FBI turning to private sector to hack phones, exploit unknown security holes

FBI turning to private sector for 'zeroday' spyware to hack suspects

Thanks to the NSA PRISM revelations we've all lost our innocence about government cyber-spying, but how far down that rabbit-hole has law-enforcement gone? Revelations from the Def Con hacking conference in Las Vegas show that such tactics are old hat for another US anti-crime department: the FBI. For instance, one ex-official said that the bureau's analysts (shown above) can routinely turn on the microphones in laptops and Android devices to record conversations without a person's knowledge. On top of such in-house expertise, a private sector cottage industry has sprung up around cyber surveillance, marketing programs that can also hack handheld devices and PCs. One company even markets "zero day" bugging software that exploits unknown security holes -- meaning crime lords can't just patch their browsers to avoid detection.

[Image credit: Wikimedia Commons]

Filed under: ,

Comments

Source: WSJ

PRISM whistleblower Edward Snowden reveals himself, reasons for leaking surveillance program (updated)

Only days after the initial leaks and explanations by the US government about the National Security Agency's data surveillance program PRISM, Edward Snowden has revealed himself as the whistleblower. He's employed by defense contractor Booz Allen Hamilton and also worked at the NSA as a "technical assistant" for the CIA. In speaking to The Guardian, he explained his reasons for disclosing the intelligence program: he wanted to "to inform the public as to that which is done in their name and that which is done against them," hoping that they'll use the information to debate the issue.

While the NSA's data-mining tool is reportedly known as Boundless Informant, Snowden has been keeping himself bound to a hotel in Hong Kong during this whole drama. Major internet companies have insisted that the government doesn't receive direct access to their servers and President Obama has stated that "nobody is listening to your phone calls, but the issue remains far from black and white. Snowden claims a "massive surveillance machine" is in the making under the radar -- at this point he's now waiting to see what happens next, assured he's made the the decision that feels right to him. Catch the full interview at the source link.

Update: In case there was any doubt that Snowden has ever been employed by Booz Allen Hamilton, the company just released the following statement:

Booz Allen can confirm that Edward Snowden, 29, has been an employee of our firm for less than 3 months, assigned to a team in Hawaii. News reports that this individual has claimed to have leaked classified information are shocking, and if accurate, this action represents a grave violation of the code of conduct and core values of our firm. We will work closely with our clients and authorities in their investigation of this matter.

Filed under:

Comments

Source: The Guardian

France investigates Skype after it doesn’t register as a telecom provider (update: Skype response)

France investigates Skype after it doesn't register as a telecom provider

You can't completely pigeonhole Skype when it serves both as a partial substitute for traditional phone service and an instant messaging service with voice and video on top. Unfortunately, French telecom regulator ARCEP doesn't trade in ambiguities. It's launching an investigation into Skype after the Microsoft-owned division reportedly ignored requests to register itself as a telecom provider in the country. The authority is concerned that Skype is offering phone service without following local laws, including requirements to offer emergency calls and avenues for legal wiretaps. We've reached out to Skype for its side of the story, although there's no certainty that ARCEP will have to take action, regardless -- Skype has long disclaimed that it's not a full phone replacement and won't work for true emergencies. If France asks for compliance, however, Skype may have to either solve a seemingly unsolvable problem or face withdrawing at least some of its services. We wouldn't count on always having VoIP in Versailles.

Update: A Skype spokesperson answered back, and the company's view is clear: it doesn't believe that its service fits the definition of a communication provider under French law and thus doesn't have to be registered. Skype adds that it's been talking with ARCEP and plans to keep that up in a "constructive" fashion, although there clearly hasn't been much progress on that front. Read the full response after the break.

[Image credit: Alexandre Vialle, Flickr]

Filed under: ,

Comments

Via: New York Times

Source: ARCEP (translated)

Indian official claims BlackBerry eavesdropping standoff is ‘heading towards a resolution’

Indian official claims BlackBerry eavesdropping standoff is 'heading towards a resolution'

Oh, bureaucracies, the fun in dealing with them is that you're told exactly what they want you to know -- or at least, believe. That's the name of the game in India, where -- as you're surely aware -- the government has been at odds with RIM for years over its insistence that the Waterloo firm provide the means to monitor encrypted emails and BBM messages. In a revelation that may relate to those BlackBerry servers in Mumbai, R. Chandrasekhar of India's Department of Information Technology has asserted, "The issue is heading towards a resolution." While it's difficult to know whether monitoring is already in place, Chandrasekhar added that, "Law enforcement agencies will get what they need." Another unknown is whether RIM played a role in these developments. For its part, the company claims, "RIM maintains a consistent global standard for lawful access requirements that does not include special deals for specific countries." So, if everything is now clear as mud for you, just remember: that's how those in charge like it.

