Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, February 17, 2016

FBI Prompts Apple to Issue Privacy Letter to Customers After San Bernadino Shooter Request

Apple | February 17, 2016



A Message to Our Customers


The United States government has demanded that Apple take an unprecedented step which threatens the security of our customers. We oppose this order, which has implications far beyond the legal case at hand.

This moment calls for public discussion, and we want our customers and people around the country to understand what is at stake.

The Need for Encryption


Smartphones, led by iPhone, have become an essential part of our lives. People use them to store an incredible amount of personal information, from our private conversations to our photos, our music, our notes, our calendars and contacts, our financial information and health data, even where we have been and where we are going.

All that information needs to be protected from hackers and criminals who want to access it, steal it, and use it without our knowledge or permission. Customers expect Apple and other technology companies to do everything in our power to protect their personal information, and at Apple we are deeply committed to safeguarding their data.

Compromising the security of our personal information can ultimately put our personal safety at risk. That is why encryption has become so important to all of us.

For many years, we have used encryption to protect our customers’ personal data because we believe it’s the only way to keep their information safe. We have even put that data out of our own reach, because we believe the contents of your iPhone are none of our business.

The San Bernardino Case


We were shocked and outraged by the deadly act of terrorism in San Bernardino last December. We mourn the loss of life and want justice for all those whose lives were affected. The FBI asked us for help in the days following the attack, and we have worked hard to support the government’s efforts to solve this horrible crime. We have no sympathy for terrorists.

When the FBI has requested data that’s in our possession, we have provided it. Apple complies with valid subpoenas and search warrants, as we have in the San Bernardino case. We have also made Apple engineers available to advise the FBI, and we’ve offered our best ideas on a number of investigative options at their disposal.

We have great respect for the professionals at the FBI, and we believe their intentions are good. Up to this point, we have done everything that is both within our power and within the law to help them. But now the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create. They have asked us to build a backdoor to the iPhone.

Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which does not exist today — would have the potential to unlock any iPhone in someone’s physical possession.

The FBI may use different words to describe this tool, but make no mistake: Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control.

The Threat to Data Security


Some would argue that building a backdoor for just one iPhone is a simple, clean-cut solution. But it ignores both the basics of digital security and the significance of what the government is demanding in this case.

In today’s digital world, the “key” to an encrypted system is a piece of information that unlocks the data, and it is only as secure as the protections around it. Once the information is known, or a way to bypass the code is revealed, the encryption can be defeated by anyone with that knowledge.

The government suggests this tool could only be used once, on one phone. But that’s simply not true. Once created, the technique could be used over and over again, on any number of devices. In the physical world, it would be the equivalent of a master key, capable of opening hundreds of millions of locks — from restaurants and banks to stores and homes. No reasonable person would find that acceptable.

The government is asking Apple to hack our own users and undermine decades of security advancements that protect our customers — including tens of millions of American citizens — from sophisticated hackers and cybercriminals. The same engineers who built strong encryption into the iPhone to protect our users would, ironically, be ordered to weaken those protections and make our users less safe.

We can find no precedent for an American company being forced to expose its customers to a greater risk of attack. For years, cryptologists and national security experts have been warning against weakening encryption. Doing so would hurt only the well-meaning and law-abiding citizens who rely on companies like Apple to protect their data. Criminals and bad actors will still encrypt, using tools that are readily available to them.

A Dangerous Precedent


Rather than asking for legislative action through Congress, the FBI is proposing an unprecedented use of the All Writs Act of 1789 to justify an expansion of its authority.

The government would have us remove security features and add new capabilities to the operating system, allowing a passcode to be input electronically. This would make it easier to unlock an iPhone by “brute force,” trying thousands or millions of combinations with the speed of a modern computer.

The implications of the government’s demands are chilling. If the government can use the All Writs Act to make it easier to unlock your iPhone, it would have the power to reach into anyone’s device to capture their data. The government could extend this breach of privacy and demand that Apple build surveillance software to intercept your messages, access your health records or financial data, track your location, or even access your phone’s microphone or camera without your knowledge.

Opposing this order is not something we take lightly. We feel we must speak up in the face of what we see as an overreach by the U.S. government.

