Google Search

Showing posts with label PRISM. Show all posts
Showing posts with label PRISM. Show all posts

Friday, December 6, 2013

PRISM: 50% of Americans approve of NSA's internet spying program

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

According to data from the Pew Research Center, 50% of Americans approve of their government’s collection of telephone and internet data as part of anti-terrorism efforts.

The research was conducted by Pew between July 17 - 21, just six weeks after Edward Snowden blew the whistle on PRISM - the US government's omnipresent internet spying initiative.

This apparent approval by a slim majority of Americans (50% approve and 44% disapprove) is all the more surprising given what else the survey has to tell us.

Only 18% believe that data collection is limited to metadata22% believe the program is limited to anti-terrorism30% believe courts provide adequate limits on what's collected

It seems that the American public doesn't believe what it has been told about PRISM by the government, nor that its citizens are adequately protected by their courts.

Indeed 63% believe that the NSA is logging the contents of emails and phone calls despite President Obama's insistence that "Nobody is listening to your telephone calls".

Perceptions of the Governments Data Collection Program

Perhaps most surprisingly, the program garners a 47% approval rate even amongst that very group of respondents who believe that the government is recording phone calls and emails.

In fact the program still has a 40% approval rating even amongst people who believe their own emails and phone calls have been logged.

The basic split between those who approve and those who don't was mirrored in the US Congress last week when the House of Representatives voted by a slim majority (50% vs 47%) to continue funding the NSA's internet dragnet.

I think that vote encapsulates the significance of these numbers. Whilst PRISM does not enjoy runaway support, the revelation of its existence, and all that its existence implies, simply has not energised people in the way many of us expected it would.

Lindsay MillsIf the TV and print media are any reflection of the public mood then Snowden's uncovering of a vast domestic surveillance grid is not nearly as significant as the international game of Where's Wally/Waldo that followed. Or the fact that his girlfriend is a pole dancer with a diverting range of self portraits.

Within the computer security community at least, there are signs of life.

At the same time as Pew was running its research, Joseph Bonneau became the inaugural recipient of the NSA's award for the Best Scientific Cybersecurity Paper for The science of guessing: analyzing an anonymized corpus of 70 million passwords.

Although he accepted the award, he also took the opportunity to say via his blog that he thought a free society is not compatible with the NSA in its current form.

A situation for which he gives the spooks a pass, laying the blame squarely at the feet of his nation's politicians.

...I’m ashamed we’ve let our politicians sneak the country down this path.

In accepting the award I don’t condone the NSA’s surveillance. Simply put, I don’t think a free society is compatible with an organisation like the NSA in its current form. Yet I’m glad I got the rare opportunity to visit with the NSA and I’m grateful for my hosts’ genuine hospitality ... It affirmed my feeling that America’s core problems are in Washington and not in Fort Meade.

The apparent ambivalence of the US public at large to the government's vast data collection effort, in spite of the obvious concerns about it, can perhaps be attributed in part to the extraordinary power that the threat of terrorism invokes.

The Pew Research Center's own research into survey wording showed that when internet surveillance was described as “part of anti-terrorism efforts” it garnered 9% more support than when this goal was not mentioned.

Whilst fighting terror is certainly a real and pressing task for government we can be sure that politicians have shown a willingness to use terror as a smokescreen in the past.

A concern that Justin Amash himself raised when introducing his bill to curtail NSA funding for PRISM:

They'll tell you that the government must violate the rights of the American people to protect us against those who hate our freedom.

Reassuringly there are also signs within the survey that invoking the threat of terrorism isn't a blank cheque.

Survey respondents were asked to say whether government anti-terror policies had 'not gone far enough to protect the country' or 'gone too far in restricting civil liberties'.

Pew has asked that question twelve times since 2004 and this was the first time that more people have expressed greater concern about civil liberties than security.

Govt Anti-Terror Policies

Follow @NakedSecurity

View the original article here

Saturday, October 19, 2013

PRISM, UK Surveillance, Sweden vs. Google, Blackberry Z10 – 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here's the latest in our 60 Second Security video series, bringing you a fast, incisive and entertaining angle on recent computer security issues.

Watch the latest security news in just 60 seconds! (Higher resolution available directly from YouTube. Click the captions button for closed captions.)

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, BlackBerry, cloud, flash, Google Apps, law, Patch, PRISM, Privacy, salem, surveillance, Sweden, vulnerability, z10


View the original article here

Saturday, October 12, 2013

PRISM - not as bad as you thought? (And don't call it PRISM!)

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

You've almost certainly heard about PRISM, an abbreviation that has come to mean "US surveillance of everything."

Since Naked Security first wrote about this unfolding drama last week, a raft of new information has come to light.

The whistleblower who leaked the information has come forward; his employer has responded; and the US Department of National Intelligence itself has spoken on the record.

