Drop Down MenusCSS Drop Down MenuPure CSS Dropdown Menu
Alternative Text Alternative Text Alternative Text Alternative Text
Survivor of US Drone Attack:
Obama Belongs on List of World's Tyrants

Poisoning Black Cities: Corporate Campaign to Ethnically Cleanse US Cities Massive Marches in Poland
Against Authoritarian Threat of Far-Right
Ethiopia’s Invisible Crisis: Land Rights Activists Kidnapped and Tortured

Global Perspectives Now Global Perspectives Now
Showing posts with label EFF. Show all posts
Showing posts with label EFF. Show all posts

Who Spies The Most On Americans — NSA, CIA?: No the DEA — Judge Orders Release of Info on Two Decades of Phone Surveillance

Illustration by the Electronic Frontier Foundation.
Illustration by the Electronic Frontier Foundation.
By Mark Rumold
A federal judge in Los Angeles has given our clients, Human Rights Watch, the go-ahead to take discovery from the government in our ongoing lawsuit challenging the constitutionality of the DEA’s bulk surveillance program. Friday's decision is rare, and it's a decisive victory—both for HRW and for the general public. EFF is not aware of any other case where discovery has been allowed into a government mass surveillance program. And the order forces the government to answer questions, under oath, about the steps it took to ensure that all illegally collected records have been fully purged from all government systems.

The case stems from the DEA’s disclosure in January of this year that it had secretly collected Americans’ international call records in bulk for over two decades. News reports described the program as massive—sweeping in billions of records of Americans’ calls to more than 100 countries around the globe, including Canada, Mexico, India, and Italy. The DEA relied only on an obscure administrative subpoena statute to obtain the records in bulk. That means, unlike the NSA’s bulk surveillance program, there was no judicial involvement whatsoever. Making matters worse, reports confirm that multiple agencies searched the illegally collected records for all kinds of cases—from terrorism, to drug trafficking, to export violations.

In April, immediately following a lengthy report in USA Today, EFF filed suit on behalf of Human Rights Watch against the DEA, DHS, FBI, and various unnamed agencies. The lawsuit challenges the constitutionality of the program, and seeks to ensure that the program is permanently stopped rather than merely suspended as claimed by DEA. The suit further asks the court to ensure that all illegally collected records are accounted for and destroyed.

The government, instead, asked the judge to dismiss the case. DEA had previously said that it had “suspended” collecting records in bulk in September 2013. Now, it submitted an additional four-paragraph declaration from a DEA agent that said the DEA’s illegally collected records had been “quarantined” and “purged.” That, the government argued, required the court to dismiss the case. The government was trying to sweep two decades worth of unconstitutional activity under the rug with a single, four-paragraph declaration.

We pushed back. We’ve seen enough government double-speak concerning surveillance programs to know that there was more to the story. We argued that the government’s four-paragraph, summary declaration wasn’t enough to establish that all of the billions of records it collected, over a twenty-year span, had been accounted for and purged. Instead, we asked the court to allow HRW to take discovery—basically, a process by which one party to a lawsuit can compel the other side to provide information—from the government about the surveillance program.

Although the court narrowed the scope of the discovery HRW can take, the decision is still a victory. It will provide some much needed insight into the government’s surveillance program and whether or not the government continues to retain and use those illegally collected records. And we'll keep fighting for more information about the program and to ensure that the program is stopped, once and for all.


Reprinted with permission from  Electronic Frontier Foundation

Was the FCC Pushed in the Right Direction by Grassroots Power?: FCC Considers Forcing Net Neutrality Via New Regulations

FCC chairman likely to support strict net neutrality protections after backing off from pro-industry initiatives


After months of pressure from grassroots groups, FCC chairman Tom Wheeler is likely to introduce strong net neutrality protections. (Photo: ALA Washington Office/ flickr/cc)
After months of pressure from grassroots groups, FCC chairman Tom Wheeler is
likely to introduce strong net neutrality protections. (Photo: ALA Washington Office/
flickr/cc)
By Nadia Prupis
Following a months-long campaign by consumer advocacy groups that pushed for strict protection of the internet, Federal Communications Commissioner Tom Wheeler appears to be ready to introduce some of the strongest regulations possible on Thursday ahead of the FCC's final net neutrality vote on February 26, according to reports.

Those regulations include redefining broadband as a public utility under Title II of the Communications Act, a policy change that has been touted by internet watchdog groups as one of the most important net neutrality protections available.

Once a lobbyist for the cable and telecommunications industries, Wheeler initially supported lax regulations that critics said would open the door to controversial paid-prioritization policies, known as "fast lanes," allowing internet service providers to charge higher fees for speedier website loading times.

According to reporting by Politico on Monday, "interviews with FCC officials, industry executives and representatives of public interest groups reveal the origins of his dramatic pivot on this issue: an intense and relatively brief grass-roots lobbying campaign that targeted two people — him and President Barack Obama."

Pressure from digital rights groups like the Electronic Frontier Foundation and Free Press, which galvanized support from consumers and progressive media figures, saw Wheeler steadily backpedaling on his initiatives last year. His shift appeared near-complete after President Barack Obama spoke out in favor of strict net neutrality regulations on November 10.

Wheeler proposed in April new rules that would allow ISPs to create fast lane deals with internet companies as long as they were "commercially reasonable."

In response, a coalition of internet watchdogs and consumer advocacy groups launched a months-long series of campaigns against the chairman's proposals, while protesters camped out in front of FCC headquarters. On June 1, Last Week Tonight host John Oliver ridiculed Wheeler and his proposed rules in a segment that quickly went viral, sending hundreds of thousands of consumers to the FCC website to comment in favor of stronger net neutrality regulations. Within months, four million emails and comments had come in, breaking FCC records.

Wheeler then moved towards a hybrid proposal that would impose Title II rules on parts of the internet, but not all of it. That, too, was met with disapproval by watchdogs and tech companies alike.

