Google Search

Friday, November 8, 2013

Using Tor and other means to hide your location piques NSA's interest in you

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Keyhole. Image courtesy of ShutterstockPresident Barack Obama and top intelligence officials have emphasized that surveillance now being referred to as PRISM is done under court oversight.

Just what, exactly, that court oversight has entailed has never been elucidated - not, that is, until Thursday, when The Guardian published top-secret documents submitted to the secret Foreign Intelligence Surveillance (FISA) court.

Those documents show that FISA judges have signed off on "broad orders" that allow the National Security Agency (NSA) to use information collected "inadvertently" from domestic US sources without a warrant, The Guardian reports.

The Guardian published in full these two documents, which describe the procedures used by the NSA to target its surveillance:

Both documents were signed by Attorney General Eric Holder and dated 29 July 2009.

In a speech delivered on Wednesday in Germany, President Obama called the surveillance "a circumscribed, narrow system" whose aim is to protect "our people", all of it being done "under the oversight of the courts."

In spite of such assurances, it turns out that the FISA courts allow for much broader surveillance and much more leeway for mistakes than the public has known up until now.

The documents detail when data collected on US persons under the foreign intelligence authority has to be destroyed, the procedures analysts must follow to ascertain whether targets are outside the US, and how US call records are used to help remove US citizens and residents from data collection.

From The Guardian, a list of how policies approved by the FISA court allow NSA agents to:

Keep data that could potentially contain details of US persons for up to five years;Retain and make use of "inadvertently acquired" domestic communications if they contain usable intelligence, information on criminal activity, threat of harm to people or property, are encrypted, or are believed to contain any information relevant to cybersecurity;Preserve "foreign intelligence information" contained within attorney-client communications;Access the content of communications gathered from "U.S. based machine[s]" or phone numbers in order to establish if targets are located in the US, for the purposes of ceasing further surveillance.

One of the most jarring revelations to come out of the documents is that the administration's assurances of US citizens' protection from warrantless surveillance seems to have plenty of footnotes and exceptions that haven't been publicly disclosed until now.

They also reveal that courts don't always determine who's targeted for surveillance because that discretion is practiced by the NSA's own analysts, with only a percentage of decisions being reviewed by regular internal audits.

To make those decisions, NSA analysts use information including IP addresses, potential targets' statements, and public information and data collected by other agencies.

Tor logoIn the absence of such information - for example, if a potential target is using online anonymity services such as Tor, or sending encrypted email and instant messages - agents are encouraged to assume that the target is outside the US.

From the documents:

"In the absence of specific information regarding whether a target is a United States person, a person reasonably believed to be located outside the United States or whose location is not known will be presumed to be a non-United States person unless such person can be positively identified as a United States person."

If it turns out that a person of interest is actually in the US, analysts are still permitted to look at the content of his or her messages, or listen to phone calls, to establish whether they are, in fact, in the country.

In 2009, Holder signed off on procedures that instructed communications interception to stop immediately once a target is confirmed to be in the US.

But that excludes large-scale data, from which the NSA claims it can't filter out US vs. non-US communications.

The NSA is allowed to argue for the retention of entirely domestic communications - i.e., when neither of the parties is overseas - if it finds "significant foreign intelligence information", "evidence of a crime", "technical database information" (such as encrypted communications), or "information pertaining to a threat of serious harm to life or property".

If communication is encrypted - particularly if a US person is using certain types of cryptology or steganography known to have been used by "individuals associated with a foreign power or foreign territory” - the NSA is free to collect it and store it "indefinitely" for future reference and cryptanalysis attempts.

The American Civil Liberties Union (ACLU) put out a statement on Thursday criticizing the government's warrantless surveillance "of innocent Americans' international communications."

