Showing posts with label surveillance. Show all posts
Showing posts with label surveillance. Show all posts

Monday, March 21, 2016

Clinton email reveals: Google sought overthrow of Syria's Assad

Washington Examiner | By RUDY TAKALA | March 19, 2016



Google in 2012 sought to help insurgents overthrow Syrian President Bashar Assad, according to State Department emails receiving fresh scrutiny this week.


Messages between former secretary of state Hillary Clinton's team and one of the company's executives detailed the plan for Google to get involved in the region.

"Please keep close hold, but my team is planning to launch a tool ... that will publicly track and map the defections in Syria and which parts of the government they are coming from," Jared Cohen, the head of what was then the company's "Google Ideas" division, wrote in a July 2012 email to several top Clinton officials.

"Our logic behind this is that while many people are tracking the atrocities, nobody is visually representing and mapping the defections, which we believe are important in encouraging more to defect and giving confidence to the opposition," Cohen said, adding that the plan was for Google to surreptitiously give the tool to Middle Eastern media.

"Given how hard it is to get information into Syria right now, we are partnering with Al-Jazeera who will take primary ownership over the tool we have built, track the data, verify it, and broadcast it back into Syria," he said.

"Please keep this very close hold and let me know if there is anything [else] you think we need to account for or think about before we launch. We believe this can have an important impact," Cohen concluded.

The message was addressed to deputy secretary of state Bill Burns; Alec Ross, a senior Clinton advisor; and Clinton's deputy chief of staff, Jake Sullivan. Sullivan subsequently forwarded Cohen's proposal to Clinton, describing it as "a pretty cool idea."

Cohen worked as a low-level staffer at the State Department until 2010, when he was hired to lead Google Ideas, but was tied to the use of social media to incite social uprisings even before he left the department. He once reportedly asked Twitter CEO Jack Dorsey to hold off of conducting system maintenance that officials believed could have impeded a brief 2009 uprising in Iran.

The unusual involvement by Google in foreign affairs highlights the difficulty of involvement in the internal politics of foreign states. While Cohen seemed to consider his company's effort as helpful to American interests, the effort to overthrow Assad helped spur the rise of the Islamic State, which eventually filled a vacuum resulting from Assad's loss of control over of Syria.

The exchange on Syria was highlighted by Wikileaks on Saturday. Earlier in the week, the secret-leaking website posted more than 30,000 emails that Clinton sent or received during her tenure leading the State Department.

Tuesday, February 9, 2016

US intelligence chief: we might use the internet of things to spy on you

The GuardianSpencer Ackerman and Sam Thielman | 9 February 2016 16.51 EST




The US intelligence chief has acknowledged for the first time that agencies might use a new generation of smart household devices to increase their surveillance capabilities.



As increasing numbers of devices connect to the internet and to one another, the so-called internet of things promises consumers increased convenience – the remotely operated thermostat from Google-owned Nest is a leading example. But as home computing migrates away from the laptop, the tablet and the smartphone, experts warn that the security features on the coming wave of automobiles, dishwashers and alarm systems lag far behind.

The government just admitted it will use smart home devices for spying.

In an appearance at a Washington thinktank last month, the director of the National Security Agency, Adm Michael Rogers, said that it was time to consider making the home devices “more defensible”, but did not address the opportunities that increased numbers and even categories of connected devices provide to his surveillance agency.

However, James Clapper, the US director of national intelligence, was more direct in testimony submitted to the Senate on Tuesday as part of an assessment of threats facing the United States.

“In the future, intelligence services might use the [internet of things] for identification, surveillance, monitoring, location tracking, and targeting for recruitment, or to gain access to networks or user credentials,” Clapper said.

Clapper did not specifically name any intelligence agency as involved in household-device surveillance. But security experts examining the internet of things take as a given that the US and other surveillance services will intercept the signals the newly networked devices emit, much as they do with those from cellphones. Amateurs are already interested in easily compromised hardware; computer programmer John Matherly’s search engine Shodan indexes thousands of completely unsecured web-connected devices.