Meanwhile, Obama had also been under pressure from internet advocacy groups, who urged him to speak out in favor of stricter regulations. On November 10, he did just that, issuing a statement that called for using a Title II reclassification to safeguard the internet, "one of the most significant democratizing influences the world has ever known."

Earlier this month, Wheeler indicated support for reclassification of the internet as a public utility under Title II, bringing praise from Free Press president and CEO Craig Aaron who said, "Chairman Wheeler appears to have heard the demands of the millions of Internet users who have called for real net neutrality protections."


Reprinted with permission from Common Dreams.


Police State Rising: Police Using Controversial Patriot Act Authority for 'Everyday' Cases — Says Civil Liberties Group

Created under the guise of fighting terrorism, 'Sneak and Peek' now being used to spy on drug suspects, immigrants, rights group finds

Law enforcement has been using provisions of the Patriot Act to conduct routine investigations, not fight terrorism, the EFF found. (Photo: Office of Public Affairs/flickr/cc)
Law enforcement has been using provisions of the Patriot Act to conduct routine investigations, not fight terrorism, the EFF found. (Photo: Office of Public Affairs/flickr/cc)

By Nadia Prupis
A contentious surveillance provision of the Patriot Act, which allows law enforcement to conduct searches while delaying informing the suspect, is broadly used, but almost never in terrorism cases—despite Justice Department officials arguments to the contrary, according to an analysis by the Electronic Frontier Foundation (EFF).

"Yet again, terrorism concerns appear to be trampling our civil liberties," writes EFF’s Mark Jaycox.

The rights group analyzed federal reports from 2011, 2012, and 2013, released after an unexplained three-year delay, on warrants that were issued under Section 213, known colloquially as "Sneak and Peek."

Out of more than 11,000 requests for those delayed-notification searches in 2013, a grand total of 51 were used for terrorism cases, EFF found. Almost all of the other Sneak and Peek warrants went to drug investigations.


Notifications of searches were routinely delayed by at least a month, and often by several. The average (pdf) delay nationwide in 2013 was 64 days.

Fraud, theft, and immigration investigations all garnered more Sneak and Peek warrants than terrorism cases.

"Exactly what privacy advocates argued in 2001 is happening: sneak and peak warrants are not just being used in exceptional circumstances—which was their original intent—but as an everyday investigative tool," Jaycox writes.

Jaycox continues:
The 2013 report confirms the incredibly low numbers. Out of 11,129 reports only 51, or .5%, of requests were used for terrorism. The majority of requests were overwhelmingly for narcotics cases, which tapped out at 9,401 requests.
In addition to their egregious use, the number of warrants issued has skyrocketed, with requests nearly tripling in just three years. By contrast, police made 47 sneak-and-peek searches nationwide from September 2001 to April 2003.

Section 213 was enacted over protests by civil rights groups who noted that the FBI already had the power to conduct delayed-notification searches in terrorism investigations through the Foreign Intelligence Surveillance Act (FISA).

"Section 213 authorizes sneak-and-peek searches in run-of-the-mill criminal investigations, not just in foreign-intelligence investigations involving terrorists," the ACLU warned in 2003. Likewise, even as the Supreme Court ruled in Wilson v. Arkansas and Richards v. Wisconsin that the Fourth Amendment required police to "knock and announce" their entry into property when conducting a search, the decision allowed for police to skirt that rule in situations where evidence or their safety was under threat.

"Section 213 codified this practice into statute, taking delayed notice from a relatively rare occurrence into standard operating law enforcement procedure," Jaycox writes.

As Radley Balko notes, "this was all immediately after the terrorist attacks of Sept. 11, 2001, and there was little patience for civil libertarians. The massive Patriot Act of course passed overwhelmingly…. sneak-and-peek is increasingly ubiquitous while the justification for granting the government this power in the first place—terrorism—is not only irrelevant to the tactic’s increasing pervasiveness, it gets more irrelevant every year."



Reprinted with permission from Common Dreams.


Stingray, the Cell Phone Spying Device: US Government 'Disappears' Stingray Spying Records

How the 'Stingray' Cellphone-Trackig Device Works
(Click to see full-sized image)

By Peter Van Buren

We’ve heard variations on the phrase “If you have nothing to hide, you have nothing to fear” from the government for quite some time. It appears this may be true, at least if you are the government.

In the case of Stingray, a cell phone spying device used against Americans, the government does have something to hide and they fear the release of more information. Meanwhile, the Fourth Amendment weeps quietly in the corner.

Stingray

Cell phone technology is very useful to the cops to locate you and to track your movements. In addition to whatever as-yet undisclosed things the NSA may be up to on its own, the FBI acknowledges a device called Stingray to create electronic, “fake,” cell phone towers and track people via their phones in the U.S. without their knowledge. The tech does not require a phone’s GPS. This technology was first known to have been deployed against America’s enemies in Iraq, and it has come home to be used against a new enemy– you.

Stingray, also known as an International Mobile Subscriber Identity, or IMSI, catcher, works like this. The cell network is designed around triangulation and whenever possible your phone is in constant contact with at least three towers. As you move, one tower “hands off” your signal to the next one in your line of motion. Stingray electronically inserts itself into this process as if it was a (fake; “spoofed”) cell tower itself to grab location data before passing your legitimate signal back to the real cell network. The handoffs in and out of Stingray are invisible to you. Stingrays also “inadvertently” scoop up the cell phone data of anyone within several kilometers of the designated target person. Though typically used to collect location metadata, Stingray can also capture conversations, texts and mobile web use if needed.

Stingray offers some unique advantages to a national security state: it bypasses the phone company entirely, which is handy if laws change and phone companies no longer must cooperate with the government, or simply if the cops don’t want the phone company or anyone else to know they’re snooping.