Jameel Jaffer, American Civil Liberties Union deputy legal director, said that the latest revelations confirm the fears that first arose when Congress enacted FISA in 2008:

"We worried that the NSA would use the new authority to conduct warrantless surveillance of Americans' telephone calls and emails. These documents confirm many of our worst fears. The 'targeting' procedures indicate that the NSA is engaged in broad surveillance of Americans' international communications.

"The 'minimization' procedures that supposedly protect Americans' constitutional rights turn out to be far weaker than we imagined they could be. For example, the NSA claims the authority to collect and disseminate attorney-client communications - and even, in some circumstances, to turn them over to Justice Department prosecutors. The government also claims the authority to retain Americans' purely domestic communications in certain situations."

ACLU Staff Attorney Alex Abdo said:

"Collectively, these documents show indisputably that the legal framework under which the NSA operates is far too feeble, that existing oversight mechanisms are ineffective, and that the government's surveillance policies now present a serious and ongoing threat to our constitutional rights. The release of these documents will help inform a crucial public debate that should have taken place years ago."

Keyhole. Image courtesy of ShutterstockThe so-called PRISM surveillance saga, far from slipping from public view, has, in fact, fueled a debate that had already begun to produce fruit, including Texas' newly enacted law against warrantless surveillance at the state level.

Meanwhile, efforts are already underway in both houses of Congress to revise the woefully antiquated Electronic Communications Privacy Act, which was written in 1986, well before the current realities of cloud storage and other technologies transformed how we use electronic communications.

The debate is, indeed, overdue, and the public deserves to be informed of every aspect possible, short of compromising national security.

Read The Guardian's reporting on the issue. It's far more extensive than what I've summarized here.

A heartfelt thank you to the news outlet for continuing to follow the story to whatever new revelations it may yet have in store.

Follow @LisaVaas
Follow @NakedSecurity

Image of keyhole and private courtesy of Shutterstock.


View the original article here

Thursday, November 7, 2013

LinkedIn unhacked, Microsoft bounties, Java in your browser - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's that time again - time for this week's 60 Second Security, our fun-but-serious "security news with a conscience" video series.

Watch the latest security news in just 60 seconds! [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Apple, applet, bounty, browser, crack, DDoS, dictionary, Erlangen, Exploit, ios, iPad, iPhone, Java, linkedin, Microsoft, network solutions, Oracle, outage, passwords, rce, update, vulnerability, Wi-fi, Window 8.1 Preview, Windows 8.1


View the original article here

Tuesday, November 5, 2013

Calling out China on hacking may be working, experts say

SINGAPORE After years of quiet and largely unsuccessful diplomacy, the U.S. has brought its persistent computer-hacking problems with China into the open, delivering a steady drumbeat of reports accusing Beijing's government and military of computer-based attacks against America.

Officials say the new strategy may be having some impact.

In recent private meetings with U.S. officials, Chinese leaders have moved past their once-intractable denials of cyber espionage and are acknowledging there is a problem. And while there have been no actual admissions of guilt, officials say the Chinese seem more open to trying to work with the U.S. to address the problems.

"By going public the administration has made a lot of progress," said James Lewis, a cybersecurity expert at the Center for Strategic and International Studies who has met with Chinese leaders on cyber issues.

Play Video

Play Video

But it will likely be a long and bumpy road, as any number of regional disputes and tensions could suddenly stir dissent and stall progress.

On Wednesday, China's Internet security chief told state media that Beijing has amassed large amounts of data about U.S.-based hacking attacks against China but refrains from blaming the White House or the Pentagon because it would be irresponsible.

The state-run English-language China Daily reported that Huang Chengqing, director of the government's Internet emergency response agency, said Beijing and Washington should cooperate rather than confront each other in the fight against cyberattacks. Huang also called for mutual trust.

President Barack Obama is expected to bring up the issue when he meets with China's new president, Xi Jinping, in Southern California later this week. The officials from the two nations have agreed to meet and discuss the issue in a new working group that Secretary of State John Kerry announced in April. Obama's Cabinet members and staff have been laying the groundwork for those discussions.

