Sunday, October 12, 2014

Act Enforcement for Activism world

Good essay by Molly Sauter: basically, there is no legal avenue for activism and protest on the Internet.
Also note Sauter's new book, The Coming Swarm.

NSA Impact In Other Countries

The latest Intercept article on the Snowden NSA documents talks about their undercover operatives working in foreign companies. There are no specifics, although the countries China, Germany, and South Korea are mentioned. It's also hard to tell if the NSA has undercover operatives working in companies in those countries, or has undercover contractors visiting those companies. The document is dated 2004, although there's no reason to believe that the NSA has changed its behavior since then.
The most controversial revelation in Sentry Eagle might be a fleeting reference to the NSA infiltrating clandestine agents into "commercial entities." The briefing document states that among Sentry Eagle's most closely guarded components are "facts related to NSA personnel (under cover), operational meetings, specific operations, specific technology, specific locations and covert communications related to SIGINT enabling with specific commercial entities (A/B/C)""
It is not clear whether these "commercial entities" are American or foreign or both. Generally the placeholder "(A/B/C)" is used in the briefing document to refer to American companies, though on one occasion it refers to both American and foreign companies. Foreign companies are referred to with the placeholder "(M/N/O)." The NSA refused to provide any clarification to The Intercept.
That program is SENTRY OSPREY, which is a program under SENTRY EAGLE.
The document makes no other reference to NSA agents working under cover. It is not clear whether they might be working as full-time employees at the "commercial entities," or whether they are visiting commercial facilities under false pretenses.
Least fun job right now: being the NSA person who fielded the telephone call from the The Intercept to clarify that (A/B/C)/(M/N/O) thing. "Hi. We're going public with SENTRY EAGLE next week. There's one thing in the document we don't understand, and we wonder if you could help us...." Actually, that's wrong. The person who fielded the phone call had no idea what SENTRY EAGLE was. The least fun job belongs to the person up the command chain who did.

Saturday, October 4, 2014

Security concerns in Firechat


Firechat is a secure wireless peer-to-peer chat app:
Firechat is theoretically resistant to the kind of centralized surveillance that the Chinese government (as well as western states, especially the US and the UK) is infamous for. Phones connect directly to one another, establish encrypted connections, and transact without sending messages to servers where they can be sniffed and possibly decoded.Firechat has security issues.

Next move after the own search engine

The NSA is building a private cloud with its own security features:
As a result, the agency can now track every instance of every individual accessing what is in some cases a single word or name in a file. This includes when it arrived, who can access it, who did access it, downloaded it, copied it, printed it, forwarded it, modified it, or deleted it.
[...]
"All of this I can do in the cloud but--in many cases--it cannot be done in the legacy systems, many of which were created before such advanced data provenance technology existed." Had this ability all been available at the time, it is unlikely that U.S. soldier Bradley Manning would have succeeded in obtaining classified documents in 2010.

Well Briefing With Snowdon Documents

Former NSA employee -- not technical director, as the link says -- explains how NSA bulk surveillance works, using some of the Snowden documents. Very interesting.
This week Microsoft announced the next version of its Operating system, dubbed WIndows 10, providing Windows 10 Technical Preview release under its "Insider Program" in order to collect feedback from users and help shape the final version of the operating system, but something really went WRONG!
Inside Microsoft’s Insider Program you'll get all the latest Windows preview builds as soon as they're available. In return, we want to know what you think. You’ll get an easy-to-use app to give us your feedback, which will help guide us along the way.” Microsoft website reads.
Well, how many of you actually read the “Terms of Service” and “Privacy Policy” documents before downloading the Preview release of Windows 10? I guess none of you, because most computer users have habit of ignoring that lengthy paragraphs and simply click "I Agree" and then "next", which is not at all a good practice.
Do you really know what permissions you have granted to Microsoft by installing Free Windows 10 Technical Preview edition? Of Course, YOU DON’T. Well, guess what, you've all but signed away your soul !!

PERMISSION TO KEYLOG
If you are unaware of Microsoft’s privacy policy, so now you should pay attention to what the policy says. Microsoft is watching your every move on the latest Windows 10 Technical Preview, Thanks to portions of Microsoft's privacy policy, which indicates that the technology giant is using keylogger to collect and use users’ data in a variety of astounding ways without the user being aware.
If you open a file, we may collect information about the file, the application used to open the file, and how long it takes any use [of] it for purposes such as improving performance, or [if you] enter text, we may collect typed characters, we may collect typed characters and use them for purposes such as improving autocomplete and spell check features,” the privacy policy states.
Essentially by accepting the Windows 10 privacy policy you are allowing Microsoft to screen your files and log your keystrokes. This means, if you open a file and type, Microsoft have access to what you type, and the file info within.

 This could likely one of the reasons why the company insisted that Windows Technical Preview not be installed on computers that are used every day.
OTHER DATA COLLECTION
But Wait! Wait! Not just this, Microsoft says it may collect even more data. The company will be watching your apps for compatibility, and collect voice information when you use speech to text. This information will be used to improve speech processing, according to Microsoft.
"When you acquire, install and use the Program, Microsoft collects information about you, your devices, applications and networks, and your use of those devices, applications and networks," the privacy policy states. "Examples of data we collect include your name, email address, preferences and interests; browsing, search and file history; phone call and SMS data; device configuration and sensor data; and application usage."
Though, technology companies continue to develop a fine line on the issue of privacy and data collection and based on the information which the Microsoft collects, it could have thousands of username and password combinations stored in a database somewhere. But we may well see a public feedback to this newest attempt to mine users data.
However, it is clearly known that they are not going to use those data to access users’ bank accounts or company's private network, but the fact that the company is collecting data by all means, could possibly open a way for someone to steal and misuse the information for their own purpose.

Although the feedback being collected in the Windows Technical Preview will only occur within the Technical Preview period, reported by WinBeta. Once Windows 10 launches to the public as RTM, the data Microsoft collects will be removed from the operating system.

If you wish to test it out, you can Download Windows 10 Preview Edition Here.

Security fear in china

The Chinese government checked ten thousand pigeons for "dangerous materials." Because fear.