Google Search

Showing posts with label Program. Show all posts
Showing posts with label Program. Show all posts

Friday, December 6, 2013

PRISM: 50% of Americans approve of NSA's internet spying program

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

According to data from the Pew Research Center, 50% of Americans approve of their government’s collection of telephone and internet data as part of anti-terrorism efforts.

The research was conducted by Pew between July 17 - 21, just six weeks after Edward Snowden blew the whistle on PRISM - the US government's omnipresent internet spying initiative.

This apparent approval by a slim majority of Americans (50% approve and 44% disapprove) is all the more surprising given what else the survey has to tell us.

Only 18% believe that data collection is limited to metadata22% believe the program is limited to anti-terrorism30% believe courts provide adequate limits on what's collected

It seems that the American public doesn't believe what it has been told about PRISM by the government, nor that its citizens are adequately protected by their courts.

Indeed 63% believe that the NSA is logging the contents of emails and phone calls despite President Obama's insistence that "Nobody is listening to your telephone calls".

Perceptions of the Governments Data Collection Program

Perhaps most surprisingly, the program garners a 47% approval rate even amongst that very group of respondents who believe that the government is recording phone calls and emails.

In fact the program still has a 40% approval rating even amongst people who believe their own emails and phone calls have been logged.

The basic split between those who approve and those who don't was mirrored in the US Congress last week when the House of Representatives voted by a slim majority (50% vs 47%) to continue funding the NSA's internet dragnet.

I think that vote encapsulates the significance of these numbers. Whilst PRISM does not enjoy runaway support, the revelation of its existence, and all that its existence implies, simply has not energised people in the way many of us expected it would.

Lindsay MillsIf the TV and print media are any reflection of the public mood then Snowden's uncovering of a vast domestic surveillance grid is not nearly as significant as the international game of Where's Wally/Waldo that followed. Or the fact that his girlfriend is a pole dancer with a diverting range of self portraits.

Within the computer security community at least, there are signs of life.

At the same time as Pew was running its research, Joseph Bonneau became the inaugural recipient of the NSA's award for the Best Scientific Cybersecurity Paper for The science of guessing: analyzing an anonymized corpus of 70 million passwords.

Although he accepted the award, he also took the opportunity to say via his blog that he thought a free society is not compatible with the NSA in its current form.

A situation for which he gives the spooks a pass, laying the blame squarely at the feet of his nation's politicians.

...I’m ashamed we’ve let our politicians sneak the country down this path.

In accepting the award I don’t condone the NSA’s surveillance. Simply put, I don’t think a free society is compatible with an organisation like the NSA in its current form. Yet I’m glad I got the rare opportunity to visit with the NSA and I’m grateful for my hosts’ genuine hospitality ... It affirmed my feeling that America’s core problems are in Washington and not in Fort Meade.

The apparent ambivalence of the US public at large to the government's vast data collection effort, in spite of the obvious concerns about it, can perhaps be attributed in part to the extraordinary power that the threat of terrorism invokes.

The Pew Research Center's own research into survey wording showed that when internet surveillance was described as “part of anti-terrorism efforts” it garnered 9% more support than when this goal was not mentioned.

Whilst fighting terror is certainly a real and pressing task for government we can be sure that politicians have shown a willingness to use terror as a smokescreen in the past.

A concern that Justin Amash himself raised when introducing his bill to curtail NSA funding for PRISM:

They'll tell you that the government must violate the rights of the American people to protect us against those who hate our freedom.

Reassuringly there are also signs within the survey that invoking the threat of terrorism isn't a blank cheque.

Survey respondents were asked to say whether government anti-terror policies had 'not gone far enough to protect the country' or 'gone too far in restricting civil liberties'.

Pew has asked that question twelve times since 2004 and this was the first time that more people have expressed greater concern about civil liberties than security.

Govt Anti-Terror Policies

Follow @NakedSecurity

View the original article here

Thursday, October 10, 2013

US uses NSA-FBI PRISM program to snoop on everything and everybody

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

President Obama, courtesy of Shutterstock"Nobody is listening to your telephone calls," President Obama said on Friday, defending a broad government surveillance program that was leaked to the press in the preceding week.

Obama defended the program, code-named "PRISM," at an event on the West coast that was initially supposed to be devoted to the health care law.

According to the New York Times, the president sought to reassure the public that the information collected from nine of the biggest internet companies about phone calls and internet traffic helps to prevent terrorist attacks and is controlled by rigorous judicial and Congressional oversight.

