Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

U.S. authorities read our e-mails

by Michael Smith (Veshengro)

on-line privacySwitzerland, February 2013: A resident of the French-speaking area of Switzerland was denied entry to the Unit ed States after a somewhat bad joke in an e-mail. He now fears that he is t he victim of "big ears" America.

The findings of the European Parliament on this in a report, even though Switzerland is not part of the EU, are unequivocal and state that this is “a serious threat" to the "rights of citizens”.

An amendment that allows U.S. authorities to monitor, in addition to communications like e-mail and telephone, all data stored in the U.S. by non-Americans.

Concerned are all synchronization services online as iCloud, Dropbox or Google Drive, and messaging services. In addition to this, it would appear, all email services that are based on US servers, such as Yahoo Mail, Google Mail, etc.

This Swiss citizen believes, probably rightfully, that he has become a victim of this “mass surveillance” enacted “without warrant” against American citizens and others.

About to go on holiday to the USA, he exchanged emails containing jokes around words such as “airplane”, “bomb” and “explode”.

While his application for a residence permit without visa (ESTA) was accepted, it was rescinded when he tried to board and he was banned from entering the United States.

Though we have no evidence of this it is more than likely that he will also find himself now on a list of people banned (for life) from entering the USA and it could even extend to flying (on any US airline).

It would not surprise me if this extends further than just the cloud services and email accounts mentioned in that the Echelon system, used by the CIA via places such as Menwith Hill (an RAF base in the UK that is wholly US military and CIA) and GCHQ, the British intelligence service monitoring station based near Cheltenham, Glos.

The Echelon system is designed to pick out key words such as the ones that have been in those emails and is used to monitor all traffic such as emails, etc., as well as voice communications.

This is about as stupid as the guy who was arrested on a plane about to depart an airport and banned from flying for saying “Hi Jack” upon recognizing a friend of his by the name of “Jack”.

The US is overstepping the line, once again, believing itself, it would appear, to be the ruler of the world and also its policeman.

About time the rest of the world told those folks there in Washington, D.C. A few home truths, namely that they may run the USA but that other countries and people are sovereign and not under their jurisdiction.

© 2013

Geo-location is potentially major security risks

by Michael Smith (Veshengro)

If you value your privacy and your security (not just your online one) then do not use geo-tagging

According to IT security and compliance specialist Cryptzone geo-location tagging security issues are likely to be a major issue in 2012 – and that many users of smartphones are unaware of the potentially serious security consequences of their use of the technology.

Most smartphones now have native GPS/satnav features, the default setting for most pictures – and videos – taken with these devices is to embed the GPS co-ordinates along with the date and time that the image was taken. This can have serious security implication for the person, and his home.

It is saying to any criminal who might know where this person lives “hi, my home is empty... come and burglarize it.”

When smartphones upload these images to the Internet – to portals such Facebook or Flickr – there is a very strong chance that they will also upload the GPS data as well. This information could be subsequently misused by third parties, perhaps for stalking purposes, for general crime and even cybercrime.

Too many users of Facebook and other such portals put too much information on to those forums but with geo-location tagging a simple picture of one's home, one's place of work, etc., immediately makes it findable on any map and via a satnav.

Since most human activities online have some kind of a location aspect, this brings both opportunities and significant risks, especially when it comes to location tagging.

Many people are too careless already by putting way too much information into their profiles, whether on Facebook, LinkedIn, MySpace, or wherever, which is one of the main reason why each and every holiday season the warning is being issued to them not to post pictures, etc., from their vacation spots.

Add geo-location tagging into that equation, and even just having the geo-location tagging used, and you have the recipe for disaster, including serious crime.

Cybercriminals are now starting to crowdsource information that is available on the Internet – using open source software such as Maltego – and then tying in geo-location data from photos.

Then you also have sites such as Youhavedownloaded.com – an open source data site – that lists the IP addresses of around 20 per cent of files that have been shared across the Internet.

