Google Search

Showing posts with label surveillance. Show all posts
Showing posts with label surveillance. Show all posts

Tuesday, June 3, 2014

'Surveillance minimization' needed to restore trust

Surveillance minimization -- where surveillance is the exception, not the rule -- could help rebuild public trust following revelations about the collection of personal data, according to a law academic from the University of East Anglia.

Dr Paul Bernal, whose research covers privacy, surveillance and human rights, says the role of government surveillance and of surveillance by commercial groups and others must be reconsidered.

He suggests surveillance minimization as a way forward and will present the idea today at the Computers, Privacy and Data Protection international conference, taking place in Brussels, Belgium. It comes after the announcement last week by American President Barack Obama of curbs on the use of bulk data collected by US intelligence agencies, including the National Security Agency (NSA). His speech followed widespread anger after leaks revealed the full extent of US surveillance operations, including the mass collection of electronic data from communications of private individuals and spying on foreign leaders.

"Surveillance minimization is a simple concept and uses one of the overriding principles of data protection, the idea of data minimization, and applies it to communications surveillance," said Dr Bernal, who is currently writing a book on internet privacy and data protection. "The potential impact upon individuals from surveillance by commercial organizations can be significant, and as the NSA's PRISM program in particular demonstrated there are inextricable links between the commercial and the governmental.

"Surveillance minimization requires surveillance to be targeted rather than universal, controlled and warranted at the point of data gathering rather than of data access, and performed for the minimum necessary time on the minimum necessary people. Surveillance minimization could play a part in rebuilding the trust that is vital in this field -- and in the construction of a more 'privacy-friendly' internet -- one where surveillance is the exception, not the rule."

Dr Bernal argues the debate and discussion around the issues has been "miscast" and the common understanding -- that there is a balance to be found between the individual right to privacy and the collective right to security -- significantly misses the point.

"Communications surveillance, and internet surveillance in particular, has become a topic of much discussion in recent years," he said. "The information released, revealing at least some of the true extent and nature of communications surveillance being carried out by the NSA and others, has come as a surprise to many and contributed to an atmosphere of confusion and of distrust in a field where trust is of the utmost importance.

"Surveillance impacts upon more than just individual privacy, but upon a wide range of human rights, from freedom of expression and freedom of association and assembly to protection from discrimination. The impact is not just on individuals but on communities and other groups, and casting the debate as one of individual versus collective rights is misleading, inappropriately downplaying the significance of the impact of surveillance. The nature of this impact needs to be understood better if a more appropriate balance is to be found between people's rights and the duties of states to provide security for their citizens. Consequently, a new understanding of the balance between the relevant competing rights, needs and imperatives has to be established."


View the original article here

Saturday, December 14, 2013

XKeyScore surveillance, Bradley Manning verdict, LinkedIn hole - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

What's XKeyScore all about? How did Bradley Manning fare? What about the authentication hole in LinkedIn?

Watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: #sophospuzzle, 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, bh2013, Bradley Manning, Cablegate, data breach, Delaware, linkedin, Manning, NSA, oauth, PRISM, surveillance, Uni Delaware, vulnerability, Wikileaks, XKeyscore


View the original article here

Thursday, October 24, 2013

Internet giants call for transparency in government surveillance requests

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Facebook and Microsoft - two companies tagged as giving the Federal Bureau of Investigation (FBI) and National Security Agency (NSA) direct access to their servers for surveillance purposes - are echoing Google's call for transparency in government surveillance requests.

Google on Tuesday sent a letter to US Attorney General Eric Holder and the FBI and published this copy on its Public Policy blog.

Letter from Google to US govt 500.jpg

In the letter, Google's chief legal officer, David Drummond, wrote to Holder seeking permission to publish "aggregate numbers of national security requests, including Foreign Intelligence Surveillance Act [FISA] disclosures".

Facebook's General Counsel Ted Ullyot chimed in with a post saying that the company would love to give a transparency report, which both Google and Twitter now do, but Facebook does not.