Standing on the stage at the Shangri-La Dialogue security conference last weekend, Defense Secretary Chuck Hagel became the latest U.S. official to openly accuse the Chinese government of cyber espionage - as members of Beijing's delegation sat in the audience in front of him. The U.S., he said, "has expressed our concerns about the growing threat of cyber intrusions, some of which appear to be tied to the Chinese government and military."

But speaking to reporters traveling with him to the meeting in this island nation in China's backyard, Hagel said it's important to use both public diplomacy and private engagements when dealing with other nations such as China on cyber problems.

"I've rarely seen that public engagement resolves a problem, but it's important," he said, adding that governments have the responsibility to keep their people informed about such issues.

The hacking issue also featured prominently over two days of meetings between the U.S. Chamber of Commerce and a leading Chinese trade think tank in Beijing.

"This is arguably the single most consequential issue that is serving to erode trust in the relationship," said Jeremie Waterman, the chamber's executive director for greater China. "Over time, it could undermine business support for U.S.-China relations."

According to Lewis and other defense officials familiar with the issue, China's willingness to engage in talks with the U.S. about the problem - even without admitting to some of the breaches - is a step in the right direction.

Cybersecurity experts say China-based instances of cyber intrusions into U.S. agencies and programs - including defense contractors and military weapons systems - have been going on since the late 1990s. And they went along largely unfettered for as much as a decade.

A recent Pentagon report compiled by the Defense Science Board laid out what it called a partial list of 37 programs that were breached in computer-based attacks, including the Terminal High Altitude Area Defense weapon, a land-based missile defense system that was recently deployed to Guam to help counter the North Korean threat. Other programs whose systems were breached include the F-35 Joint Strike Fighter, the F-22 Raptor fighter jet and the hybrid MV-22 Osprey, which can take off and land like a helicopter and fly like an airplane.

The report also listed 29 broader defense technologies that have been compromised, including drone video systems and high-tech avionics. The information was gathered more than two years ago, so some of the data are dated and a few of the breaches - such as the F-35 - had already become public.

According to U.S. officials and cyber experts, China hackers use gaps in software or scams that target users' email systems to infiltrate government and corporate networks. They are then often able to view or steal files or use those computers to move through the network accessing other data.

Chinese officials have long denied any role in cyberattacks and insisted that the law forbids hacking and that their military has no role in it. They have also asserted that they, too, are often the victim.

Cyber experts say some of the breaches that emanate from Internet locations in China may be the product of patriotic hackers who are not working at the behest of Beijing's government or military but in independent support of it.

The Chinese government's control of the Internet, however, suggests that those hackers are likely operating with at least the knowledge of authorities who may choose to look the other way.

U.S. officials have quietly grumbled about the problem for several years but steadfastly refused to speak publicly about it. As the intrusions grew in number and sophistication, affecting an increasing number of government agencies, private companies and citizens, alarmed authorities began to rethink that strategy.

They were pressed on by cybersecurity experts - including prominent former government officials - who argued that using cyberattacks to steal intellectual property, weapons and financial data and other corporate secrets brought great gain at very little cost to the hackers. The U.S. government, they said, had to make it clear to the Chinese that continued bad behavior would trigger consequences.

In November 2011, U.S. intelligence officials for the first time publicly accused China and Russia of systematically stealing American high-tech data for economic gain.

That was followed by specific warnings about Chinese cyberattacks in the last two annual Pentagon reports on China's military power. And in February, the Virginia-based cybersecurity firm Mandiant laid out a detailed report directly linking a secret Chinese military unit in Shanghai to years of cyberattacks against U.S. companies. After analyzing breaches that compromised more than 140 companies, Mandiant concluded that they can be linked to a unit that experts believe is part of the People's Liberation Army's cyber command.

The change in tone from the Chinese leaders came through during recent meetings with Gen. Martin Dempsey, chairman of the Joint Chiefs of Staff, and has continued, according to officials and experts familiar with more recent discussions with Chinese leaders.