This has led the Electronic Frontier Foundation (EFF) to warn

“A Stingray— which could potentially be beamed into all the houses in one neighborhood looking for a particular signal— is the digital version of the pre-Revolutionary war practice of British soldiers going door-to-door, searching Americans’ homes without rationale or suspicion, let alone judicial approval… [Stingray is ] the biggest technological threat to cell phone privacy.”

Trying to Learn about Stingray

Learning how Stingray works is difficult.

The Electronic Privacy Information Center filed a FOIA request for more information on Stingrays, but the FBI is sitting on 25,000 pages of documents explaining the device that it won’t release.

The device itself is made by the Harris Corporation. Harris makes electronics for commercial use and is a significant defense contractor. For Stingray, available only to law enforcement agencies, Harris requires a non-disclosure agreement that police departments around the country have been signing for years explicitly prohibiting them from telling anyone, including other government bodies, about their use of the equipment “without the prior written consent of Harris.”

A price list of Harris’ spying technology, along with limited technical details, was leaked online, but that’s about all we know.

Though the non-disclosure agreement includes an exception for “judicially mandated disclosures,” there are no mechanisms for judges even to learn that the equipment was used at all, thus cutting off any possibility they could know enough demand disclosure. In at least one case in Florida, a police department revealed that it had decided not to seek a warrant to use the technology explicitly to avoid telling a judge about the equipment. It subsequently kept the information hidden from the defendant as well. The agreement with Harris goes further to require law enforcement to notify Harris any time journalists or anyone else files a public records request to obtain information about Stingray and also demands the police department assist Harris in deciding what information to release.

Something to Hide

An evolving situation in Florida shows how hard the government is working to keep the details of its Stingray spying on Americans secret.

The ACLU originally sought Stingray records in Sarasota, Florida after they learned a detective there obtained permission to use the device simply by filing an application with a local court, instead of obtaining a probable-cause warrant as once was required by the Fourth Amendment of the Constitution. It became clear that the Sarasota police had additionally used Stingray at least 200 times since 2010 without even the minimal step of even notifying a judge. In line with the non-disclosure agreement, very rarely were arrested persons advised that Stingray data was used to locate and prosecute them.

The ACLU, which earlier in 2014 filed a Florida state-level FOIA-type request with the Sarasota police department for information detailing its use of Stingray, had an appointment with the local cops to review documents. The local police agreed to the review. However, the June 2014 morning of the ACLU’s appointment, U.S. Marshals arrived ahead of them and physically took possession of the files. The Marshals barred the Sarasota police from releasing them. The rationale used by the federal government was that having quickly deputized a Sarasota cop, all Sarasota records became federal property.

“This is consistent with what we’ve seen around the country with federal agencies trying to meddle with public requests for Stingray information,” an ACLU spokesperson said, noting that federal authorities have in other cases invoked the Homeland Security Act to prevent the release of such records. “The feds are working very hard to block any release of this information to the public.”

The Cops are Lying in Court about Stingray

Yeah, it gets worse. According to emails uncovered by the ACLU, Florida law enforcement had concealed the use of Stingray in court documents. Specifically, one e-mail from Sarasota police to North Port police states, “In reports or depositions we simply refer to the assistance as ‘received information from a confidential source regarding the location of the suspect.’ To date this has not been challenged.” By hiding the fact from the court (and the defendant) that information used in the prosecution came from Stingray, the police effectively blocked any possibility that that information could be challenged in court. This appears in direct confrontation with the Sixth Amendment’s right to confront witnesses.

Russell Covey, a law professor at Georgia State University, stated


“The failure of law enforcement officials to disclose to courts the actual source of their information and to pretend that it came from a ‘confidential source,’ is deceptive and possibly fraudulent. Affirmatively misleading the courts about the source of evidence in sworn warrant applications would clearly constitute a constitutional violation.”

A Court Says the Feds Can Hide the Records

Following the feds’ seizure of the Stingray records, the ACLU filed an emergency motion with a Florida court that would require Sarasota to make its Stingray records available. However, in a decision issued June 17, 2014, a Florida state circuit court judge found that his court lacked jurisdiction over a federal agency, allowing the transfer of the Stingray documents to the feds and de facto blocking their release.

The ACLU plans further appeals. Unless and until they succeed, details of another way of spying on Americans will remain secret. The government does indeed have something to hide.

Peter Van Buren writes about current events at blog. His book,Ghosts of Tom Joad: A Story of the #99Percent, is available now from from Amazon.



Reprinted with permission from Center for Research in Globalization.

Cops Must Swear Silence to Access Vehicle Tracking System: Corporations Insist License Plate Tracking Stay Hidden Media and Public

Vehicle tracking software screenshot
(click to see full-size image)
Image: Vigilant Solutions


By
It’s no secret that police departments around the country are deploying automated license plate readers to build massive databases to identify the location of vehicles. But one company behind this Orwellian tracking system is determined to stay out of the news.

How determined? Vigilant Solutions, founded in 2009, claims to have the nation’s largest repository of license-plate images with nearly 2 billion records stored in its National Vehicle Location Service (NVLS). Despite the enormous implications of the database for the public, any law enforcement agency that signs up for the service is sworn to a vow of silence by the company’s terms of service.
Vigilant is clear about the reason for the secrecy: it’s to prevent customers from “cooperating” with media and calling attention to its database.

That database is used by law enforcement and others to track stolen cars or vehicles used in crimes, as well as to locate illegal immigrants, kidnapping victims and others — though the vast majority of license plates stored belong to ordinary drivers who aren’t suspected of a crime.

The agreement law enforcement signs, which was uncovered by the Electronic Frontier Foundation, reads in part:
You shall not create, publish, distribute, or permit any written, electronically transmitted or other form of publicity material that makes reference to LEARN or this Agreement without first submitting the material to LEARN-NVLS and receiving written consent from LEARN-NVLS. This prohibition is specifically intended to prohibit users from cooperating with any media outlet to bring attention to LEARN or LEARN-NVLS. Breach this provision may result in LEARN-NVLS immediately termination of this Agreement upon notice to you [sic].1

LEARN stands for Law Enforcement Archival and Reporting Network and is Vigilant’s online portal where license plate data and images are aggregated and analyzed for law enforcement to access.