The conspiracy theories probably haven't been shaken, but they've certainly been stirred.

A chap by the name of Edward Snowden, who's 29 years old and works for a defence contractor, has outed himself as the source of the PRISM leak.

According to The Guardian, he slipped out of the US, flew to Hong Kong and holed up in a hotel.

Apparently, he's been out of his room only three times in the past three weeks.

From Hong Kong, he blew the whistle, purportedly claiming that:

I don't want to live in a society that does these sort of things.

He also seems to have come up with a very quotable quote that will probably end up being seen as selfless by his fans, but as mildly messianic by his detractors:

I understand that I will be made to suffer for my actions, but I will be satisfied if the federation of secret law, unequal pardon and irresistible executive powers that rule the world that I love are revealed even for an instant

His employer, the redolently-named Booz Allen Hamilton, has reacted with undisguised outrage:

Booz Allen can confirm that Edward Snowden, 29, has been an employee of our firm for less than 3 months, assigned to a team in Hawaii. News reports that this individual has claimed to have leaked classified information are shocking, and if accurate, this action represents a grave violation of the code of conduct and core values of our firm. We will work closely with our clients and authorities in their investigation of this matter.

The US Office of the Director of National Intelligence has gone public, too.

The Director himself, James R. Clapper, has opened up a list of previously-classified nuggets about the PRISM project.

(You can download the official version from the DNI's website. [PDF, 3 pages.])

Here's a very brief summary of the DNI's brief summary:

It's not called PRISM; that's just the name of the computer system that makes it work.It's really called the Collection of Intelligence Pursuant to Section 702 of the Foreign Intelligence Surveillance Act, or Section 702 for short.Section 702 doesn't operate outside the oversight of Congress and the courts.It doesn't collect information without court approval or without informing service providers.It isn't allowed to target anyone inside the US, or any US citizen anywhere.It isn't allowed to target foreigners in order to target people inside the US.It's actually been jolly useful and has mitigated potential computer network attacks.

There you have it.

The DNI followed up its declassification by passing the buck to the Department of Justice, pretty much ruling out any further comment from the intelligence community:

Because the matter has been referred to the Department of Justice, we refer you to the Department of Justice for comment on any further specifics of the unauthorized disclosure of classified information by a person with authorized access. The Intelligence Community is currently reviewing the damage that has been done by these recent disclosures. Any person who has a security clearance knows that he or she has an obligation to protect classified information and abide by the law.

And that's that.

All I can say is that I can't see the DNI persuading people to stop using PRISM as a collective noun for the entire schemozzle, and I can't see the schemozzle abating for quite some time.

What do you think? What will happen next?

Let us know in the comments below!

Follow @duckblog


View the original article here

Thursday, October 10, 2013

US uses NSA-FBI PRISM program to snoop on everything and everybody

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

President Obama, courtesy of Shutterstock"Nobody is listening to your telephone calls," President Obama said on Friday, defending a broad government surveillance program that was leaked to the press in the preceding week.

Obama defended the program, code-named "PRISM," at an event on the West coast that was initially supposed to be devoted to the health care law.

According to the New York Times, the president sought to reassure the public that the information collected from nine of the biggest internet companies about phone calls and internet traffic helps to prevent terrorist attacks and is controlled by rigorous judicial and Congressional oversight.

News about the secret surveillance program was broken on Wednesday by the Guardian, which revealed that the National Security Agency (NSA) is collecting telephone records of millions of Verizon's US customers under a top-secret order issued on April 25 by the secret Foreign Intelligence Surveillance Court (FISA) to the Federal Bureau of Investigation (FBI).

The order, obtained by the Guardian, directs Verizon to hand over information on all telephone calls in its systems, both within the US and between the US and other countries, on an "ongoing, daily basis."

The court order contains a gag provision that prohibits Verizon from disclosing to the public either the FBI's request for customer records or the court order itself.

It covers a nearly three-month period ending July 19 (although Senator Dianne Feinstein on Thursday said that the order has been renewed every three months for the last seven years) and requires the numbers of both parties on a call to be handed over, as well as location data, call duration, unique identifiers, and the time of all calls.

The order doesn't cover call content.

As the Guardian reports, the document is the first demonstration that the current US administration is collecting, indiscriminately and in bulk, communications records of millions of US citizens, whether or not they're suspected of wrongdoing.

Why is this such a big deal?

US surveillance, images courtesy of ShutterstockThe slides explicitly state that collection is being done "directly" from the servers of these US service providers:The American Civil Liberties Union (ACLU) answers that question in a posting of the court order that it's annotated with comments.