Online threats again topped the intelligence chief’s list of “worldwide threats” the US faces, with the mutating threat of low-intensity terrorism quickly following. While Clapper has for years used the equivocal term “evolving” when asked about the scope of the threat, he said Tuesday that Sunni violent extremism “has more groups, members, and safe havens than at any other point in history”.


The Islamic State topped the threat index, but Clapper also warned that the US-backed Saudi war in Yemen was redounding to the benefit of al-Qaida’s local affiliate.

Domestically, “homegrown extremists” are the greatest terrorist threat, rather than Islamic State or al-Qaida attacks planned from overseas. Clapper cited the San Bernardino and Chattanooga shootings as examples of lethal operations emanating from self-starting extremists “without direct guidance from [Isis] leadership”.

US intelligence officials did not foresee Isis suffering significant setbacks in 2016 despite a war in Syria and Iraq that the Pentagon has pledged to escalate. The chief of defense intelligence, Marine Lt Gen Vincent Stewart, said the jihadist army would “probably retain Sunni Arab urban centers” in 2016, even as military leaders pledged to wrest the key cities of Raqqa and Mosul from it.

Contradicting the US defense secretary, Ashton Carter, Stewart said he was “less optimistic in the near term about Mosul”, saying the US and Iraqi government would “certainly not” retake it in 2016.

The negative outlook comes as Carter traveled on Tuesday to meet with his fellow defense chiefs in Brussels for a discussion on increasing their contributions against Isis.

On the Iran nuclear deal, Clapper said intelligence agencies were in a “distrust and verify mode”, but added: “We have no evidence thus far that they’re moving toward violation.”

Clapper’s admission about the surveillance potential for networked home devices is rare for a US official. But in an overlooked 2012 speech, the then CIA director David Petraeus called the surveillance implications of the internet of things “transformational … particularly to their effect on clandestine tradecraft”.

During testimony to both the Senate armed services committee and the intelligence panel, Clapper cited Russia, China, Iran, North Korea and the Islamic State as bolstering their online espionage, disinformation, theft, propaganda and data-destruction capabilities. He warned that the US’s ability to correctly attribute the culprits of those actions would probably diminish with “improving offensive tradecraft, the use of proxies, and the creation of cover organizations”.

Clapper suggested that US adversaries had overtaken its online capabilities: “Russia and China continue to have the most sophisticated cyber programs.”

The White House’s new cybersecurity initiative, unveiled on Tuesday, pledged increased security for nontraditional networked home devices. It tasked the Department of Homeland Security to “test and certify networked devices within the ‘Internet of Things’.” It did not discuss any tension between the US’s twin cybersecurity and surveillance priorities.

Connected household devices are a potential treasure trove to intelligence agencies seeking unobtrusive ways to listen and watch a target, according to a study that Harvard’s Berkman Center for Internet and Society released last week. The study found that the signals explosion represented by the internet of things would overwhelm any privacy benefits by users of commercial encryption – even as Clapper in his testimony again alleged that the growth of encryption was having a “negative effect on intelligence gathering”.

The report’s authors cited a 2001 case in which the FBI had sought to compel a company that makes emergency communications hardware for automobiles – similar by description to OnStar, though the company was not named – to assist agents in Nevada in listening in on conversations in a client’s car.

In February 2015, news reports revealed that microphones on Samsung “smart” televisions were “always on” so as to receive any audio that it could interpret as an instruction.

“Law enforcement or intelligence agencies may start to seek orders compelling Samsung, Google, Mattel, Nest or vendors of other networked devices to push an update or flip a digital switch to intercept the ambient communications of a target,” the authors wrote.

Thursday, February 4, 2016

U.S. eyes ways to toughen fight against domestic extremists

Reuters | By Julia Harte, Julia Edwards and Andy Sullivan | February 4, 2016
Department of Justice


WASHINGTON (Reuters) - The U.S. Justice Department is considering legal changes to combat what it sees as a rising threat from domestic anti-government extremists, senior officials told Reuters, even as it steps up efforts to stop Islamic State-inspired attacks at home.