We are challenging the FBI’s demands with the deepest respect for American democracy and a love of our country. We believe it would be in the best interest of everyone to step back and consider the implications.

While we believe the FBI’s intentions are good, it would be wrong for the government to force us to build a backdoor into our products. And ultimately, we fear that this demand would undermine the very freedoms and liberty our government is meant to protect.


Tim Cook

Friday, February 12, 2016

NYPD TRACKED CITIZENS’ CELLPHONES 1,000 TIMES SINCE 2008 WITHOUT WARRANTS

Ciara McCarthy | The Guardian - FEBRUARY 11, 2016

IMAGE CREDITS: FLICKR, 49770271@N08.

New York City police have tracked citizens’ cellphones over 1,000 times since 2008 without using warrants, according to public records obtained by the New York Civil Liberties Union.


The organization announced on Thursday that the NYPD has typically used “stingrays” after obtaining lower-level court orders, but not warrants, before using the devices. The department also does not have a policy guiding how police can use the controversial devices. This is the first time that the scope of stingray use by the nation’s largest police agency has been confirmed.

The devices, generically known as stingrays, work by mimicking cell towers and tracking a cellphone’s location at a specific time. Law enforcement agencies can use the technology to track people’s movements through their cellphone use. Stingrays can also detect the phone numbers that a person has been communicating with, according to the NYCLU. The devices allow law enforcement to bypass cellphone carriers, who have provided information to police in the past, and can track data about bystanders in close proximity to the intended target.

Mariko Hirose, the NYCLU attorney who filed the records request, said the records reveal knowledge about NYPD’s stingray use that should have been divulged before police decided to start using them.

Read more

Tuesday, February 9, 2016

US intelligence chief: we might use the internet of things to spy on you

The Guardian | Spencer Ackerman and Sam Thielman | 9 February 2016 16.51 EST




The US intelligence chief has acknowledged for the first time that agencies might use a new generation of smart household devices to increase their surveillance capabilities.



As increasing numbers of devices connect to the internet and to one another, the so-called internet of things promises consumers increased convenience – the remotely operated thermostat from Google-owned Nest is a leading example. But as home computing migrates away from the laptop, the tablet and the smartphone, experts warn that the security features on the coming wave of automobiles, dishwashers and alarm systems lag far behind.

The government just admitted it will use smart home devices for spying.

In an appearance at a Washington thinktank last month, the director of the National Security Agency, Adm Michael Rogers, said that it was time to consider making the home devices “more defensible”, but did not address the opportunities that increased numbers and even categories of connected devices provide to his surveillance agency.

However, James Clapper, the US director of national intelligence, was more direct in testimony submitted to the Senate on Tuesday as part of an assessment of threats facing the United States.

“In the future, intelligence services might use the [internet of things] for identification, surveillance, monitoring, location tracking, and targeting for recruitment, or to gain access to networks or user credentials,” Clapper said.

Clapper did not specifically name any intelligence agency as involved in household-device surveillance. But security experts examining the internet of things take as a given that the US and other surveillance services will intercept the signals the newly networked devices emit, much as they do with those from cellphones. Amateurs are already interested in easily compromised hardware; computer programmer John Matherly’s search engine Shodan indexes thousands of completely unsecured web-connected devices.

Online threats again topped the intelligence chief’s list of “worldwide threats” the US faces, with the mutating threat of low-intensity terrorism quickly following. While Clapper has for years used the equivocal term “evolving” when asked about the scope of the threat, he said Tuesday that Sunni violent extremism “has more groups, members, and safe havens than at any other point in history”.


The Islamic State topped the threat index, but Clapper also warned that the US-backed Saudi war in Yemen was redounding to the benefit of al-Qaida’s local affiliate.

Domestically, “homegrown extremists” are the greatest terrorist threat, rather than Islamic State or al-Qaida attacks planned from overseas. Clapper cited the San Bernardino and Chattanooga shootings as examples of lethal operations emanating from self-starting extremists “without direct guidance from [Isis] leadership”.

US intelligence officials did not foresee Isis suffering significant setbacks in 2016 despite a war in Syria and Iraq that the Pentagon has pledged to escalate. The chief of defense intelligence, Marine Lt Gen Vincent Stewart, said the jihadist army would “probably retain Sunni Arab urban centers” in 2016, even as military leaders pledged to wrest the key cities of Raqqa and Mosul from it.