Still, experts say that progress with the Chinese will still be slow and that it's naive to think the cyberattacks will stop.

"This will take continuous pressure for a number of years," said Lewis. "We will need both carrots and sticks, and the question is when do you use them."


View the original article here

Monday, November 4, 2013

Official describes rampant computer hacking at VA - Quincy Herald-Whig | Illinois & Missouri News, Sports

By KEVIN FREKING
Associated Press

WASHINGTON (AP) - At least eight foreign-sponsored organizations, mostly connected to the Chinese military, have hacked into computer networks at the Veterans Affairs Department in recent years or were actively trying to do so, a former VA computer security chief told Congress on Tuesday.

Jerry Davis, who served as the VA's chief information security officer until February 2013, testified at a House subcommittee hearing that the VA became aware of the computer hacking in March 2010 and that attacks continue "to this very day."

Davis said the hacking "successfully compromised VA networks and data," but he did not indicate to lawmakers how the information may have been used. The intrusions raise the potential for identity theft and could complicate efforts to share data with the Pentagon, long viewed as key to quicker processing of disability claims.

"The entire veteran database in VA, containing personally identifiable information on roughly 20 million veterans, is not encrypted, and evidence suggests that it has repeatedly been compromised since 2010 by foreign actors, including in China and possibly in Russia," said Rep. Mike Coffman, R-Colo., chairman of the House Veterans' Affairs oversight and investigations subcommittee.

Officials with the VA's inspector general's office said the main threat to veterans would appear to be credit card theft. They could not point to any specific instances in which such fraud has occurred because of foreign agents. While foreign hackers had obtained access to the emails of senior VA managers, investigators did not know what had been done with the emails.

Davis, who now works at NASA, singled out China's military as responsible for hackings at the VA. In talking to a reporter after the hearing, he said 6 of the eight foreign-sponsored organizations he spoke of during the hearing were connected in some way to the People's Liberation Army. Davis said the data the foreign hackers accessed included such things as Social Security numbers and dates of birth. He said officials know that some information was encrypted and removed from the VA's computers. Officials should assume that if such information was accessed, then it went out as well.

When asked by a reporter if the information removed included such things as Social Security numbers, he replied "it's the safe bet."

Linda Halliday, an assistant inspector general, said investigators were seeing fewer weaknesses with the VA's computer security, but she told lawmakers that 4,000 weaknesses and vulnerabilities have not been addressed. She cited weak passwords and user accounts with inappropriate access as among the most common problems.

Stephen Warren, acting assistant secretary for information and technology at the VA, said the state of computer security at the VA was something he wrestled with continually, but the inspector general's citation of security threats dealt with what could go wrong. He said that's not the same as the removal of information from the VA's computers.

"We're talking about potential. We're not talking about actuals," Warren said in describing the computer security problem at the VA.

Warren told lawmakers he disagreed with Coffman's assessment that the VA's computer systems had been compromised repeatedly by foreign entities. He said he knew of only one such instance. He declined to cite which country that involved, saying he would prefer to discuss it in a closed session.

At another point in the hearing, Warren said he was aware of more than one foreign entity that had attempted to hack into the VA's systems. He said such attacks go beyond foreign governments, but through crime syndicates seeking financial gain.

Copyright 2013 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


View the original article here

Saturday, November 2, 2013

Former VA official tells lawmakers of state-sponsored computer hacking at VA

WASHINGTON - At least eight foreign-sponsored organizations have hacked into computer networks at the Veterans Affairs Department in recent years or were actively trying to do so, a former VA computer security chief told Congress on Tuesday.

Jerry Davis, who served as the VA's chief information security officer until February 2013, said in written testimony to a House subcommittee that the VA became aware of the computer hacking in March 2010 and that attacks continue "to this very day."