Filed under: ,

Indian official claims BlackBerry eavesdropping standoff is 'heading towards a resolution' originally appeared on Engadget on Wed, 08 Aug 2012 21:17:00 EDT. Please see our terms for use of feeds.

Permalink Phys.Org  |  sourceWSJ  | Email this | Comments

Federal appeals court says warrantless wiretapping is legal

Federal appeals court says warrantless wiretapping is legal

A federal appeals court has ruled today that the US government can tap into Americans' communications without worrying over frivolous things like "being sued" by its people. In what most sane civilians will probably see as a depressing loss of protection, a three-judge panel of the 9th US Circuit Court of Appeals ruled that citizens can sue the United States for damages stemming from the use of information collected via wiretap, but not for the collection of information itself. In typical pass-the-buck fashion, Wired reports that Judge Michael Daly Hawkins and Judge Harry Pregerson added the following: "Although such a structure may seem anomalous and even unfair, the policy judgment is one for Congress, not the courts." Alrighty. For those unaware, the back and forth surrounding this issue extends back to Congress' authorization of the Bush spy program in 2008, and more specifically, a pair of US lawyers and the now-defunct al-Haramain Islamic Foundation -- a group that was granted over $2.5 million combined in legal fees after proving that they were spied on sans warrants. The full report can be found in the PDF below.

Filed under:

Federal appeals court says warrantless wiretapping is legal originally appeared on Engadget on Tue, 07 Aug 2012 16:47:00 EDT. Please see our terms for use of feeds.

Permalink Wired  |  sourceUS Court of Appeals [PDF]  | Email this | Comments

Carriers face big surge in cellphone surveillance requests, raise a few alarm bells

Marcelo phone call wiretap

Color us unsurprised that US law enforcers would push hard for surveillance access. Congressman Ed Markey has published a new report on requests to cellular carriers that shows a recent rush of demand for information, including last year. The rates vary sharply, but T-Mobile has seen a yearly hike of 12 to 16 percent, while Verizon has seen its own grown 15 percent -- and Sprint took nearly twice as many surveillance requests as AT&T or Verizon in 2011, despite its smaller size. Markey's concern is that police and other investigators are casting too wide a net and sweeping up innocent customers through widescale requests, potentially violating their privacy in the process. Whether or not cell tower dumps and other broad fishing attempts are problems, carriers have been quick to point out that they have huge teams in place to deal with police requests and cling steadfastly to requiring a warrant when the law demands it. Needless to say, there are a few groups that strongly disagree with that last claim.

Filed under: , ,

Carriers face big surge in cellphone surveillance requests, raise a few alarm bells originally appeared on Engadget on Mon, 09 Jul 2012 20:27:00 EDT. Please see our terms for use of feeds.

Permalink Reuters  |  sourceCongressman Ed Markey  | Email this | Comments

FBI reportedly pressing for backdoor access to Facebook, Google

Image

Investigators at the FBI supposedly aren't happy that social networks like Facebook or Google+ don't have the same kind of facility for wiretaps that phones have had for decades. If claimed industry contacts for CNET are right, senior staff at the bureau have floated a proposed amendment to the 1994-era Communications Assistance for Law Enforcement Act (CALEA) that would require that communication-based websites with large user bases include a backdoor for federal agents to snoop on suspects. It would still include the same requirement for a court order as for phone calls, even if US carriers currently enjoy immunity for cooperating with any warrantless wiretapping. As might be expected, technology firms and civil liberties advocates like the Electronic Frontier Foundation object to deepening CALEA's reach any further, and Apple is thought to be preemptively lobbying against another definition of the law that might require a government back channel for audiovisual chat services like FaceTime or Skype. The FBI didn't explicitly confirm the proposal when asked, but it did say it was worried it might be "going dark" and couldn't enforce wiretaps.

[Image credit: David Drexler, Flickr]

FBI reportedly pressing for backdoor access to Facebook, Google originally appeared on Engadget on Sat, 05 May 2012 14:18:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceCNET  | Email this | Comments