Extremist groups motivated by a range of U.S.-born philosophies present a "clear and present danger," John Carlin, the Justice Department's chief of national security, told Reuters in an interview. “Based on recent reports and the cases we are seeing, it seems like we’re in a heightened environment.”

Over the past year, the Justice Department has brought charges against domestic extremist suspects accused of attempting to bomb U.S. military bases, kill police officers and fire bomb a school and other buildings in a predominantly Muslim town in New York state.

But federal prosecutors tackling domestic extremists still lack an important legal tool they have used extensively in dozens of prosecutions against Islamic State-inspired suspects: a law that prohibits supporting designated terrorist groups.

Carlin and other Justice Department officials declined to say if they would ask Congress for a comparable domestic extremist statute, or comment on what other changes they might pursue to toughen the fight against anti-government extremists.

The U.S. State Department designates international terrorist organizations to which it is illegal to provide "material support." No domestic groups have that designation, helping to create a disparity in charges faced by international extremist suspects compared to domestic ones.

A Reuters analysis of more than 100 federal cases found that domestic terrorism suspects collectively have faced less severe charges than those accused of acting on behalf of Islamic State since prosecutors began targeting that group in early 2014.

Over the past two years, 27 defendants have been charged with plotting or inciting attacks within the United States in the name of Islamic State. They have faced charges that carried a median prison sentence of 53 years - half of the defendants faced more, and half faced less.

In the same period, 27 adherents of U.S.-based anti-government ideologies have been charged with similar activity. They faced charges that carried a median prison sentence of 20 years.

Carlin said his counter-terrorism team, including a recently hired counsel, is taking a “thoughtful look at the nature and scope of the domestic terrorism threat” and helping to analyze “potential legal improvements and enhancements to better combat those threats.”

The counsel, who was appointed last October and has not been named publicly, will identify cases being prosecuted at the state level that “could arguably meet the federal definition of domestic terrorism," a Justice Department official said.

That would give the department a direct role in more domestic extremism cases.

Recognizing that domestic threats were “rapidly evolving, and had the potential to grow,” the department in March 2015 rated disrupting such terrorists as a key component of its broader counter-terrorism efforts, officials said.

THE THREAT PENDULUM


The Justice Department aggressively pursued domestic extremists after Timothy McVeigh bombed a federal building in Oklahoma City in 1995, killing 168 people.

The government shifted its focus to international terrorism after al Qaeda killed nearly 3,000 Americans on Sept. 11, 2001.

But in recent years anti-government activists, like those who occupied a wildlife preserve in eastern Oregon last month, have regained prominence.

As law enforcement experts confront domestic militia groups, "sovereign citizens" who do not recognize government authority, and other anti-government extremists, they also face a heightened threat from Islamic extremists like the couple who carried out the Dec. 2 shootings in San Bernardino, California.

"A new development we're seeing is that when it comes to ISIL investigations, the flash-to-bang time from radicalization to action appears to be happening faster than with other types of terrorists," said Michael Steinbach, the head of the FBI’s Counterterrorism Division.

As a result, government agents are quick to investigate people who appear sympathetic toward Islamic State, current and former officials say. But some say the government has been overzealous in its pursuit of Islamic State suspects.

Similar actions by extremist suspects have yielded sharply disparate sentences.

Eight Islamic State-related defendants have been sentenced so far, to prison terms that range from three to 20 years, the Reuters review found. Over the same period, 18 domestic extremists have been sentenced to terms from one day to 12 years.

Prosecutors say Harlem Suarez, 23, of Key West, Florida, tried to buy a bomb last year from an undercover FBI agent as he plotted attacks on behalf of Islamic State. He faces a possible sentence of life in prison and has pleaded not guilty.

Michael Sibley, 67, left two unexploded pipe bombs and a Koran in a park in Roswell, Georgia in 2014 in what he later told police was an attempt to highlight the danger of Islamic terrorism. He pleaded guilty and faces a maximum of five years in prison.