Davis said the hacking "successfully compromised VA networks and data," but he did not indicate how the information may have been used. The intrusions raise the potential for identity theft and could complicate efforts to share data with the Pentagon, long viewed as key to quicker processing of disability claims.

"The entire veteran database in VA, containing personally identifiable information on roughly 20 million veterans, is not encrypted, and evidence suggests that it has repeatedly been compromised since 2010 by foreign actors, including in China and possibly in Russia," said Rep. Mike Coffman, R-Colo., chairman of the House Veterans' Affairs oversight and investigations subcommittee.

Officials with the VA's inspector general's office said the main threat to veterans would appear to be credit card theft. They also could not point to any specific instances in which such fraud has occurred. Investigators also said hackers had obtained access to the emails of senior VA managers, but did not know what had been done with the emails.

Linda Halliday, an assistant inspector general, said investigators were seeing fewer weaknesses with the VA's computer security, but she told lawmakers that 4,000 weaknesses and vulnerabilities have not been addressed. She cited weak passwords and user accounts with inappropriate access as among the most common problems.

Stephen Warren, acting assistant secretary for information and technology at the VA, said the state of computer security at the VA was something he wrestled with continually, but the inspector general's citation of security threats dealt with what could go wrong. He said that's not the same as the removal of information from the VA's computers.

"We're talking about potential. We're not talking about actuals," Warren said in describing the computer security problem at the VA.

Warren told the hearing he disagreed with Coffman's assessment that the VA's computer systems had been compromised repeatedly by foreign entities. He said he knew of only one such instance. He declined to cite which country that involved, saying he would prefer to discuss it in a closed session.

At another point in the hearing, Warren said he was aware of more than one foreign entity that had attempted to hack into the VA's systems. He said such attacks go beyond foreign governments, but through crime syndicates seeking financial gain.


View the original article here

Friday, November 1, 2013

Child porn sentence for Wickford hacker

Child porn sentence for Wickford hacker (From Echo) Jump to main content News Sport Weather forecast

Mobile site E-Newsletters News feed Find us on Twitter@Essex_Echo

Follow us

Find us on FacebookEcho

Like us on Facebook

Site map Register Log in EchoChild porn sentence for Wickford hacker (From Echo)

Get involved: send your pictures, video, news and views by texting ECHONEWS to 80360, or email us »

Search: NewsSportLeisureLocal InfoEventsAnnouncementsPublic NoticesJobs with usAdvertiseClick2findBuy & SellDatingCarsHomesJobsLocal NewsNationalVideoLettersTopicsArchive Echo » News » News RSS Feed Send your news, pictures & videos Child porn sentence for Wickford hacker 8:13am Wednesday 12th June 2013 in News

Ryan Cleary Ryan Cleary

A member of the computer hacking group LulzSec is due to be sentenced today for possessing indecent images relating to extreme child pornography.

Ryan Cleary, 21, of Wickford, known as ViraL, appeared in court last month where he admitted hacking and launching cyber attacks on a range of organisations including the CIA and the Serious Organised Crime Agency as part of his work with the "hacktivist" group.

He was jailed for a total of two years and eight months.

But Cleary, who has Asperger's, also admitted possessing indecent images relating to extreme child pornography, which were found on his hard drive.

He is due to be sentenced for this at London's Southwark Crown Court today.

His barrister, John Cooper QC, told the court in May how Cleary is a ''totally obsessed, compulsive individual'' who became fixated with computers after being sent to boarding school aged 11.

By the time of his arrest he was ''reclusive'', living in his bedroom.

Cleary is not ''a career sexual pervert'', Mr Cooper said, linking the 172 indecent images, downloaded in one session, to his Asperger's and computer obsession.

Fellow LulzSec members Ryan Ackroyd, Jake Davis and Mustafa Al-Bassam were handed various sentences last month for their roles in the hacking.