But such a report would by necessity be misleading, Ullyot wrote, given that government restrictions on disclosure would poke so many holes in it:

"In the past, we have questioned the value of releasing a transparency report that, because of exactly these types of government restrictions on disclosure, is necessarily incomplete and therefore potentially misleading to users.

We would welcome the opportunity to provide a transparency report that allows us to share with those who use Facebook around the world a complete picture of the government requests we receive, and how we respond."

Such nondisclosure obligations regarding how many FISA requests Google receives and the number of user accounts they cover just fuel speculation that "our compliance with these requests gives the U.S. government unfettered access to [Google] users' data," which is false, Drummond wrote in his letter.

According to the BBC, Microsoft has also said that greater transparency on government requests for information "would help the community understand and debate these important issues''.

For whatever reason, Twitter was absent from the initial list of nine major internet companies specified as giving the government direct access to servers in information leaked to the Washington Post and the Guardian by (likely soon to be "former") Booz Allen Hamilton employee Edward Snowden.

Regardless, on Tuesday, Twitter threw its support behind those who've demanded more transparency around national security letters (NSLs), such as Google, Senator Jeff Merkley (who, along with 7 other senators of both parties, is pushing a bill to declassify FISA court rulings), and others.

Twitter General Counsel Alex Macgillivray's Twitter message to that effect:

Alex Macgillivray tweet

Completely agree with @Google, @SenJeffMerkley & others - we'd like more NSL transparency and @Twitter supports efforts to make that happen

Outrage over the surveillance program, known as PRISM*, continues to ignite, regardless of the Obama administration's strenuous efforts to poo-poo the media attention and public reaction sparked by what many interpret as the we-eavesdrop-on-everything program.

For its part, the American Civil Liberties Union (ACLU) has filed a lawsuit against the government over its "dragnet" collection of domestic phone call logs, saying that it's illegal and asking a judge to order that the program be stopped and its records purged.

Beyond calling for more transparency, the idea of a back door into their servers has seemingly outraged the nine internet companies.

Facebook founder and CEO Mark Zuckerberg, for one, crafted a personal post on Friday to both ask for more transparency and to address what he called "outrageous press reports about PRISM."*

Message from Zuckerberg on PRISM

From his post:

"We have never received a blanket request or court order from any government agency asking for information or metadata in bulk, like the one Verizon reportedly received. And if we did, we would fight it aggressively. We hadn't even heard of PRISM before yesterday."

At this point, much of the vehement denial over having a back door to servers could well be attributed to how, exactly, one defines "back door".

The New York Times, among others, has sketched out how the information hand-off takes place:

Instead of adding a back door to their servers, the companies were essentially asked to erect a locked mailbox and give the government the key....The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data.

....FISA orders can range from inquiries about specific people to a broad sweep for intelligence, like logs of certain search terms, lawyers who work with the orders said. There were 1,856 such requests last year, an increase of 6 percent from the year before.

*In light of director of national intelligence James R. Clapper's
of the Foreign Intelligence Surveillance Act" href="http://www.dni.gov/files/documents/Facts%20on%20the%20Collection%20of%20Intelligence%20Pursuant%20to%20Section%20702.pdf" rel="nofollow">corrections [PDF] about the project, we know that PRISM is just the name of the computer system that makes the data-Hoover-machine run and not the name of the project itself.

But given that the acronym for the program's real name - CIPS702FISA, or the Collection of Intelligence Pursuant to Section 702 of the Foreign Intelligence Surveillance Act - is unpronounceable, I think I'll just pretend, until somebody thinks up a more elegant name, that this whole thing is still called PRISM.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Saturday, October 19, 2013

PRISM, UK Surveillance, Sweden vs. Google, Blackberry Z10 – 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here's the latest in our 60 Second Security video series, bringing you a fast, incisive and entertaining angle on recent computer security issues.

Watch the latest security news in just 60 seconds! (Higher resolution available directly from YouTube. Click the captions button for closed captions.)