“LEARN provides agencies with an easy way to manage users and vehicle hotlists, query historical license plate reader (LPR) data and used [sic] advanced analytics for enhanced investigations,” the company’s web site says.
Vigilant’s prohibition against talking about its system recalls a similar, even more restrictive prohibition, by the Harris Corporation, whose non-disclosure agreement with law enforcement agencies prohibits them from disclosing to the media or even other government bodies their use of a cell-phone spy tool that Harris makes, known as a stingray.

Read More

Parody Twitter Account?: Police Raided A House For Mocking Peoria, Illinois Mayor

Twitter addiction: Illustration by Carrot Creative.
Illustration by Carrot Creative.
By Lauren C. Williams
Police raided a home last week in Peoria, IL, over a fake Twitter account that mocked the city’s mayor.

Jon Daniel, 28, and his housemates were accused of impersonating Mayor Jim Ardis via the parody Twitter account, @peoriamayor. The seldom-used account, which used the mayor’s likeness and email, had a few dozen followers with just as many tweets, many referencing sex and drugs. Twitter shut down the account, but Ardis still had police descend on Daniel’s house with a broad warrant to search for drugs and paraphernalia along with any electronic devices that could have been used to operate the account. No one was charged with “impersonating a public official” — the sole basis for the raid — but police seized computers and arrested one roommate for marijuana possession.

The raid sparked national outrage for abusing police and government power for what was clearly a joke. Ardis defended his actions on Tuesday, saying, “As a person, I felt a victim of sexual doggerel and filth. It was filth. It was absolute filth.”

Yet in the Peoria case, “there was no underlying crime — parody is protected by free speech under the First Amendment,” David Greene, senior staff attorney for the Electronic Frontier Foundation in San Francisco told ThinkProgress. The problem arises, however, when police think using social media itself is the crime, Greene said.


Read More

The Wild West of Surveillance Explained: Selling Your Secrets, Building Backdoors, Bounty Hunters, Harvesting Your Data - Which Way Out?

"Spy Tech"
"Spy Tech" (Photo by Peter Terrone)
Here we have an anatomy of a surveillance world that grows more, not less, powerful and full of itself with every passing moment and technological advance, a national security world whose global ambitions know no bounds.


By Pratap Chatterjee and Tom Engelhardt
The question Senator Ron Wyden asked on March 12 of last year was straightforward enough and no surprise for Director of National Intelligence James Clapper. He had been given it a day in advance of his testimony before the Senate Intelligence Committee and after he was done, Senator Wyden and his staff offered him a chance to “amend” his answer if he wished. Did the National Security Agency, Wyden wanted to know, gather “any type of data at all on millions or hundreds of millions of Americans”? Being on that committee and privy to a certain amount of secret intelligence information, Wyden already knew the correct answer to the question. Clapper, with a day to prepare, nonetheless answered, “No, sir. Not wittingly. There are cases where they could inadvertently perhaps collect, but not wittingly.”

That was a bald-faced lie, though Clapper would later term it the “least untruthful” thing he felt he could say. As we now know, the NSA was, among many other things, gathering the phone “data” of every American and storing it for future use. In other words, after some forethought, the director perjured himself.

Mind you, Clapper isn’t exactly shy about charging other people with implicit crimes. In recent testimony before Congress, he demanded that whistleblower and former NSA contractor Edward Snowden “and his accomplices” return all agency documents. It was a stunning use of a term whose only meaning is criminal and clearly referred to the journalists - Glenn Greenwald, filmmaker Laura Poitras, and reporters from the Guardian, the New York Times, and the Washington Post, among other papers - who have been examining and writing about the Snowden documents.

It caught something of the chutzpah of the top officials who run Washington’s national security state - and little wonder that they feel emboldened and demanding. After all, not only is Clapper not going to be charged with perjury, but he has retained his post without a blink. He has kept the “support” of President Obama, who recently told CNN’s Jake Tapper (in what passes these days for a rebuke of our surveiller-in-chief), “Jim Clapper himself would acknowledge, and has acknowledged, that he should have been more careful about how he responded.” More careful indeed!

I've long argued that while we, the citizens of the US, remain in legal America, the US national security state exists in "post-legal America" because no illegal act from warrantless surveillance to torture committed in its service will ever be prosecuted. So it's no surprise that Clapper won’t even be forced to resign for lying to Congress. He's free as a bird and remains powerful indeed. Tell that to some of our whistleblowers.

In his latest post, TomDispatch regular Pratap Chatterjee offers an anatomy of a surveillance world that grows more, not less, powerful and full of itself with every passing moment and technological advance, a national security world whose global ambitions know no bounds. Tom Engelhardt

Selling your secrets
By Pratap Chatterjee
Imagine that you could wander unseen through a city, sneaking into houses and offices of your choosing at any time, day or night. Imagine that, once inside, you could observe everything happening, unnoticed by others - from the combinations used to secure bank safes to the clandestine rendezvous of lovers. Imagine also that you have the ability to silently record everybody’s actions, whether they are at work or play without leaving a trace. Such omniscience could, of course, make you rich, but perhaps more important, it could make you very powerful.

That scenario out of some futuristic sci-fi novel is, in fact, almost reality right now. After all, globalization and the internet have connected all our lives in a single, seamless virtual city where everything is accessible at the tap of a finger. We store our money in online vaults; we conduct most of our conversations and often get from place to place with the help of our mobile devices. Almost everything that we do in the digital realm is recorded and lives on forever in a computer memory that, with the right software and the correct passwords, can be accessed by others, whether you want them to or not.