News about the secret surveillance program was broken on Wednesday by the Guardian, which revealed that the National Security Agency (NSA) is collecting telephone records of millions of Verizon's US customers under a top-secret order issued on April 25 by the secret Foreign Intelligence Surveillance Court (FISA) to the Federal Bureau of Investigation (FBI).

The order, obtained by the Guardian, directs Verizon to hand over information on all telephone calls in its systems, both within the US and between the US and other countries, on an "ongoing, daily basis."

The court order contains a gag provision that prohibits Verizon from disclosing to the public either the FBI's request for customer records or the court order itself.

It covers a nearly three-month period ending July 19 (although Senator Dianne Feinstein on Thursday said that the order has been renewed every three months for the last seven years) and requires the numbers of both parties on a call to be handed over, as well as location data, call duration, unique identifiers, and the time of all calls.

The order doesn't cover call content.

As the Guardian reports, the document is the first demonstration that the current US administration is collecting, indiscriminately and in bulk, communications records of millions of US citizens, whether or not they're suspected of wrongdoing.

Why is this such a big deal?

US surveillance, images courtesy of ShutterstockThe slides explicitly state that collection is being done "directly" from the servers of these US service providers:The American Civil Liberties Union (ACLU) answers that question in a posting of the court order that it's annotated with comments.

A few examples from the ACLU's annotations:

The court order likely refers to an earlier, longer opinion on the legality of using Section 215 of the Patriot Act to track all Americans’ phone calls that was never made public but should have been. The FBI and the military are focusing on purely domestic calls, "sweeping up the phone records of countless innocent Americans," the ACLU says.Even if the NSA doesn't record call content, it's collecting metadata that can be as sensitive as content: e.g., information about whom you’re calling, who calls you, how long you talk, and maybe even where you’re talking from. This allows the government to build a profile that can reveal political and religious affiliations, medical conditions, infidelities, and more.

But PRISM is larger than Verizon.

For its part, the Washington Post also obtained a top-secret document that showed that the NSA and the FBI are "tapping directly into the central servers" of the nine largest internet companies to extract audio and video chats, photographs, e-mails, documents, and connection logs that enable analysts to track foreign targets.

The Guardian on Friday reported that it has obtained documents that further show that the United Kingdom's electronic eavesdropping and security agency, Government Communications Headquarters (GCHQ), has been piggybacking on PRISM, secretly gathering intelligence.

According to The Guardian, PRISM allows GCHQ to bypass the formal legal process required in the UK to obtain content such as emails, photos and videos from internet companies based outside the country's borders.

US director of national intelligence James R. Clapper on Thursday confirmed in a statement that coverage from both newspapers pertains to collection of communications pursuant to Section 702 of the Foreign Intelligence Surveillance Act (FISA).

Clapper claimed that the two newspapers' coverage contains "numerous inaccuracies" but failed to elaborate.

The Washington Post obtained a set of 41 partially redacted briefing slides that describe the operation, intended for senior analysts in the NSA's Signals Intelligence Directorate.

The list of companies allegedly providing access to the NSA includes:

Google (Gmail, YouTube, etc)FacebookMicrosoft (Hotmail, Skype, etc.)AppleYahoo PalTalkAOL

Yet spokespeople at these companies have denied allowing the US government direct access to their servers, The Guardian reports.

Here's what spokespeople had to say, courtesy of the Guardian:

Apple: "We have never heard of PRISM. We do not provide any government agency with direct access to our servers and any agency requesting customer data must get a court order."Facebook: "When Facebook is asked for data or information about specific individuals, we carefully scrutinise any such request for compliance with all applicable laws, and provide information only to the extent required by law."Google: "Google cares deeply about the security of our users' data. We disclose user data to government in accordance with the law, and we review all such requests carefully. From time to time, people allege that we have created a government 'backdoor' into our systems, but Google does not have a 'back door' for the government to access private user data."Microsoft: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don't participate in it."Yahoo: "Yahoo! takes users' privacy very seriously. We do not provide the government with direct access to our servers, systems, or network."Regarding executives speaking off the record, the Guardian writes: "Executives said they had never even heard of PRISM until contacted by the Guardian."

While that's a bit of what we do know about PRISM, there's plenty we don't know.

One of the main things we don't know, of course, is the identity of the whistleblower who leaked details of the program.

Whoever it is has risked getting him-, her- or themselves in deep trouble with this administration, which has proved zealous in pursuing whistleblowers.

