by the police. Eurojust, a European Union agency responsible for coordinating judicial investigations across different jurisdictions, has announced the opening of an investigation involving all 27 countries of the European Union."

Monday, 26 January 2009

Monster.com Data Stolen

This is a copy and paste from a Slashdot post:
"There's been another break-in at Monster.com. It's surprising that there are still unencrypted passwords stored in database despite the previous hack, as is the decision to not email users — presumably so that no one will make a fuss. From PC World: 'Monster.com user IDs and passwords were stolen, along with names, e-mail addresses, birth dates, gender, ethnicity, and in some cases, users' states of residence. The information does not include Social Security numbers, which Monster.com said it doesn't collect, or resumes. Monster.com posted the warning about the breach on Friday morning and does not plan to send e-mails to users about the issue, said Nikki Richardson, a Monster.com spokeswoman. The SANS Internet Storm Center also posted a note about the break-in on Friday.'"

Indymedia Server Seized By UK Police

This is a copy paste from a Slashdot post:
"On 22 January 2009, Kent Police seized an Indymedia server hosted by Manchester-based colocation facility UK Grid and run by the alternative news platform Indymedia UK. The server was taken in relation to comments on an article regarding the convictions in the recent Stop Huntingdon Animal Cruelty (SHAC) trial. Seven activists were sentenced to a total of 50 years in prison." The complete story is worth reading; timbrown continues: "I'm posting this as a concerned UK administrator who hosts a number of sites. The message appears to be clear: the UK establishment does not want political content, legitimate or otherwise, hosted from these shores. The message has been noted, however free speech must be supported even where it may not be agreeable."

Monday, 5 January 2009

UK Police allowed to hack into your home PCs

According to this Slashdot post:

"The Times of London reports that the United Kingdom's Home Office has quietly adopted a new plan to allow police across Britain to routinely hack into people's personal computers without a warrant. The move, which follows a decision by the European Union's council of ministers in Brussels, has angered civil liberties groups and opposition MPs. They described it as a sinister extension of the surveillance state that drives 'a coach and horses' through privacy laws."

Sunday, 5 October 2008

Skype Messages Monitored In China

Once more, Slashdot reports:
"Human-rights activists have discovered a huge surveillance system in China that monitors and archives Internet text conversations sent by customers of Tom-Skype, a joint venture between a Chinese wireless operator and eBay. Researchers say the system monitors a list of politically charged words that includes words related to the religious group Falun Gong, Taiwan independence, the Chinese Communist Party and also words like democracy, earthquake and milk powder. The encrypted list of words inside the Tom-Skype software blocks the transmission of these words and records personal information about the customers who send the messages. Researchers say their discovery contradicts a public statement made by Skype executives in 2006 that 'full end-to-end security is preserved and there is no compromise of people's privacy.' The Chinese government is not alone in its Internet surveillance efforts. In 2005, The New York Times reported that the National Security Agency was monitoring large volumes of telephone and Internet communications flowing into and out of the United States as part of an eavesdropping program that President Bush approved after the Sept. 11 attacks. 'This is the worst nightmares of the conspiracy theorists around surveillance coming true,' says Ronald J. Deibert, an associate professor of political science at the University of Toronto. 'It's "X-Files" without the aliens.'"

And Skype features a encrypted messaging system? And shows you a little lock at the bottom of each chat window!

Tuesday, 9 September 2008

Your mobile phone: the spy who you loved

I found this link on Slashdot. The article on CNet is quite scary.
Quote:
[...] private companies now sell off-the-shelf data-mining solutions to government spies interested in analyzing mobile-phone calling records and real-time location information. These companies include ThorpeGlen, VASTech, Kommlabs, and Aqsacom--all of which sell "passive probing" data-mining services to governments around the world.
According to the screenshot on the web page, you can with this software obtain the following information about any user:
  • physical location, tracking a person's move
  • email addresses he uses
  • call fingerprinting: you can follow the user even if he uses multiple SIMs and handsets
Read more if you want to have a look at the potential abuses that these technologies raises.

Friday, 5 September 2008

UK ISPs To Hand Over Thousands of File Sharers' Data

Slashdot reports:
"US game developer Topware Interactive, the people behind the now infamous Dream Pinball affair, are about to turn up the heat. Operating through London lawyers Davenport Lyons, they have managed to convince the High Court to send out an order demanding that ISPs in the UK start to hand over the details of several thousand alleged pirates... BT, one of the UK's largest ISPs..., confirmed it had been ordered to hand over details of alleged copyright infringing file-sharers... Virgin Media was a little more slippery in its response but reading between the lines it seems obvious they are involved too."