Contradicting the US defense secretary, Ashton Carter, Stewart said he was “less optimistic in the near term about Mosul”, saying the US and Iraqi government would “certainly not” retake it in 2016.

The negative outlook comes as Carter traveled on Tuesday to meet with his fellow defense chiefs in Brussels for a discussion on increasing their contributions against Isis.

On the Iran nuclear deal, Clapper said intelligence agencies were in a “distrust and verify mode”, but added: “We have no evidence thus far that they’re moving toward violation.”

Clapper’s admission about the surveillance potential for networked home devices is rare for a US official. But in an overlooked 2012 speech, the then CIA director David Petraeus called the surveillance implications of the internet of things “transformational … particularly to their effect on clandestine tradecraft”.

During testimony to both the Senate armed services committee and the intelligence panel, Clapper cited Russia, China, Iran, North Korea and the Islamic State as bolstering their online espionage, disinformation, theft, propaganda and data-destruction capabilities. He warned that the US’s ability to correctly attribute the culprits of those actions would probably diminish with “improving offensive tradecraft, the use of proxies, and the creation of cover organizations”.

Clapper suggested that US adversaries had overtaken its online capabilities: “Russia and China continue to have the most sophisticated cyber programs.”

The White House’s new cybersecurity initiative, unveiled on Tuesday, pledged increased security for nontraditional networked home devices. It tasked the Department of Homeland Security to “test and certify networked devices within the ‘Internet of Things’.” It did not discuss any tension between the US’s twin cybersecurity and surveillance priorities.

Connected household devices are a potential treasure trove to intelligence agencies seeking unobtrusive ways to listen and watch a target, according to a study that Harvard’s Berkman Center for Internet and Society released last week. The study found that the signals explosion represented by the internet of things would overwhelm any privacy benefits by users of commercial encryption – even as Clapper in his testimony again alleged that the growth of encryption was having a “negative effect on intelligence gathering”.

The report’s authors cited a 2001 case in which the FBI had sought to compel a company that makes emergency communications hardware for automobiles – similar by description to OnStar, though the company was not named – to assist agents in Nevada in listening in on conversations in a client’s car.

In February 2015, news reports revealed that microphones on Samsung “smart” televisions were “always on” so as to receive any audio that it could interpret as an instruction.

“Law enforcement or intelligence agencies may start to seek orders compelling Samsung, Google, Mattel, Nest or vendors of other networked devices to push an update or flip a digital switch to intercept the ambient communications of a target,” the authors wrote.

Thursday, January 28, 2016

Hundreds of DHS badges, guns, cell phones lost or stolen since 2012

By Adam Shaw | Published January 27, 2016 | Fox News

Feb. 20, 2014: A U.S. Customs and Border Protection arm patch and badge is seen at Los Angeles International Airport, California. (Reuters)


Hundreds of badges, credentials, cell phones and guns belonging to Department of Homeland Security employees have been lost or stolen in recent years -- raising serious security concerns about the potential damage these missing items could do in the wrong hands.

Inventory reports, obtained by the news site Complete Colorado and shared with FoxNews.com, show that over 1,300 badges, 165 firearms and 589 cell phones were lost or stolen over the span of 31 months between 2012 and 2015.

The majority of the credentials belonged to employees of Customs and Border Protection (CBP), while others belonged to Immigration and Customs Enforcement (ICE) and U.S. Citizenship and Immigration Services (USCIS) employees.

The lost or stolen guns also mostly belonged to CBP employees, though others were cited as belonging to TSA and ICE workers. The agencies all fall under DHS.

The missing badges and guns suggest a shocking lack of security from federal law enforcement officers and represent a significant security risk, experts say.

“It’s scary that you’d have that number of credentials out there that someone could manipulate,” Tim Miller, a retired Secret Service special agent, told FoxNews.com.

While Miller said the phones are likely to have enough protocols in place to prevent them from being used for nefarious purposes, the badges and credentials are an entirely different matter and could allow access to sensitive areas such as cargo.

