Google Search

Showing posts with label using. Show all posts
Showing posts with label using. Show all posts

Friday, November 8, 2013

Using Tor and other means to hide your location piques NSA's interest in you

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Keyhole. Image courtesy of ShutterstockPresident Barack Obama and top intelligence officials have emphasized that surveillance now being referred to as PRISM is done under court oversight.

Just what, exactly, that court oversight has entailed has never been elucidated - not, that is, until Thursday, when The Guardian published top-secret documents submitted to the secret Foreign Intelligence Surveillance (FISA) court.

Those documents show that FISA judges have signed off on "broad orders" that allow the National Security Agency (NSA) to use information collected "inadvertently" from domestic US sources without a warrant, The Guardian reports.

The Guardian published in full these two documents, which describe the procedures used by the NSA to target its surveillance:

Both documents were signed by Attorney General Eric Holder and dated 29 July 2009.

In a speech delivered on Wednesday in Germany, President Obama called the surveillance "a circumscribed, narrow system" whose aim is to protect "our people", all of it being done "under the oversight of the courts."

In spite of such assurances, it turns out that the FISA courts allow for much broader surveillance and much more leeway for mistakes than the public has known up until now.

The documents detail when data collected on US persons under the foreign intelligence authority has to be destroyed, the procedures analysts must follow to ascertain whether targets are outside the US, and how US call records are used to help remove US citizens and residents from data collection.

From The Guardian, a list of how policies approved by the FISA court allow NSA agents to:

Keep data that could potentially contain details of US persons for up to five years;Retain and make use of "inadvertently acquired" domestic communications if they contain usable intelligence, information on criminal activity, threat of harm to people or property, are encrypted, or are believed to contain any information relevant to cybersecurity;Preserve "foreign intelligence information" contained within attorney-client communications;Access the content of communications gathered from "U.S. based machine[s]" or phone numbers in order to establish if targets are located in the US, for the purposes of ceasing further surveillance.

One of the most jarring revelations to come out of the documents is that the administration's assurances of US citizens' protection from warrantless surveillance seems to have plenty of footnotes and exceptions that haven't been publicly disclosed until now.

They also reveal that courts don't always determine who's targeted for surveillance because that discretion is practiced by the NSA's own analysts, with only a percentage of decisions being reviewed by regular internal audits.

To make those decisions, NSA analysts use information including IP addresses, potential targets' statements, and public information and data collected by other agencies.

Tor logoIn the absence of such information - for example, if a potential target is using online anonymity services such as Tor, or sending encrypted email and instant messages - agents are encouraged to assume that the target is outside the US.

From the documents:

"In the absence of specific information regarding whether a target is a United States person, a person reasonably believed to be located outside the United States or whose location is not known will be presumed to be a non-United States person unless such person can be positively identified as a United States person."

If it turns out that a person of interest is actually in the US, analysts are still permitted to look at the content of his or her messages, or listen to phone calls, to establish whether they are, in fact, in the country.

In 2009, Holder signed off on procedures that instructed communications interception to stop immediately once a target is confirmed to be in the US.

But that excludes large-scale data, from which the NSA claims it can't filter out US vs. non-US communications.

The NSA is allowed to argue for the retention of entirely domestic communications - i.e., when neither of the parties is overseas - if it finds "significant foreign intelligence information", "evidence of a crime", "technical database information" (such as encrypted communications), or "information pertaining to a threat of serious harm to life or property".

If communication is encrypted - particularly if a US person is using certain types of cryptology or steganography known to have been used by "individuals associated with a foreign power or foreign territory” - the NSA is free to collect it and store it "indefinitely" for future reference and cryptanalysis attempts.

The American Civil Liberties Union (ACLU) put out a statement on Thursday criticizing the government's warrantless surveillance "of innocent Americans' international communications."

Jameel Jaffer, American Civil Liberties Union deputy legal director, said that the latest revelations confirm the fears that first arose when Congress enacted FISA in 2008:

"We worried that the NSA would use the new authority to conduct warrantless surveillance of Americans' telephone calls and emails. These documents confirm many of our worst fears. The 'targeting' procedures indicate that the NSA is engaged in broad surveillance of Americans' international communications.

"The 'minimization' procedures that supposedly protect Americans' constitutional rights turn out to be far weaker than we imagined they could be. For example, the NSA claims the authority to collect and disseminate attorney-client communications - and even, in some circumstances, to turn them over to Justice Department prosecutors. The government also claims the authority to retain Americans' purely domestic communications in certain situations."

ACLU Staff Attorney Alex Abdo said:

"Collectively, these documents show indisputably that the legal framework under which the NSA operates is far too feeble, that existing oversight mechanisms are ineffective, and that the government's surveillance policies now present a serious and ongoing threat to our constitutional rights. The release of these documents will help inform a crucial public debate that should have taken place years ago."

Keyhole. Image courtesy of ShutterstockThe so-called PRISM surveillance saga, far from slipping from public view, has, in fact, fueled a debate that had already begun to produce fruit, including Texas' newly enacted law against warrantless surveillance at the state level.

Meanwhile, efforts are already underway in both houses of Congress to revise the woefully antiquated Electronic Communications Privacy Act, which was written in 1986, well before the current realities of cloud storage and other technologies transformed how we use electronic communications.

The debate is, indeed, overdue, and the public deserves to be informed of every aspect possible, short of compromising national security.