Wednesday, 27 August 2008

The Internet's Biggest Security Hole Revealed

Slashdot runs the following story:
At DEFCON, Tony Kapela and Alex Pilosov demonstrated a drastic weakness in the Internet's infrastructure that had long been rumored, but wasn't believed practical. They showed how to hijack BGP (the border gateway protocol) in order to eavesdrop on Net traffic in a way that wouldn't be simple to detect. Quoting: "'It's at least as big an issue as the DNS issue, if not bigger,' said Peiter 'Mudge' Zatko, noted computer security expert and former member of the L0pht hacking group, who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. 'I went around screaming my head about this about ten or twelve years ago... We described this to intelligence agencies and to the National Security Council, in detail.' The man-in-the-middle attack exploits BGP to fool routers into re-directing data to an eavesdropper's network."
Note that the US Government knows since 1998 how to eavesdrop without being noticed.

Thursday, 14 August 2008

UK Gov't Proposes Massive Internet Snooping, Data Storage

Slashdoted story on PC Pro UK:
The Government will store "a billion incidents of data exchange a day" as details of every text, email and browsing session in the UK are recorded under new proposals published yesterday.

The information will be made available to police forces in order to crack down on serious crime, but will also be accessible by local councils, health authorities and even Ofsted and the Post Office.

Tuesday, 5 August 2008

Information is "imported" can now be intercepted without a warrant

Shameless copy paste from http://www.cs.columbia.edu/~smb/blog/2008-07/2008-07-10.html

FISA and Border Searches of Laptops
10 July 2008

There's been a lot of attention paid recently to the issue of laptop searches at borders, including a congressional hearing and a New York Times editorial. I've seen articles with advice on how to protect your data under such circumstances; generally speaking, the advice boils down to "delete what you can, encrypt the rest, hope that Customs officials don't compel production of your key, and securely clean up the deleted files". If you need sensitive information while you're traveling, the usual suggestion is to download it over a secure connection, per the EFF:

Another option is to bring a clean laptop and get the information you need over the internet once you arrive at your destination, send your work product back, and then delete the data before returning to the United States. Historically, the Foreign Intelligence Surveillance Act (FISA) generally prohibited warrantless interception of this information exchange. However, the Protect America Act amended FISA so that surveillance of people reasonably believed to be located outside the United States no longer requires a warrant. Your email or telnet session can now be intercepted without a warrant. If all you are concerned about is keeping border agents from rummaging through your revealing vacation photos, you may not care. If you are dealing with trade secrets or confidential client data, an encrypted VPN is a better solution.

But is it?

When a laptop is searched, the customs agents are not looking for drugs embedded in the batteries or for whether or not the connectors have too much gold on the contacts. Rather, they're looking for information.

In that sense, it would seem to make little difference if the information is "imported" into the US via a physical laptop or via a VPN, or for that matter by a web connection. The right to search a laptop for information, then, is equivalent to the right to tap any and all international connections, without a warrant or probable cause. (More precisely, one always has a constitutional protection against "unreasonable" search and seizure; the issue is what the definition of "unreasonable" is.)

Sunday, 20 July 2008

Secret Bilderberg Agenda to Microchip Americans Leaked

The Strategy reports:
microchip you in name of fighting terrorism

By Paul Joseph Watson

Sources from inside the 2008 Bilderberg meeting have leaked the details of what elitists were discussing in Chantilly Virginia last week and the talking points were ominous - a plan to microchip Americans under the pretext of fighting terrorist groups which will be identified as blonde haired, blue eyed westerners.

Veteran Bilderberg sleuth Jim Tucker relies on sources who regularly attend Bilderberg as aides and assistants but who are not Bilderberg members themselves. The information they provided this year is bone-chilling for those who have tracked the development of the plan to make the general public consider implanted microchips as a convenience as routine as credit cards.

"Under the heading of resisting terrorism there were points made about how the terrorist organizations are recruiting people who do not look like terrorists - blonde, blue eyed boys - they're searching hard for those types to become the new mad bombers," said Tucker.


Friday, 4 July 2008

Lost or stolen laptops and your privacy

I just saw this story on Slashdot:
Apparently companies are even worse about losing our data than we suspected. From the article:'According to a study of 106 major U.S. airports and 800 business travelers published by the Ponemon Institute and Dell Computer, about 12,000 laptops are lost in airports each week. Only 30 percent of travelers ever recover the lost devices. Nearly half of the travelers say their laptops contain customer data or confidential business information.'