"A different standard is being applied to Muslims than to other people," said Daryl Johnson, a former counterterrorism expert at the Department of Homeland Security who now works as a law enforcement consultant.

"SPRING-LOADED"


Steinbach said that the FBI can never open up any type of investigation “just on the basis of race, creed, or religion,”

But he added that federal agents are "spring-loaded" to open investigations into Americans who support groups on the State Department list of designated terrorist organizations.

The maximum penalty for supporting one of these groups has been raised from 10 years to 20 years in prison since 2001.

It has been applied in 58 of the government's 79 Islamic State cases since 2014 against defendants who engaged in a wide range of activity, from traveling to Syria to fight alongside Islamic State to raising money for a friend who wished to do so.

Judges usually issue sentences below the maximum, but some charges trigger sentencing "enhancements" that raise the baseline sentence a judge can issue – and the material support charge raises it more than most.

Domestic groups enjoy greater constitutional protections because being a member of those groups, no matter how extreme their rhetoric, is not a crime.

Prosecutors can bring “material support” terrorism charges against defendants who aren't linked to groups on the State Department's list, but they have only done so twice against non-jihadist suspects since the law was enacted in 1994. The law, which prohibits supporting people who have been deemed to be terrorists by their actions, carries a maximum sentence of 15 years in prison.

Current and former federal prosecutors say they rarely consider that statute in domestic terrorism cases because it is often hard to convince a jury that someone who is not affiliated with a foreign group can be guilty of terrorism.

William Wilmoth, a former federal prosecutor who invoked that law in a 1996 case against a West Virginia militia member, said he was surprised to hear that it isn't used more often.

"These guys have every right to have off-center political views," he said. "But when they made affirmative steps to blow up an actual federal facility... we thought it was an important place for us to go and prosecute."



(Reporting by Julia Harte, Julia Edwards and Andy Sullivan; editing by Stuart Grudgings)

Monday, February 1, 2016

New Technologies Give Government Ample Means to Track Suspects, Study Finds

NY Times | By DAVID E. SANGER | JAN. 31, 2016

The F.B.I. director, James B. Comey, and other Justice Department officials have said moves by technology firms to encrypt data have choked off critical ways to monitor suspects. Credit: Kevin hagen for The New York Times


WASHINGTON — For more than two years the F.B.I. and intelligence agencies have warned that encrypted communications are creating a “going dark” crisis that will keep them from tracking terrorists and kidnappers.

Now, a study in which current and former intelligence officials participated concludes that the warning is wildly overblown, and that a raft of new technologies — like television sets with microphones and web-connected cars — are creating ample opportunities for the government to track suspects, many of them worrying.


“ ‘Going dark’ does not aptly describe the long-term landscape for government surveillance,” concludes the study, to be published Monday by the Berkman Center for Internet and Society at Harvard.

The study argues that the phrase ignores the flood of new technologies “being packed with sensors and wireless connectivity” that are expected to become the subject of court orders and subpoenas, and are already the target of the National Security Agency as it places “implants” into networks around the world to monitor communications abroad.

The products, ranging from “toasters to bedsheets, light bulbs, cameras, toothbrushes, door locks, cars, watches and other wearables,” will give the government increasing opportunities to track suspects and in many cases reconstruct communications and meetings.

The study, titled, “Don’t Panic: Making Progress on the ‘Going Dark’ Debate,” is among the sharpest counterpoints yet to the contentions of James B. Comey, the F.B.I. director, and other Justice Department officials, mostly by arguing that they have defined the issue too narrowly.

Over the past year, they have repeatedly told Congress that the move byApple to automatically encrypt data on its iPhone, and similar steps by Google and Microsoft, are choking off critical abilities to track suspects, even with a court order.

President Obama, however, concluded last fall that any effort to legislate a government “back door” into encrypted communications would probably create a pathway for hackers — including those working for foreign governments like Russia, China and Iran — to gain access as well, and create a precedent for authoritarian governments demanding similar access.