Now - one more moment of imagining - what if every one of your transactions in that world was infiltrated? What if the government had paid developers to put trapdoors and secret passages into the structures that are being built in this new digital world to connect all of us all the time? What if they had locksmiths on call to help create master keys for all the rooms? And what if they could pay bounty hunters to stalk us and build profiles of our lives and secrets to use against us?

Well, check your imagination at the door, because this is indeed the brave new dystopian world that the US government is building, according to the latest revelations from the treasure trove of documents released by National Security Agency whistleblower Edward Snowden.

Over the last eight months, journalists have dug deep into these documents to reveal that the world of NSA mass surveillance involves close partnerships with a series of companies most of us have never heard of that design or probe the software we all take for granted to help keep our digital lives humming along.

There are three broad ways that these software companies collaborate with the state: a National Security Agency program called “Bullrun” through which that agency is alleged to pay off developers like RSA, a software security firm, to build “backdoors” into our computers; the use of “bounty hunters” like Endgame and Vupen that find exploitable flaws in existing software like Microsoft Office and our smartphones; and finally the use of data brokers like Millennial Media to harvest personal data on everybody on the internet, especially when they go shopping or play games like Angry Birds, Farmville, or Call of Duty.

Of course, that’s just a start when it comes to enumerating the ways the government is trying to watch us all, as I explained in a previous TomDispatch piece, “Big Bro is Watching You.” For example, the FBI uses hackers to break into individual computers and turn on computer cameras and microphones, while the NSA collects bulk cell phone records and tries to harvest all the data traveling over fiber-optic cables. In December 2013, computer researcher and hacker Jacob Appelbaum revealed that the NSA has also built hardware with names like Bulldozer, Cottonmouth, Firewalk, Howlermonkey, and Godsurge that can be inserted into computers to transmit data to US spooks even when they are not connected to the internet.

“Today, [the NSA is] conducting instant, total invasion of privacy with limited effort,” Paul Kocher, the chief scientist of Cryptography Research, Inc. which designs security systems, told the New York Times. “This is the golden age of spying.”

Building backdoors
Back in the 1990s, the Clinton administration promoted a special piece of NSA-designed hardware that it wanted installed in computers and telecommunication devices. Called the Clipper Chip, it was intended to help scramble data to protect it from unauthorized access - but with a twist. It also transmitted a "Law Enforcement Access Field" signal with a key that the government could use if it wanted to access the same data.

Activists and even software companies fought against the Clipper Chip in a series of political skirmishes that are often referred to as the Crypto Wars. One of the most active companies was RSA from California. It even printed posters with a call to “Sink Clipper.” By 1995, the proposal was dead in the water, defeated with the help of such unlikely allies as broadcaster Rush Limbaugh and Senators John Ashcroft and John Kerry.

But the NSA proved more tenacious than its opponents imagined. It never gave up on the idea of embedding secret decryption keys inside computer hardware - a point Snowden has emphasized (with the documents to prove it).

A decade after the Crypto Wars, RSA, now a subsidiary of EMC, a Massachusetts company, had changed sides. According to an investigative report by Joseph Menn of Reuters, it allegedly took $10 million from the National Security Agency in exchange for embedding an NSA-designed mathematical formula called the Dual Elliptic Curve Deterministic Random Bit Generator inside its Bsafe software products as the default encryption method.

The Dual Elliptic Curve has a “flaw” that allows it to be hacked, as even RSA now admits. Unfortunately for the rest of us, Bsafe is built into a number of popular personal computer products and most people would have no way of figuring out how to turn it off.

According to the Snowden documents, the RSA deal was just one of several struck under the NSA’s Bullrun program that has cost taxpayers over $800 million to date and opened every computer and mobile user around the world to the prying eyes of the surveillance state.

“The deeply pernicious nature of this campaign - undermining national standards and sabotaging hardware and software - as well as the amount of overt private sector cooperation are both shocking,” wrote Dan Auerbach and Kurt Opsahl of the Electronic Frontier Foundation, a San Francisco-based activist group that has led the fight against government surveillance. “Back doors fundamentally undermine everybody's security, not just that of bad guys.”


Bounty hunters
For the bargain basement price of $5,000, hackers offered for sale a software flaw in Adobe Acrobat that allows you to take over the computer of any unsuspecting victim who downloads a document from you. At the opposite end of the price range, Endgame Systems of Atlanta, Georgia, offered for sale a package named Maui for $2.5 million that can attack targets all over the world based on flaws discovered in the computer software that they use. For example, some years ago, Endgame offered for sale targets in Russia including an oil refinery in Achinsk, the National Reserve Bank, and the Novovoronezh nuclear power plant. (The list was revealed by Anonymous, the online network of activist hackers.)

While such “products,” known in hacker circles as “zero day exploits,” may sound like sales pitches from the sorts of crooks any government would want to put behind bars, the hackers and companies who make it their job to discover flaws in popular software are, in fact, courted assiduously by spy agencies like the NSA who want to use them in cyberwarfare against potential enemies.

Take Vupen, a French company that offers a regularly updated catalogue of global computer vulnerabilities for an annual subscription of $100,000. If you see something that you like, you pay extra to get the details that would allow you to hack into it. A Vupen brochure released by Wikileaks in 2011 assured potential clients that the company aims “to deliver exclusive exploit codes for undisclosed vulnerabilities” for “covertly attacking and gaining access to remote computer systems.”

At a Google sponsored event in Vancouver in 2012, Vupen hackers demonstrated that they could hijack a computer via Google’s Chrome web browser. But they refused to hand over details to the company, mocking Google publicly. “We wouldn’t share this with Google for even $1 million,” Chaouki Bekrar of Vupen boasted to Forbes magazine. “We don’t want to give them any knowledge that can help them in fixing this exploit or other similar exploits. We want to keep this for our customers.”