A few examples from the ACLU's annotations:

The court order likely refers to an earlier, longer opinion on the legality of using Section 215 of the Patriot Act to track all Americans’ phone calls that was never made public but should have been. The FBI and the military are focusing on purely domestic calls, "sweeping up the phone records of countless innocent Americans," the ACLU says.Even if the NSA doesn't record call content, it's collecting metadata that can be as sensitive as content: e.g., information about whom you’re calling, who calls you, how long you talk, and maybe even where you’re talking from. This allows the government to build a profile that can reveal political and religious affiliations, medical conditions, infidelities, and more.

But PRISM is larger than Verizon.

For its part, the Washington Post also obtained a top-secret document that showed that the NSA and the FBI are "tapping directly into the central servers" of the nine largest internet companies to extract audio and video chats, photographs, e-mails, documents, and connection logs that enable analysts to track foreign targets.

The Guardian on Friday reported that it has obtained documents that further show that the United Kingdom's electronic eavesdropping and security agency, Government Communications Headquarters (GCHQ), has been piggybacking on PRISM, secretly gathering intelligence.

According to The Guardian, PRISM allows GCHQ to bypass the formal legal process required in the UK to obtain content such as emails, photos and videos from internet companies based outside the country's borders.

US director of national intelligence James R. Clapper on Thursday confirmed in a statement that coverage from both newspapers pertains to collection of communications pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA).

Clapper claimed that the two newspapers' coverage contains "numerous inaccuracies" but failed to elaborate.

The Washington Post obtained a set of 41 partially redacted briefing slides that describe the operation, intended for senior analysts in the NSA's Signals Intelligence Directorate.

The list of companies allegedly providing access to the NSA includes:

Google (Gmail, YouTube, etc)FacebookMicrosoft (Hotmail, Skype, etc.)AppleYahoo PalTalkAOL

Yet spokespeople at these companies have denied allowing the US government direct access to their servers, The Guardian reports.

Here's what spokespeople had to say, courtesy of the Guardian:

Apple: "We have never heard of PRISM. We do not provide any government agency with direct access to our servers and any agency requesting customer data must get a court order."Facebook: "When Facebook is asked for data or information about specific individuals, we carefully scrutinise any such request for compliance with all applicable laws, and provide information only to the extent required by law."Google: "Google cares deeply about the security of our users' data. We disclose user data to government in accordance with the law, and we review all such requests carefully. From time to time, people allege that we have created a government 'backdoor' into our systems, but Google does not have a 'back door' for the government to access private user data."Microsoft: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don't participate in it."Yahoo: "Yahoo! takes users' privacy very seriously. We do not provide the government with direct access to our servers, systems, or network."Regarding executives speaking off the record, the Guardian writes: "Executives said they had never even heard of PRISM until contacted by the Guardian."

While that's a bit of what we do know about PRISM, there's plenty we don't know.

One of the main things we don't know, of course, is the identity of the whistleblower who leaked details of the program.

Whoever it is has risked getting him-, her- or themselves in deep trouble with this administration, which has proved zealous in pursuing whistleblowers.

Obama denounced this particular leak by saying it only helps terrorists when the media publicizes surveillance operations:

"If every step that we're taking to try to prevent a terrorist act is on the front page of the newspapers or on television, then presumably the people who are trying to do us harm are going to be able to get around our preventive measures."

The Atlantic pulled together some of the other remaining question marks in this article.

Just a small sample of the unknowns:

The slides show that PRISM supposedly supplies one-seventh of the intelligence that goes into Obama's daily briefings, yet only cost $20 million. How can it be so cheap?Why are Twitter and Amazon missing from the list? Does Twitter's fierce protection of user data have anything to do with it?Apple didn't join the list until October 2012, five years after Microsoft. Why? Are the tech companies lying about the access to their servers, forbidden from acknowledging the program or their participation, or is it being done surreptitiously, via an API or an intermediary, such as a government vendor?

CNN's Michael Pearson has put together an FAQ about how US data collection affects each of us.

But after we learn how it affects us, many of us will want to know how to protect ourselves from government spying on our email, online searches, Skype calls and other electronic communications.

To that end, PC World on Friday put out this list of tips on protecting your PC from PRISM.

These aren't guaranteed to make your PC surveillance-proof, mind you, but they're a start, at the very least. Just remember that, given enough resources, an attacker can ferret out most anything about us.

Some of PC World's tips:

Avoid using popular Web services. Rather than Google search, for example, try a lesser known search engine such as DuckDuckGo, which promises not to track or store your search history.Ditch your smartphone. If you go with a dumb phone, you're likely still trackable, but it can capture a whole lot less information about you.Encrypt your hard drive, files and email. Subscribe to a VPN.

Of course, these protective measures beg the question: If you're a serious criminal, wouldn't you already be using secure communications anyway, covering your tracks with strong encryption and using throwaway phones?

Follow @LisaVaas
Follow @NakedSecurity

Image of President Obama, surveillance cameras, and American flag courtesy of Shutterstock.


View the original article here