Most Republican candidates for president have demanded that technology companies create a way for investigators to unlock encrypted communications, and on the Democratic side, Hillary Clinton has taken a tough line on Silicon Valley companies, urging them to join the fight against the Islamic State.

Apple’s chief executive, Timothy D. Cook, has led the charge on the other side. He recently told a group of White House officials seeking technology companies’ voluntary help to counter the Islamic State that the government’s efforts to get the keys to encrypted communications would be a boon for hackers and put legitimate business transactions, financial data and personal communications at greater risk.

The Harvard study, funded by the Hewlett Foundation, was unusual because it involved technical experts, civil libertarians and officials who are, or have been, on the forefront of counterterrorism. Larry Kramer, the former dean of Stanford Law School, who heads the foundation, noted Friday that until now “the policy debate has been impeded by gaps in trust — chasms, really — between academia, civil society, the private sector and the intelligence community” that have impeded the evolution of a “safe, open and resilient Internet.”

Among the chief authors of the report is Matthew G. Olsen, who was a director of the National Counterterrorism Center under Mr. Obama and a general counsel of the National Security Agency.

Two current senior officials of the N.S.A. — John DeLong, the head of the agency’s Commercial Solutions Center, and Anne Neuberger, the agency’s chief risk officer — are described in the report as “core members” of the group, but did not sign the report because they could not act on behalf of the agency or the United States government in endorsing its conclusions, government officials said.

“Encryption is a real problem, and the F.B.I. and intelligence agencies are right to raise it,” Mr. Olsen said Sunday. But he noted that in their testimony officials had not described the other technological breaks that are falling their way, nor had they highlighted cases in which they were able to exploit mistakes made by suspects in applying encryption to their messages.

Jonathan Zittrain, a professor of law and computer science at Harvard who convened the group, said in an interview that the goal was “to have a discussion among people with very different points of view” that would move “the state of the debate beyond its well-known bumper stickers. We managed to do that in part by thinking of a larger picture, specifically in the unexpected ways that surveillance might be attempted.”

He noted that in the current stalemate there was little discussion of the “ever-expanding ‘Internet of things,’ where telemetry from teakettles, televisions and light bulbs might prove surprisingly, and worryingly, amenable to subpoena from governments around the world.”

Those technologies are already being exploited: The government frequently seeks location data from devices like cellphones and EZ Passes to track suspects.

The study notes that such opportunities are expanding rapidly. A Samsung “smart” television contains a microphone meant to relay back to Samsung voice instructions to the TV — “I want to see the last three ‘Star Wars’ movies” — and a Hello, Barbie brought out by Mattel last year records children’s conversations with the doll, processes them over the Internet and sends back a response.

The history of technology shows that what is invented for convenience can soon become a target of surveillance. “Law enforcement or intelligence agencies may start to seek orders compelling Samsung, Google, Mattel, Nest or vendors of other networked devices to push an update or flip a digital switch to intercept the ambient communications of a target,” the report said.

These communications, too, may one day be encrypted. But Google’s business model depends on picking out key words from emails to tailor advertisements for specific users of Gmail, the popular email service. Apple users routinely back up the contents of their phones to iCloud — a service that is not encrypted and now is almost a routine target for investigators or intelligence agencies. So are the tracking and mapping systems for cars that rely on transmitted global positioning data.

“I think what this report shows is that the world today is like living in a big field that is more illuminated than ever before,” said Joseph Nye, a Harvard government professor and former head of the National Intelligence Council. “There will be dark spots — there always will be. But it’s easy to forget that there is far more data available to governments now than ever before.”

Wednesday, January 27, 2016

DHS WANTS BETTER SOCIAL MEDIA SCREENING TECHNOLOGY

Nextgov | By Mohana Ravindranath | January 26, 2016

IMAGE CREDITS: Pixelkult

The Department of Homeland Security wants businesses to present their cutting-edge social media analytics services next month -- especially technology that could enhance criminal investigations, traveler screenings and situational awareness.