“The thing that’s particularly concerning is that if you get real credentials, it’s very easy to manipulate them, and you’ve got someone else’s picture on what law enforcement would see as valid," Miller said. "Then you factor in terrorism, it’s a significant concern that people would run around with authentic credentials and be able to access areas they wouldn’t otherwise be able to access.”

When reached for comment, DHS did not dispute the inventory report data -- which Complete Colorado, a Colorado-based online news site, had obtained via a Freedom of Information Act request. The reporter who obtained the data also works with Denver-based free-market think tank the Independence Institute.

In a statement to FoxNews.com, a DHS spokesman said they strive to be “good stewards of government resources” and have improved oversight and reduced the number of lost or stolen items over the past few years.

“If a credential holder loses or has their credentials stolen, the holder must report the incident to their supervisor and credential issuance office immediately,” spokesman Justin Greenberg said. “Once the incident has been reported, this information is entered into appropriate DHS and law enforcement databases, which disables use of the lost or stolen item.”

He also noted that DHS encrypts all mobile devices, laptops and tablets.

Miller said officials need to be doing more, considering the sheer number of guns and badges that have been lost or stolen.

Lawmakers also have expressed concern about the safety of DHS property in the past. In December, the Senate Commerce, Science, and Transportation Committee approved legislation that would tighten screening of TSA workers, review security protocols and increase fines and enforcement requirements related to missing credentials.

The legislation was put forward after members of the committee wrote to TSA officials in March expressing concern about reports of unaccounted TSA badges, and the reported use of badges to bypass security checkpoints.

“Officials entrusted with protecting the American public cannot consider the loss of sensitive items normal or routine," Sen. John Thune, R-S.D., chairman of the committee, told FoxNews.com.

"When the Commerce Committee looked at lost and missing airport security credentials, we discovered that existing rules weren’t being effectively enforced. Mistakes happen, but if we don’t work to eliminate them and insist on accountability, then we’re left with unacceptable risk,” Thune said.

Tuesday, January 26, 2016

Terrifying IoT Search Engine Lets You Spy On Strangers' Webcams

Vocativ | By Jennings Brown and Adi Cohen on Jan 25, 2016 at 3:27 PM

PSA: Create strong passwords (Not actual footage from a web cam) (Getty Images)

Think of the millions of devices with video feeds—maybe the baby monitor perched over your kid’s crib or a security camera looking out over your back porch. A new feature on the most popular search engine for the Internet of Things just made it a lot easier to find such feeds. And it’s even creepier than you can imagine.

Shodan is a website that scans the internet for publicly accessible devices and captures their IP addresses—creating a searchable index that includes everything from in-home surveillance cameras to traffic lights to fetal heart monitors to power switches for hospitals. Essentially any of the so-called Internet of Things that doesn’t have a password is up for grabs, and that’s more devices than you’d think.

Programmer John Matherly developed the site in 2009 when he was a teenager, and he originally thought his pet project would help large tech companies see who was using their devices. But now the site is mostly used by hackers and researchers. Until recently, Shodan was used almost exclusively within the cybersecurity community, because searches require a general understanding of technical language. But a new feature has made it easier for anyone to peek people’s home surveillance devices. The new channel includes screen grabs of security camera feeds along with their location.

As Ars Technica reports, these webcams show feeds from sensitive locations like schools, banks, marijuana plantations, labs and babies’ rooms. Shodan members who pay the $49 monthly fee can search the full feed at images.shodan.io. A Vocativ search of some of the most recently added images shows offices, school, porches and the interior of people’s homes. Accompanying each of these grabs is a pinned map that shows the location of the device capturing that footage.


The site also offers free memberships that allow anyone to search through thousands of webcams. Most of these devices require a password to view the feed (Shodan users have written a few articles about the most-used passwords so that others can easily hack feeds), but unfortunately many people don’t set up password authentication on their devices. Such cameras are easily accessed through Shodan, and many of them can even be controlled by Shodan users.

Moments after setting up a free account, we were able to access and maneuver several security cameras, moving them from left to right and up to down within homes, businesses and a room holding adorable Pomeranian puppies. Shodan also provided the general location where each of these live feeds were coming from, which means it would not be difficult to track down those puppies and figure out when their owner is away.

So, if you value your puppies or personal privacy, set up a password on all your connected devices.