Obama denounced this particular leak by saying it only helps terrorists when the media publicizes surveillance operations:

"If every step that we're taking to try to prevent a terrorist act is on the front page of the newspapers or on television, then presumably the people who are trying to do us harm are going to be able to get around our preventive measures."

The Atlantic pulled together some of the other remaining question marks in this article.

Just a small sample of the unknowns:

The slides show that PRISM supposedly supplies one-seventh of the intelligence that goes into Obama's daily briefings, yet only cost $20 million. How can it be so cheap?Why are Twitter and Amazon missing from the list? Does Twitter's fierce protection of user data have anything to do with it?Apple didn't join the list until October 2012, five years after Microsoft. Why? Are the tech companies lying about the access to their servers, forbidden from acknowledging the program or their participation, or is it being done surreptitiously, via an API or an intermediary, such as a government vendor?

CNN's Michael Pearson has put together an FAQ about how US data collection affects each of us.

But after we learn how it affects us, many of us will want to know how to protect ourselves from government spying on our email, online searches, Skype calls and other electronic communications.

To that end, PC World on Friday put out this list of tips on protecting your PC from PRISM.

These aren't guaranteed to make your PC surveillance-proof, mind you, but they're a start, at the very least. Just remember that, given enough resources, an attacker can ferret out most anything about us.

Some of PC World's tips:

Avoid using popular Web services. Rather than Google search, for example, try a lesser known search engine such as DuckDuckGo, which promises not to track or store your search history.Ditch your smartphone. If you go with a dumb phone, you're likely still trackable, but it can capture a whole lot less information about you.Encrypt your hard drive, files and email. Subscribe to a VPN.

Of course, these protective measures beg the question: If you're a serious criminal, wouldn't you already be using secure communications anyway, covering your tracks with strong encryption and using throwaway phones?

Follow @LisaVaas
Follow @NakedSecurity

Image of President Obama, surveillance cameras, and American flag courtesy of Shutterstock.


View the original article here

Tuesday, April 9, 2013

Mega's bug bounty program - one week down, "a few billion billion years" to go

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mega, the cloud storage service brought to you by larger-than-life New Zealand digeratus Kim Dotcom, has released the first feedback on its bug bounty program.

Mega, in case you missed it, is a recent reincarnation of the controversial Kiwi file-sharing service Megaupload.

Megaupload imploded a year ago when Dotcom was arrested in New Zealand to face extradition to the USA on serious criminal charges, including racketeering (organised criminality) and money laundering.

The background to the charges was the allegedly vast amount of pirated material hosted on the Megaupload site.

On the anniversary of the big fella's arrest (in case you haven't come across Dotcom before, he's said to have the impressive vital statistics of 200cm and 135kg - he's the silhouette on the left in the image above), Mega arose from the ashes of Megaupload.

This time the company aims to sidestep accusations that it's a front for piracy by using built-in cryptography so that it doesn't, and indeed cannot, know what you're uploading and downloading.

As we put it when Mega launched, "all it does is to store a giant pile of shredded cabbage on your behalf."

Cryptanalysts and cypherpunks soon took aim at some aspects of Mega's cryptography.

Critics came up with some interesting commentary about its design and implementation, such as:

Disapproving of the random number generation technique used when setting up your encryption keys.Questioning the cryptographic mechanism for generating confirmation links sent by email.Wondering how Mega could claim to offer a deduplication feature if it genuinely knew nothing about the content of your uploads.Lamenting that most of Mega's secure content servers used only 1024-bit public keys, currently considered the lowest rung of acceptability.

Mega soon fired its own verbal broadside back, declaring itself "not too impressed with the results."

The company was particularly scathing of the critique of its cheap-and-cheerful 1024-bit keys, pointing out that the 1024-bit-protected content was itself protected by a cryptographic checksum authenticated with 2048-bit security, so there.

That counterblast was followed a critique from hacking group fail0verflow, pointing out that Mega's programmers had got the implementation of the 2048-bit-protected checksum all wrong.

This time, Mega hit back with actions, not words, quickly adapting its own code to repair the mistakes, and rightly earning praise for the speed of its response.

Instead of concatenating all checksummed files and computing a single "combo-checksum", Mega began to publish separate checksums for each file.

Checksumming all files as if they were one is imprecise because you can alter the boundaries between the combined files without changing the checksum.

Subtle attacks might be possible by shifting JavaScript code out of one source file into another.

And instead of using a forgeable CBC-MAC checksum, it switched to SHA-256.

Shortly after that, Mega got onto the front foot and announced bug bounties that would pay "up to €10,000 per bug, depending on its complexity and impact potential."