In a new request for information, DHS said it is looking for open source analytics tools that can make internal operations more efficient and reduce costs through "advanced analytic automation,” across the department, all while using “privacy, civil rights and civil liberties-protecting analytic methods.”

Respondents have until Feb. 9 to submit descriptions of their analytics capabilities, including geospatial processing, foreign and spoken language processing, and keyword, image and video analysis, among other elements.

DHS plans to ask 30 “exemplars of social media analytics capabilities in the market place” to present technology that could help analysts find patterns “in the context of homeland security investigative, screening and/or homeland security mission related situation awareness missions.”

Those groups will be asked to present on Feb. 26, the RFI said.

The solicitation also asked respondents to describe the way they “protect the privacy, civil rights and civil liberties of individuals involved in open source and social media communications,” including factors such as data removal methods, “role based access to information, user audit, system logging, policy enforcing mechanisms, encryption, etc.”

The announcement comes weeks after federal social media screening policies came under fire, especially in light of the San Bernardino shootings, when it was widely reported that one of the shooters had posted public pro-ISIS messages on Facebook. (Federal Bureau of Investigation director James Comey subsequently said those were private, direct communications.)

DHS policies in particular were criticized last month when Congress blasted the department for not examining immigrants' social media accounts closely and routinely when granting visas, The Hill reported.

DHS officials said they do occasionally look at social media accounts, according to The Hill. But a DHS memo obtained by MSNBC last month found that the department had rejected a policy to screen foreign visa applicants’ social media accounts in 2011, after a year of revisions.

According to a spokesperson, DHS does not comment on open solicitations and declined Nextgov's request for comment.

Tuesday, January 26, 2016

Terrifying IoT Search Engine Lets You Spy On Strangers' Webcams

Vocativ | By Jennings Brown and Adi Cohen on Jan 25, 2016 at 3:27 PM

PSA: Create strong passwords (Not actual footage from a web cam) (Getty Images)

Think of the millions of devices with video feeds—maybe the baby monitor perched over your kid’s crib or a security camera looking out over your back porch. A new feature on the most popular search engine for the Internet of Things just made it a lot easier to find such feeds. And it’s even creepier than you can imagine.

Shodan is a website that scans the internet for publicly accessible devices and captures their IP addresses—creating a searchable index that includes everything from in-home surveillance cameras to traffic lights to fetal heart monitors to power switches for hospitals. Essentially any of the so-called Internet of Things that doesn’t have a password is up for grabs, and that’s more devices than you’d think.

Programmer John Matherly developed the site in 2009 when he was a teenager, and he originally thought his pet project would help large tech companies see who was using their devices. But now the site is mostly used by hackers and researchers. Until recently, Shodan was used almost exclusively within the cybersecurity community, because searches require a general understanding of technical language. But a new feature has made it easier for anyone to peek people’s home surveillance devices. The new channel includes screen grabs of security camera feeds along with their location.

As Ars Technica reports, these webcams show feeds from sensitive locations like schools, banks, marijuana plantations, labs and babies’ rooms. Shodan members who pay the $49 monthly fee can search the full feed at images.shodan.io. A Vocativ search of some of the most recently added images shows offices, school, porches and the interior of people’s homes. Accompanying each of these grabs is a pinned map that shows the location of the device capturing that footage.


The site also offers free memberships that allow anyone to search through thousands of webcams. Most of these devices require a password to view the feed (Shodan users have written a few articles about the most-used passwords so that others can easily hack feeds), but unfortunately many people don’t set up password authentication on their devices. Such cameras are easily accessed through Shodan, and many of them can even be controlled by Shodan users.

Moments after setting up a free account, we were able to access and maneuver several security cameras, moving them from left to right and up to down within homes, businesses and a room holding adorable Pomeranian puppies. Shodan also provided the general location where each of these live feeds were coming from, which means it would not be difficult to track down those puppies and figure out when their owner is away.

So, if you value your puppies or personal privacy, set up a password on all your connected devices.