Read The Guardian's reporting on the issue. It's far more extensive than what I've summarized here.

A heartfelt thank you to the news outlet for continuing to follow the story to whatever new revelations it may yet have in store.

Follow @LisaVaas
Follow @NakedSecurity

Image of keyhole and private courtesy of Shutterstock.


View the original article here

Wednesday, November 7, 2012

Skype worm spreads, using LOL trick to infect unwary users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SkypeSkype users are warned to be on their guard, regarding malicious instant messages that have been sent through the service, designed to infect Windows computers.

A malicious worm is taking advantage of the Skype API to spam out messages similar to the one below:

lol is this your new profile pic? http://goo.gl/[REDACTED]?img=[USERNAME]

Clicking on the suspicious links leads to the download of a ZIP files (variously called skype_06102012_image.zip or skype_08102012_image.zip) that contains executable files detected by Sophos anti-virus products as Troj/Agent-YCW or Troj/Agent-YDC.

The Trojan horse opens a backdoor, allowing a remote hacker to take control of infected PCs, communicating with a remote server via HTTP.

On execution the malware copies itself to

%PROFILE%\Application Data\Jqfsfb.exe

and sets the autostart entry as below:

entry_location = "HKCU\Software\Microsoft\Windows\CurrentVersion\Run"entry = "Jqfsfb"description = "Skype "publisher = "Skype Technologies S.A."image = "c:\documents and settings\support\application data\jqfsfb.exe"launch_string = "C:\Documents and Settings\support\Application Data\Jqfsfb.exe"

Before you know it, your computer has been recruited into a botnet (the malware is a variant of the Dorkbot worm) and could fall victim to a ransomware attack.

There have been many variants of the Dorkbot attack spotted over the least year or so, spreading via Facebook and Twitter. The threat can also spread via USB sticks, and various instant messaging protocols.

The danger is, of course, that Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users.

Always remember to be suspicious of unsolicited out-of-character messages sent to you by your online friends.

You don't know that it was a friend who sent you the message, all you know is that it was their account which posted it to you... and who knows if it was compromised or not?

Follow @gcluley

Thanks to Anna and Julie at SophosLabs for their assistance with this article.


View the original article here

Monday, June 25, 2012

Gmail accounts targeted by 'state-sponsored attackers' using Internet Explorer zero-day vulnerability

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

IE and GmailBoth Google and Microsoft have put out alerts about an unpatched, zero-day hole in Internet Explorer that didn't get fixed on Patch Tuesday and is actively being exploited in the wild.

According to ZDNet, those attacks are apparently being launched by the "state-sponsored attackers" that Google warned Gmail users about last week.

Neither Google nor Microsoft referred to those state attackers in their respective security warnings. ZDNet attributed that particular detail to a source it said was "close to these investigations".

This source confirmed to ZDNet that the attacks motivated Google to warn Gmail users last week about the attackers.

As ZDNet pointed out, Gmail users have been reporting on Twitter that they've been hit by the Gmail warning.

Google security engineer Andrew Lyons wrote in the company's security blog that Google reported the vulnerability to Microsoft on May 30 and that the two companies have been working on the problem since.

He wrote on Tuesday:

Today Microsoft issued a Security Advisory describing a vulnerability in the Microsoft XML component. We discovered this vulnerability - which is leveraged via an uninitialized variable - being actively exploited in the wild for targeted attacks.

Lyons said that the attacks are spreading both from malicious web pages set up to snare Internet Explorer users and through Office documents.

Users running any flavor of supported Windows are vulnerable, from XP onwards up to and including Windows 7. All supported editions of Microsoft Office 2003 and Microsoft Office 2007 are also vulnerable.

The hole hasn't been stitched up yet, but Microsoft is suggesting a workaround that will help prevent it from being exploited.

Microsoft Fix itMicrosoft's security advisory recommends that IE and Office users immediately install a Fix it solution, downloadable with instructions from Microsoft Knowledge Base Article 2719615, until the company gets the final fix out.

The vulnerability crops up when Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 try to access an object in memory that hasn't been initialized, which can corrupt memory such that an attacker could execute arbitrary code on a hijacked machine.

A victim would have to visit a maliciously crafted site using IE to suffer an attack. An attacker might lure users into visiting a boobytrapped site by enticing them to click on a link in an email or via messaging.

A successful attack grants the intruder the same user rights as the logged-on user. Therefore, a mitigating factor is to configure accounts with fewer rights, as opposed to operating with administrative user rights.

Microsoft noted that by default, IE on Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2 runs in a restricted mode known as Enhanced Security Configuration. That also mitigates the vulnerability.

As far as bolting down Gmail goes, Sophos's Graham Cluley has a collection of tips on how to stop your Gmail account from getting hacked.

Gmail login screenIt's definitely worth a read. Here's a quick cheat-sheet; Graham gives you more detail on these items in his article:

OK, that last one's not a tip, per se, but it's food for thought if you are, in fact, important enough that a state would want to attack your Gmail account.

If you are, think twice about using a free web email provider for sensitive information. If you're working for the government or the military, like Graham said, put all that sensitive information on secure systems instead.

Follow @LisaVaas
Hairy spider image, courtesy of Shutterstock.

Tags: 2719615, gmail, Google, IE, Internet Explorer, Microsoft, Microsoft XML Core Services, Office, security advisory, state-sponsored attackers, Windows, XML Core Services, Zero Day


View the original article here