It also published two outright challenges that are worth €10,000 each.

One requires you to to find the decryption key for a file on the site. (Decrypting the file is not enough. You have to recover the key, which is a somewhat stronger result.) The other requires you to recover the user's password from a confirmation email link.

Whatever you think of Mega, its founder, its raison d'etre, its bombasticity and even the value of the bounties its offering, it nevertheless reflects to the company's credit that it came out with the bounties at all.

And just a week after the bounties were announced, Mega has announced the first "interim results," as it calls them.

No mention of how much was paid to whom for exactly what, but no-one's pulled off a crown jewels crack yet (or Severity V and Severity VI in Mega's terminology: remote code execution or worse).

That's good news for Mega, though of course it's only a week into the bug bounty program.

Nevertheless, the company is as gung-ho as ever, needlessly mentioning that it is "needless to mention that nobody cracked any of the brute-force challenges yet (please check back in a few billion billion years)."

Let's hope the Megabloggers are right...

Follow @duckblog

Image of cabbage, including the shredded stuff, courtesy of Shutterstock.


View the original article here

Wednesday, September 28, 2011

Pentagon Extends Program to Defend Cyber Networks - ABC News

By LOLITA C. BALDOR Associated Press WASHINGTON September 26, 2011 (AP)

The Pentagon is extending a pilot program to help protect its prime defense contractors, an effort the Obama administration can use as a model to prevent hackers and hostile nations from breaching networks and stealing sensitive data.

The move comes as cybersecurity officials warn of increasingly sophisticated cyberattacks against U.S. defense companies, including data related to critical Pentagon weapons systems and aircraft.

Officials at the Department of Homeland Security are reviewing the program, with an eye toward extending similar protections to power plants, the electric grid and other critical infrastructure.

Efforts to better harden the networks of defense contractors come as Pentagon analysts investigate a growing number of cases involving the mishandling or removal of classified data from military and corporate systems. Intrusions into defense networks are now close to 30 percent of the Pentagon's Cyber Crime Center's workload, according to senior defense officials. And they say it continues to increase.

The Pentagon's pilot program represents a key breakthrough in the Obama administration's push to make critical networks more secure by sharing intelligence with the private sector and helping companies better protect their systems. In many cases, particularly for defense contractors, the corporate systems carry data tied to sensitive U.S. government programs and weapons.

null Computer hard drives, from closed criminal cases, sit on a shelf waiting to be wiped of information at the Department of Defense Cyber Crime Center in Linthicum, Thursday, Aug. 11, 2011. Hackers and hostile nations are launching increasingly sophisticated cyberattacks against U.S. defense contractors. And the Pentagon is extending a program to help protect its prime suppliers, while serving as a possible model for other government agencies. Pentagon analysts are investigating a growing number of cases involving the mishandling or removal of classified data from military and corporate systems. Defense officials say intrusions into defense networks are now close to 30 percent of the Pentagon's Cyber Crime Center's workload. (AP Photo/Cliff Owen) Close

So far, the trial program involves at least 20 defense companies. It will be extended through mid-November amid ongoing discussions about how to expand it to more companies and subcontractors.

"The results this far are very promising," said William Lynn, the deputy secretary of defense who launched the program in May. "I do think it offers the potential opportunity to add a layer of protection to the most critical sectors of our infrastructure."

He said the program has been able to block hundreds of intrusions into the defense companies, including some that were very sophisticated.

Lynn, who will leave office in early October, said the Pentagon is reviewing the costs of extending the program and so far it does not seem to be prohibitive. He said the government should move as quickly as possible to expand the protections to other vital sectors.

A senior DHS official said no decisions have been made, but any effort to extend the program — including to critical infrastructure — faces a number of challenges.

The official, who spoke on condition of anonymity because the program review is ongoing, said it would be helpful if Congress would pass legislation that explicitly says DHS is responsible for helping private sector companies protect themselves against cyberattack. Also, the legislation should say that companies can be protected from certain privacy and other laws in order to share information with the government for cybersecurity purposes, the official said.

Senior U.S. leaders have been blunt about the escalating dangers of a cyberattack, and have struggled to improve the security of federal networks while also encouraging the public and corporate America to do the same.

"Cyber actually can bring us to our knees," said Adm. Mike Mullen, chairman of the Joint Chiefs of Staff, adding that at some point the Pentagon may need to develop some type of governing structure similar to how the U.S. and allies monitor and limit nuclear weapons.


View the original article here