In addition to Endgame and Vupen, other players in this field include Exodus Intelligence in Texas, Netragard in Massachussetts, and ReVuln in Malta.

Their best customer? The NSA, which spent at least $25 million in 2013 buying up dozens of such “exploits.” In December, Appelbaum and his colleagues reported in Der Spiegel that agency staff crowed about their ability to penetrate any computer running Windows at the moment that machine sends messages to Microsoft. So, for example, when your computer crashes and helpfully offers to report the problem to the company, clicking yes could open you up for attack.

The federal government is already alleged to have used such exploits (including one in Microsoft Windows) - most famously when the Stuxnet virus was deployed to destroy Iran’s nuclear centrifuges.

“This is the militarization of the Internet,” Appelbaum told the Chaos Computer Congress in Hamburg. “This strategy is undermining the internet in a direct attempt to keep it insecure. We are under a kind of martial law.”

Harvesting your data
Among the Snowden documents was a 20-page 2012 report from the Government Communications Headquarters (GCHQ) - the British equivalent of the NSA - that listed a Baltimore-based ad company, Millennial Media. According to the spy agency, it can provide “intrusive” profiles of users of smartphone applications and games. The New York Times has noted that the company offers data like whether individuals are single, married, divorced, engaged, or “swinger,” as well as their sexual orientation (“straight, gay, bisexuall, and ‘not sure’”).

How does Millennial Media get this data? Simple. It happens to gather data from some of the most popular video game manufacturers in the world. That includes Activision in California which makes Call of Duty, a military war game that has sold over 100 million copies; Rovio of Finland, which has given away 1.7 billion copies of a game called Angry Birds that allows users to fire birds from a catapult at laughing pigs; and Zynga - also from California - which makes Farmville, a farming game with 240 million active monthly users.

In other words, we’re talking about what is undoubtedly a significant percentage of the connected world unknowingly handing over personal data, including their location and search interests, when they download “free” apps after clicking on a licensing agreement that legally allows the manufacturer to capture and resell their personal information. Few bother to read the fine print or think twice about the actual purpose of the agreement.

The apps pay for themselves via a new business model called “real-time bidding” in which advertisers like Target and Walmart send you coupons and special offers for whatever branch of their store is closest to you. They do this by analyzing the personal data sent to them by the “free” apps to discover both where you are and what you might be in the market for.

When, for instance, you walk into a mall, your phone broadcasts your location and within a millisecond a data broker sets up a virtual auction to sell your data to the highest bidder. This rich and detailed data stream allows advertisers to tailor their ads to each individual customer. As a result, based on their personal histories, two people walking hand in hand down a street might get very different advertisements, even if they live in the same house.

This also has immense value to any organization that can match up the data from a device with an actual name and identity - such as the federal government. Indeed, the Guardian has highlighted an NSA document from 2010 in which the agency boasts that it can “collect almost every key detail of a user's life: including home country, current location (through geolocation), age, gender, zip code, marital status… income, ethnicity, sexual orientation, education level, and number of children.”

In denial
It’s increasingly clear that the online world is, for both government surveillance types and corporate sellers, a new Wild West where anything goes. This is especially true when it comes to spying on you and gathering every imaginable version of your “data.”

Software companies, for their part, have denied helping the NSA and reacted with anger to the Snowden disclosures. “Our fans’ trust is the most important thing for us and we take privacy extremely seriously,” commented Mikael Hed, CEO of Rovio Entertainment, in a public statement. “We do not collaborate, collude, or share data with spy agencies anywhere in the world.”

RSA has tried to deny that there are any flaws in its products. "We have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use,” the company said in a statement on its website. “We categorically deny this allegation." (Nonetheless RSA has recently started advising clients to stop using the Dual Elliptical Curve.)

Other vendors like Endgame and Millennial Media have maintained a stoic silence. Vupen is one of the few that boasts about its ability to uncover software vulnerabilities.

And the NSA has issued a Pravda-like statement that neither confirms nor denies the revelations. "The communications of people who are not valid foreign intelligence targets are not of interest to the National Security Agency," an NSA spokeswoman told the Guardian. "Any implication that NSA's foreign intelligence collection is focused on the smartphone or social media communications of everyday Americans is not true.”

The NSA has not, however, denied the existence of its Office of Tailored Access Operations (TAO), which Der Spiegel describes as “a squad of [high-tech] plumbers that can be called in when normal access to a target is blocked.”

The Snowden documents indicate that TAO has a sophisticated set of tools at its disposal - that the NSA calls “Quantum Theory” - made up of backdoors and bugs that allow its software engineers to plant spy software on a target computer. One powerful and hard to detect example of this is TAO’s ability to be notified when a target’s computer visits certain websites like LinkedIn and to redirect it to an NSA server named “Foxacid” where the agency can upload spy software in a fraction of a second.

Which way out of the walled garden?
The simple truth of the matter is that most individuals are easy targets for both the government and corporations. They either pay for software products like Pages and Office from well known manufacturers like Apple and Microsoft or download them for free from game companies like Activision, Rovio, and Zynga for use inside “reputable” mobile devices like Blackberries and iPhones.

These manufacturers jealously guard access to the software that they make available, saying that they need to have quality control. Some go even further with what is known as the “walled garden” approach, only allowing pre-approved programs on their devices. Apple’s iTunes, Amazon’s Kindle, and Nintendo’s Wii are examples of this.

But as the Snowden revelations have helped make clear, such devices and software are vulnerable both to manufacturer’s mistakes, which open exploitable backdoors into their products, and to secret deals with the NSA.

So in a world where, increasingly, nothing is private, nothing is simply yours, what is an internet user to do? As a start, there is an alternative to most major software programs for word processing, spreadsheets, and layout and design - the use of free and open source software like Linux and Open Office, where the underlying code is freely available to be examined for hacks and flaws. (Think of it this way: if the NSA cut a deal with Apple to copy everything on your iPhone, you would never know. If you bought an open-source phone - not an easy thing to do - that sort of thing would be quickly spotted.) You can also use encrypted browsers like Tor and search engines like Duck Duck Go that don’t store your data.