Email Print this page Email Print this page click2find Block list Jobs

Search for hundreds of jobs in Essex and beyond

Search Now »

Dating

Bring love into your life! Find a date in Essex

Search Now »

Homes

Homes for sale, and to let, in Essex

Search Now »

Cars

New and used cars in Essex and across the UK

Search Now »

NewsSportLeisureLocal InfoEventsAnnouncementsPublic NoticesJobs with usAdvertiseClick2findBuy & SellDatingCarsHomesJobs Cookie Policy Contact Us Subscribe Photo Sales Advertise AdChoices AdChoices Archive Topics Announcements Site Map Exchange and Mart Twos Company Dating Terms & Conditions Privacy Policy © Copyright 2001-2013
This site is part of Newsquest's audited local newspaper network A Gannett Company

Newsquest (Essex) Ltd, 58 Church Street, Weybridge, Surrey. KT13 8DP|3102787|Registered in England & Wales

About cookies

We want you to enjoy your visit to our website. That's why we use cookies to enhance your experience. By staying on our website you agree to our use of cookies. Find out more about the cookies we use.

I agree

View the original article here

CBS Confirms Hacking Of Reporter Sharyl Attkisson’s Computer

CBS News confirms hacking of Sharyl Attkisson computer

CBS News has officially confirmed that Sharyl Attkission’s computer was hacked by an as-yet unknown intruder.

Back in May, the Emmy-winning reporter explained that her home and work computers were breached perhaps as a result of her work as an investigative journalist. At that time, during an interview on a Philadelphia radio station, Sharyl Attkisson said that “There’s definitely been an intrusion into my computer system… I really can’t say more than that right now.”

This was of course was way before the NSA PRISM massive domestic surveillance program was leaked by NSA contractor Edward Snowden.

With regard to the James Rosen/Fox News and Associated Press surveillance by the Justice Department, Attkisson added that “there could be some relationship between these types of things and what’s happened to me.”

Attkisson is one of the few mainstream media reporters that covered the Fast and Furious scandal, a botched Obama administration operation that allowed firearms to fall into the hands of drug cartels. These same weapons have been linked to the murder of Border Patrol agent Brian Terry and many others. She’s also been digging into the Benghazi scandal.

In that May radio interview, Attkisson explained that something fishy may have been going on since February 2011 (or even before) when she was covering Fast and Furious and also reported on stories about the taxpayer money spent on failed green energy initiatives “that the [Obama] administration was very sensitive about.”

In a statement released this morning, CBS News confirmed the Attkisson data breach: “A cyber security firm hired by CBS News has determined through forensic analysis that Sharyl Attkisson’s computer was accessed by an unauthorized, external, unknown party on multiple occasions late in 2012. Evidence suggests this party performed all access remotely using Attkisson’s accounts. While no malicious code was found, forensic analysis revealed an intruder had executed commands that appeared to involve search and exfiltration of data. This party also used sophisticated methods to remove all possible indications of unauthorized activity, and alter system times to cause further confusion. CBS News is taking steps to identify the responsible party and their method of access.”

Do you think there is connection between the Attkisson computer hacking and the federal government’s NSA PRISM program?

[Image credit: Honeyplant]

Category: PoliticsTags: CBS News, CBS News reporter hacked, hacking, journalist, journalists, news reporter, NSA, NSA PRISM, Sharyl Attkisson, Sharyl Attkisson computers, Sharyl Attkisson hackedPosted: June 14, 2013Love It? jQuery(function(){ jQuery('#hp-oh-wrapper').masonry({ // options itemSelector : 'article', columnWidth : 256, isAnimated: !Modernizr.csstransitions });});dmn.asyncLoad('http://connect.facebook.net/en_US/all.js');window.fbAsyncInit = function() {FB.init({appId: 164157850314499, status: true, cookie: true, xfbml: true, channelUrl: 'http://www.inquisitr.com/channel.html'});FB.getLoginStatus(function(response){dmn.FB.setUpFb();dmn.FB.queueRead();});};

Clicky


View the original article here