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, BlackBerry, cloud, flash, Google Apps, law, Patch, PRISM, Privacy, salem, surveillance, Sweden, vulnerability, z10


View the original article here

Saturday, October 5, 2013

SSCC 110 - Skype "surveillance," piracy, small biz and cybersecurity awareness [PODCAST]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Podcast

Episode #110 of our popular Chet Chat podcast series is out.

Chet and Duck (Chester Wisniewski and Paul Ducklin) offer you an infusion of interesting insights into the latest computer security news.

If this is your first time listening to the Chet Chat: episodes come out every two weeks, and usually last about a quarter of an hour.

That makes the Chet Chat podcast ideal for your daily commute or for a spot of lunchtime listening.

(You can keep up with our podcasts via RSS or iTunes, and catch up on previous Chet Chats and other Sophos podcasts by browsing our podcast archive.)

• Microsoft Skype. Is it really a privacy nightmare that Microsoft is extracting URLs from Skype instant messages to scan for dodgy links? Can we reasonably infer from this that Redmond must be listening to our calls as well?

• The IP Commission Report. A US think tank published a report which seems to suggest that we should go after pirates by locking your computer and forcing you to contact law enforcement to get the password. Legalised ransomware? Is that really what the report said? And, even if it did, is that such a bad idea?

• Small business cybersecurity. A UK survey claims that only 36% of small businesses patch regularly. Should we be surprised? Does it matter? What about the 17% that the survey says don't patch (or concern themselves with cybersecurity) at all?

• CSAWs. Cybersecurity Awareness Weeks are a good idea. But what should those of us who already care about cybersecurity do by way of participating?

• The AusCERT 2013 #sophospuzzle. The fastest three finishers didn't win a prize because the prize draw included all 58 finishers randomly. So Chester persuaded Duck to give them a shout out in the podcast: @pirate_security, Lee Cronin and Phil Rhea.

Don't forget: for a regular Chet Chat fix, follow us via RSS or on iTunes.

http://twitter.com/NakedSecurity

http://twitter.com/duckblog

Image of small business crushed by foot courtesy of Shutterstock.

Tags: #sophospuzzle, chet chat, CSAW, ip commission, Patching, Podcast, ransomware, skype, Small Business, sscc, surveillance


View the original article here

Sunday, May 26, 2013

High-rolling gambler uses casino's own surveillance system to scoop $32 million...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A high-rolling gambler has allegedly won $32 million at a casino in Melbourne, Australia, thanks to a little network hackery carried out by accomplices.

Games like poker are much easier to win if you know some or all of your opponents' cards.

After all, it's hard to sustain a bluff if the person you're bluffing has actually seen your hand.

In this case, the un-named "whale" - casino argot for a player who wagers large amounts of money, often on giant-sized individual bets - is said to have relied on his accomplices to feed him information about what other players at his table were holding.

His accomplices were able to snoop on the other players because they had remote access to the casino's own surveillance system, giving them a bird's eye view from CCTV cameras right inside the high-rollers' room.

The $32 million was apparently scooped in the course of eight big-stakes hands.

To increase their chance of catching cheaters (and thereby, no doubt, to discourage gamblers from trying to cheat in the first place), casinos typically have substantial networks of cameras giving high-quality, real-time video feeds.

So, this is an excellent reminder that the modern trend towards "big data" - where you hoover up as much information as possible, in as much detail as you can manage, about as many of your customers as you can - cuts both ways.

"Big data" can not only help to uncover patterns that expose fraud and criminality, but also end up enabling it.

(Why would you needs a miniature camera cunningly mounted on an ATM to skim PINs from unsuspecting users, if you could just hack into a shopping mall's CCTV system and let someone else's camera do the work?)

By the way, do you have video surveillance in your workplace?

If so, how well do you protect your own CCTV network, which may very well include proprietary software and equipment, from prying eyes?

It's not just your employees' privacy that's at stake, but possibly also (as the Melbourne casino found out) the financial health of your business...

Follow @duckblog


View the original article here