Sunday, 5 October 2008
Skype Messages Monitored In China
"Human-rights activists have discovered a huge surveillance system in China that monitors and archives Internet text conversations sent by customers of Tom-Skype, a joint venture between a Chinese wireless operator and eBay. Researchers say the system monitors a list of politically charged words that includes words related to the religious group Falun Gong, Taiwan independence, the Chinese Communist Party and also words like democracy, earthquake and milk powder. The encrypted list of words inside the Tom-Skype software blocks the transmission of these words and records personal information about the customers who send the messages. Researchers say their discovery contradicts a public statement made by Skype executives in 2006 that 'full end-to-end security is preserved and there is no compromise of people's privacy.' The Chinese government is not alone in its Internet surveillance efforts. In 2005, The New York Times reported that the National Security Agency was monitoring large volumes of telephone and Internet communications flowing into and out of the United States as part of an eavesdropping program that President Bush approved after the Sept. 11 attacks. 'This is the worst nightmares of the conspiracy theorists around surveillance coming true,' says Ronald J. Deibert, an associate professor of political science at the University of Toronto. 'It's "X-Files" without the aliens.'"
And Skype features a encrypted messaging system? And shows you a little lock at the bottom of each chat window!
Tuesday, 9 September 2008
Your mobile phone: the spy who you loved
Quote:
[...] private companies now sell off-the-shelf data-mining solutions to government spies interested in analyzing mobile-phone calling records and real-time location information. These companies include ThorpeGlen, VASTech, Kommlabs, and Aqsacom--all of which sell "passive probing" data-mining services to governments around the world.According to the screenshot on the web page, you can with this software obtain the following information about any user:
- physical location, tracking a person's move
- email addresses he uses
- call fingerprinting: you can follow the user even if he uses multiple SIMs and handsets
Friday, 5 September 2008
UK ISPs To Hand Over Thousands of File Sharers' Data
"US game developer Topware Interactive, the people behind the now infamous Dream Pinball affair, are about to turn up the heat. Operating through London lawyers Davenport Lyons, they have managed to convince the High Court to send out an order demanding that ISPs in the UK start to hand over the details of several thousand alleged pirates... BT, one of the UK's largest ISPs..., confirmed it had been ordered to hand over details of alleged copyright infringing file-sharers... Virgin Media was a little more slippery in its response but reading between the lines it seems obvious they are involved too."
Wednesday, 27 August 2008
The Internet's Biggest Security Hole Revealed
At DEFCON, Tony Kapela and Alex Pilosov demonstrated a drastic weakness in the Internet's infrastructure that had long been rumored, but wasn't believed practical. They showed how to hijack BGP (the border gateway protocol) in order to eavesdrop on Net traffic in a way that wouldn't be simple to detect. Quoting: "'It's at least as big an issue as the DNS issue, if not bigger,' said Peiter 'Mudge' Zatko, noted computer security expert and former member of the L0pht hacking group, who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. 'I went around screaming my head about this about ten or twelve years ago... We described this to intelligence agencies and to the National Security Council, in detail.' The man-in-the-middle attack exploits BGP to fool routers into re-directing data to an eavesdropper's network."Note that the US Government knows since 1998 how to eavesdrop without being noticed.
Thursday, 14 August 2008
UK Gov't Proposes Massive Internet Snooping, Data Storage
The Government will store "a billion incidents of data exchange a day" as details of every text, email and browsing session in the UK are recorded under new proposals published yesterday.
The information will be made available to police forces in order to crack down on serious crime, but will also be accessible by local councils, health authorities and even Ofsted and the Post Office.
Tuesday, 5 August 2008
Information is "imported" can now be intercepted without a warrant
FISA and Border Searches of Laptops
10 July 2008
There's been a lot of attention paid recently to the issue of laptop searches at borders, including a congressional hearing and a New York Times editorial. I've seen articles with advice on how to protect your data under such circumstances; generally speaking, the advice boils down to "delete what you can, encrypt the rest, hope that Customs officials don't compel production of your key, and securely clean up the deleted files". If you need sensitive information while you're traveling, the usual suggestion is to download it over a secure connection, per the EFF:
Another option is to bring a clean laptop and get the information you need over the internet once you arrive at your destination, send your work product back, and then delete the data before returning to the United States. Historically, the Foreign Intelligence Surveillance Act (FISA) generally prohibited warrantless interception of this information exchange. However, the Protect America Act amended FISA so that surveillance of people reasonably believed to be located outside the United States no longer requires a warrant. Your email or telnet session can now be intercepted without a warrant. If all you are concerned about is keeping border agents from rummaging through your revealing vacation photos, you may not care. If you are dealing with trade secrets or confidential client data, an encrypted VPN is a better solution.
But is it?
When a laptop is searched, the customs agents are not looking for drugs embedded in the batteries or for whether or not the connectors have too much gold on the contacts. Rather, they're looking for information.
In that sense, it would seem to make little difference if the information is "imported" into the US via a physical laptop or via a VPN, or for that matter by a web connection. The right to search a laptop for information, then, is equivalent to the right to tap any and all international connections, without a warrant or probable cause. (More precisely, one always has a constitutional protection against "unreasonable" search and seizure; the issue is what the definition of "unreasonable" is.)
Sunday, 20 July 2008
Secret Bilderberg Agenda to Microchip Americans Leaked
microchip you in name of fighting terrorismBy Paul Joseph Watson
Sources from inside the 2008 Bilderberg meeting have leaked the details of what elitists were discussing in Chantilly Virginia last week and the talking points were ominous - a plan to microchip Americans under the pretext of fighting terrorist groups which will be identified as blonde haired, blue eyed westerners.
Veteran Bilderberg sleuth Jim Tucker relies on sources who regularly attend Bilderberg as aides and assistants but who are not Bilderberg members themselves. The information they provided this year is bone-chilling for those who have tracked the development of the plan to make the general public consider implanted microchips as a convenience as routine as credit cards.
"Under the heading of resisting terrorism there were points made about how the terrorist organizations are recruiting people who do not look like terrorists - blonde, blue eyed boys - they're searching hard for those types to become the new mad bombers," said Tucker.