Next, if you own and use a mobile device on a regular basis, you owe it yourself to turn off as many of the location settings and data-sharing options as you can. And last but hardly least, don’t play Farmville, go out and do the real thing. As for Angry Birds and Call of Duty, honestly, instead of shooting pigs and people, it might be time to think about finding better ways to entertain yourself. Pick up a paintbrush, perhaps? Or join an activist group like the Electronic Frontier Foundation and fight back against Big Brother.

This piece, including Tom Engelhardt's introduction, is reposted from TomDispatch.com with that site's permission.




Reprinted with permission from openDemocracy.

Free Expression, Surveillance, and the Fight Against Impunity

Internet Surveillance. (Illustration: Mike Licht)
Internet Surveillance. (Illustration: Mike Licht)
By Danny O'Brien
Journalists, bloggers and others who speak out against the powerful risk terrible repercussions for their work. Around the world, they face physical intimidation, violent attacks, and even murder for speaking out.

When such crimes are committed against those who exercise their right to free speech, the perpetrators all too often go unpunished. Those who are meant to enforce the law turn a blind eye. The oppressors can act with absolute impunity.

Every November 23rd, free speech organizations around the world draw attention to these travesties of justice in a Day To End Impunity. The number of uninvestigated crimes and unsolved murders of journalists makes for depressing reading—as does the slow but inexorable increase in victims who are targeted for their online work. Since 1993, the Committee to Protect Journalists have recorded the deaths of twenty-nine online reporters who were murdered for their work. Seventeen of those crimes went unsolved and unpunished.

New Hi-Tech Police Surveillance: The “StingRay” Cell Phone Spying Device

Stop Big Brother
Stop Big Brother
(Illustration by Charles Fettinger)

Blocked by a Supreme Court decision from using GPS tracking devices without a warrant, federal investigators and other law enforcement agencies are turning to a new, more powerful and more threatening technology in their bid to spy more freely on those they suspect of drug crimes. That’s leading civil libertarians, electronic privacy advocates, and even some federal judges to raise the alarm about a new surveillance technology whose use has yet to be taken up definitively by the federal courts.




By Clarence Walker, Global Research November 16, 2013
The new surveillance technology is the StingRay (also marketed as Triggerfish, IMSI Catcher, Cell-site Simulator or Digital Analyzer), a sophisticated, portable spy device able to track cell phone signals inside vehicles, homes and insulated buildings. StingRay trackers act as fake cell towers, allowing police investigators to pinpoint location of a targeted wireless mobile by sucking up phone data such as text messages, emails and cell-site information.

Cellphones at a concert
Photo: Josué Goge
When a suspect makes a phone call, the StingRay tricks the cell into sending its signal back to the police, thus preventing the signal from traveling back to the suspect’s wireless carrier. But not only does StingRay track the targeted cell phone, it also extracts data off potentially thousands of other cell phone users in the area.

Although manufactured by a Germany and Britain-based firm, the StingRay devices are sold in the US by the Harris Corporation, an international telecommunications equipment company. It gets between $60,000 and $175,000 for each Stingray it sells to US law enforcement agencies.

Stingray: Version 1 and 2
Stingray 1 (top) and 2.
US Patent O
While the US courts are only beginning to grapple with StingRay, the high tech cat-and-mouse game between cops and criminals continues afoot. Foreign hackers reportedly sell an underground IMSI tracker to counter the Stingray to anyone who asks for $1000. And in December 2011, noted German security expert Karsten Nohl released "Catcher Catcher," powerful software that monitors a network's traffic to seek out the StingRay in use.
Originally intended for terrorism investigations, the feds and local law enforcement agencies are now using the James Bond-type surveillance to track cell phones in drug war cases across the nation without a warrant. Federal officials say that is fine — responding to a Freedom of Information Act (FOIA) request filed by the Electronic Freedom Foundation (EFF) and the First Amendment Coalition, the Justice Department argued that no warrant was needed to use StingRay technology.

“If a device is not capturing the contents of a particular dialogue call, the device does not require a warrant, but only a court order under the Pen Register Statute showing the material obtained is relevant to an ongoing investigation,” the department wrote.

The FBI claims that it is adhering to lawful standards in using StingRay. “The bureau advises field officers to work closely with the US Attorney’s Office in their districts to comply with legal requirements,” FBI spokesman Chris Allen told the Washington Post last week, but the agency has refused to fully disclose whether or not its agents obtain probable cause warrants to track phones using the controversial device.

And the federal government’s response to the EFF’s FOIA about Stingray wasn’t exactly responsive. While the FOIA request generated over 20,000 records related to StingRay, the Justice Department released only a pair of court orders and a handful of heavily redacted documents that didn’t explain when and how the technology was used.

The LA Weekly reported in January that the StingRay “intended to fight terrorism was used in far more routine Los Angeles Police criminal investigations,” apparently without the courts’ knowledge that it probes the lives of non-suspects living in the same neighborhood with a suspect.

Critics say the technology wrongfully invades technology and that its uncontrolled use by law enforcement raised constitutional questions. “It is the biggest threat to cell phone privacy you don’t know about,” EFF said in a statement.

LAPD police cruiser
LAPD police cruiser: today's police are equipped with high-technology.
(Photo: 888bailbond)
ACLU privacy researcher Christopher Soghoian told a Yale Law School Location Tracking and Biometrics Conference panel last month that “the government uses the device either when a target is routinely and quickly changing phones to thwart a wiretap or when police don’t have sufficient cause for a warrant.”

“The government is hiding information about new surveillance technology not only from the public, but even from the courts,” ACLU staff attorney Linda Lye wrote in a legal brief in the first pending federal StingRay case (see below). “By keeping courts in the dark about new technologies, the government is essentially seeking to write its own search warrants, and that’s not how the Constitution works.”