So far Suren Ter-Saakov – the Russian IT expert behind this portal – claims to have crowdsourced around 50 million unique IP addresses that have file-shared all manner of music, video and software files.

And when you start to tie all this information together – related photo information, the GPS coordinates of where an image or video was taken, and the IP addresses of users – you start to assemble a pastiche of the user. From this data, you then can begin to assemble a profile of the user and what their habits are.

This is why geo-location data is potentially so dangerous, as it can be used to bolster other information that is available on the Internet, and which can readily be assembled using software like Maltego.

From there it is then a relatively easy step to perform a highly targeted phishing or similar type of attack on the individual – using information about their location, their interests and other data derived from, say, their Facebook profile.

Geo-location and -tagging brings with it many new opportunities, but there are significant and serious dangers associated with this pool of information. And no matter how many times the experts say it, this type of information is not as anonymous as you might think.

So, what do you do?

  1. You turn off geo-location tagging, whether on your smartphone or your laptop/netbook and you also do the same on Facebook, etc., where this possibility exists.

  2. You check very carefully as to what you have on information in your profiles, whether on Facebook, Blogger, Twitter, LinkedIn, or what-have-you, and make sure that you have minimum information on there only, and have the security settings, even with the minimum information, set to the highest settings.

Only the other day I have seen someone on a forum where I am a member, and – theoretically it is a members only one with the entire site hidden – where people are often rather paranoid, posting their personal telephone numbers and such. This is highly dangerous.

So, let's be careful out there and let's be careful what we “share” online.

© 2011

Microsoft about to hand source-code of Skype to Russian secret service?

By Michael Smith (Veshengro)

The Russian daily Vedomosti and the British press agency Bloomberg announced the possible cooperation of the now Microsoft-owned business, Skype, with the Russian secret service, the FSB.

It is the aim, apparently, to hand over to the FSB part of the source-code for the application and by doing so they would hand the successor to the KGB a very powerful tool to intercept Skype communications.

Microsoft is, however, denying that this would be the case. They would, wouldn't they.

So far the Voice-Over-IP-service Skype is being considered as extremely secure. It is impossible for outsiders, due to complicated algorithms, to log themselves into chats or telephone conversation and thus monitor communications.

Even governments and their agencies, including secret services, do not have, according to official sources, the possibility to decode the data that is being sent via Skype, whichever form this data may be having. Skype has, so far, got the reputation that its encryption is of the highest military grade making it impossible to wiretap the conversations.

But, if the report by the news agency Bloomberg is anything to go by then this could change soon.

Ever since the acquisition of the Skype service by Microsoft the directors of company in Redmond have become very happy to cooperate with law enforcement agencies and intelligence services. That is why Skype is intending, so Bloomberg, to hand over pats of the source-code to the FSB.

It was rather obvious that, as soon as MS was getting their mitts on Skype they were going to screw up the privacy that Skype used to provide. MS, like Mark Zuckerberg of Facebook, do not know what privacy means. Or would MS otherwise deem it to be right to snoop on your and my PC when we connect to their sites for updates and such?

Should this indeed happen as indicated by the Bloomberg report then the successor organization to the KGB might not directly be given the “master key” with which to be able to tap in to each and every Skype call or chat but with the source-code they could find back doors with which to do just that.

Redmond, however, claims that there is nothing true on the reports but they would deny such things, would they not. People would be leaving the Skype service in droves, I am sure, should that those shenanigans by Microsoft become reality and, obviously, they don't want to spook the horses as yet.

In a statement to the Blomberg agency Microsoft reiterated that there are no moves afoot to give away the source-code for Skype but, then again, no one was talking about giving the source-code away to all and sundries now.

According to the Russian daily Vedomosti has the FSB been developing good relations to and with many software giants and Skype would not be the first program which the agency would be given full access to.

Maybe this will have to also be seen in the light of some recent communications that came out of Russia where it stated that the Russian government was going to switch over to Open Source altogether including Linux and such operating systems. Is Microsoft oiling the wheels so it can keep in with the Russian government?

© 2011