Lye further expressed concern over the StingRay’s ability to interfere with cell phone signals in violation of Federal Communication Act. “We haven’t seen documents suggesting the LAPD or any other agency have sought or obtained FCC authorization,” she wrote.

“If the government shows up in your neighborhood, essentially every phone is going to check in with the government,” said the ACLU’s Soghoian. “The government is sending signals through people’s walls and clothes and capturing information about innocent people. That’s not much different than using invasive technology to search every house on a block,” Soghoian said during interviews with reporters covering the StingRay story.

A Harris Corporation price list for the StingRay
indicates a unit price of more than $75,000.
Advocates also raised alarms over another troubling issue: Using the StingRay allows investigators to bypass the routine process of obtaining fee-based location data from cell service providers like Sprint, AT&T, Verizon, T-Mobile and Comcast. Unlike buying location data fro service providers, using StingRay leaves no paper trail for defense attorneys.

Crack defense attorney Stephen Leckar who scored a victory in a landmark Supreme Court decision over the feds’ warrantless use of a GPS tracker in US v. Jones, a cocaine trafficking case where the government tracked Jones’ vehicle for weeks without a warrant, also has concerns.

“Anytime the government refuses to disclose the ambit of its investigatory device, one has to wonder, what’s really happening,” he told the Chronicle. ”If without a warrant the feds use this sophisticated device for entry into people’s homes, accessing private information, they may run afoul of a concurring opinion by Justice Alito, who ruled in US v Jones whether people would view unwarranted monitoring of their home or property as Constitutionally repugnant.”

Leckar cited Supreme Court precedent in Katz v. US (privacy) and US v. Kyllo (thermal imaging), where the Supreme Court prohibited searches conducted by police from outside the home to obtain information behind closed doors. Similar legal thinking marked February’s Supreme Court decision in a case where it prohibited the warrantless use of drug dogs to sniff a residence, Florida v. Jardines.

The EFF FOIA lawsuit shed light on how the US government sold StingRay devices to state and local law enforcement agencies for use specifically in drug cases. The Los Angeles and Fort Worth police departments have publicly acknowledged buying the devices, and records show that they are using them for drug investigations.

“Out of 155 cell phone investigations conducted by LAPD between June and September 2012, none of these cases involved terrorism, but primarily involved drugs and other felonies,” said Peter Scheer, director of the First Amendment Center.

The StingRay technology is so new and so powerful that it not only raises Fourth Amendment concerns, it also raises questions about whether police and federal agents are withholding information about it from judges to win approval to monitor suspects without meeting the probable cause standard required by the Fourth. At least one federal judge thinks they are. Magistrate Judge Brian Owsley of the Southern District of Texas in Corpus Christi told the Yale conference federal prosecutors are using clever techniques to fool judges into allowing use of StingRay. They will draft surveillance requests to appear as Pen Register applications, which don’t need to meet the probable cause standards.

“After receiving a second StingRay request,” Owsley told the panel, “I emailed every magistrate judge in the country telling them about the device. And hardly anyone understood them.”

In a earlier decision related to a Cell-site Simulator, Judge Owsley denied a DEA request to obtain data information to identify where the cell phone belonging to a drug trafficker was located. DEA wanted to use the suspect’s E911 emergency tracking system that is operated by the wireless carrier. E911 trackers reads signals sent to satellites from a cell phone’s GPS chip or by triangulation of radio transmitted signal. Owsley told the panel that federal agents and US attorneys often apply for a court order to show that any information obtained with a StingRay falls under the Stored Communication Act and the Pen Register statute.

DEA later petitioned Judge Owsley to issue an order allowing the agent to track a known drug dealer with the StingRay. DEA emphasized to Owsley how urgently they needed approval because the dealer had repeatedly changed cell phones while they spied on him. Owsley flatly denied the request, indicating the StingRay was not covered under federal statute and that DEA and prosecutors had failed to disclose what they expected to obtain through the use of the stored data inside the drug dealer’s phone, protected by the Fourth Amendment.

“There was no affidavit attached to demonstrate probable cause as required by law under rule 41 of federal criminal procedures,” Owsley pointed out. The swiping of data off wireless phones is “cell tower dumps on steroids,” Owsley concluded.

But judges in other districts have ruled favorably for the government. A federal magistrate judge in Houston approved DEA request for cell tower data without probable cause. More recently, New York Southern District Federal Magistrate Judge Gabriel Gorenstein approved warrantless cell-site data.

GPS Devices in car
(Photo: M. Roach)
“The government did not install the tracking device — and the cell user chose to carry the phone that permitted transmission of its information to a carrier,” Gorenstein held in that opinion. “Therefore no warrant is needed.”

In a related case, US District Court Judge Liam O’Grady of the Northern District of Virginia ruled that the government could obtain data from Twitter accounts of three Wikileakers without a warrant. Because they had turned over their IP addresses when they opened their Twitter accounts, they had no expectation of privacy, he ruled.

“Petitioners knew or should have known that their IP information was subject to examination by Twitter, so they had a lessened expectation of privacy in that information, particularly in light of their apparent consent to the Twitter terms of service and privacy policy,” Judge O’Grady wrote.

A federal judge in Arizona is now set to render a decision in the nation’s first StingRay case. After a hearing last week, the court in US v. Rigmaiden is expected to issue a ruling that could set privacy limits on how law enforcement uses the new technology. Just as the issue of GPS tracking technology eventually ended up before the Supreme Court, this latest iteration of the ongoing balancing act between enabling law enforcement to do its job and protecting the privacy and Fourth Amendment rights of citizens could well be headed there, too.

____
Copyright © Clarence Walker, Drug War Chronicle and Global Research, 2013
Related Posts Plugin for WordPress, Blogger...