Feds put heat on Web firms for master encryption keys

Found on CNet News on Thursday, 25 July 2013
Browse Internet

These demands for master encryption keys, which have not been disclosed previously, represent a technological escalation in the clandestine methods that the FBI and the National Security Agency employ when conducting electronic surveillance against Internet users.

"The government is definitely demanding SSL keys from providers," said one person who has responded to government attempts to obtain encryption keys. The source spoke with CNET on condition of anonymity.

"The requests are coming because the Internet is very rapidly changing to an encrypted model," a former Justice Department official said. "SSL has really impacted the capability of U.S. law enforcement. They're now going to the ultimate application layer provider."

Of course the Internet will change to a fully encrypted version; and guess why?

Japanese Gov't Accidentally Shares Internal Email Over Google Groups

Found on IT World on Saturday, 13 July 2013
Browse Internet

An official at Japan's Ministry of the Environment created the group to share mails and documents related to Japan's negotiations during the Minamata Convention, a meeting held in Geneva in January to create international standards to limit international mercury use. But the official used the default privacy setting, leaving the exchanges open to searches and views in the months since.

Now that is a transparent government.

Revealed: how Microsoft handed the NSA access to encrypted messages

Found on The Guardian on Thursday, 11 July 2013
Browse Internet

Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal

The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail

The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide

Remember this next time someone tells you that closed source and centralized systems are more secure. MS is working hand in hand with the NSA to provide them with the best support and easy access. This also explains why the Xbox One has a camera and was planned to be always online.

Will the NSA Controversy Drive People To Use Privacy Software?

Found on Slashdot on Saturday, 06 July 2013
Browse Internet

As the U.S. government continues to pursue former NSA contractor Edward Snowden for leaking some of the country's most sensitive intelligence secrets, the debate over federal surveillance seems to have abated somewhat — despite Snowden's stated wish for his revelations to spark transformative and wide-ranging debate, it doesn't seem as if anyone's taking to the streets to protest the NSA's reported monitoring of Americans' emails and phone-call metadata.

Despite some polling data that suggests people are concerned about their privacy, software for securing it is just not an exciting topic for most folks.

The sad truth is that the vast majority of people just won't care and forget about all this in a few weeks while the NSA et al with just keep on doing what they did.

This Student Project Could Kill Digital Ad Targeting

Found on AdAge on Friday, 05 July 2013
Browse Internet

Her creation, called "Vortex," is a browser extension that's part game, part ad-targeting disrupter that helps people turn their user profiles and the browsing information into alternate fake identities that have nothing to do with reality.

Vortex features a profile switcher that people can use and share to take on a new identity while browsing the web. "It's a way of masking your identity across networks," she said.

Vortex has security holes that could be exploited by nefarious actors, which is one reason Ms. Law refuses to release the full platform.

While the idea of messing up the profiles advertisers create is fun, it's not the best idea to randomly share cookies since they can contain sensitive information.

You can now donate to WikiLeaks with your credit card via Iceland

Found on Ars Technica on Wednesday, 03 July 2013
Browse Internet

On Wednesday, WikiLeaks announced that Valitor, its payment processor in Iceland, has resumed accepting credit card-based donations for the famed leaking site.

Less than a week after the Icelandic district court’s ruling in July 2012, WikiLeaks opened up a donations avenue through a French bank. And a new group, the Freedom of the Press Foundation, set up an online means to donate to Assange’s initiative by December 2012.

No more random blocking without legal reasons. Nice to see this decision.

New slides reveal greater detail about PRISM data collection

Found on CNet News on Sunday, 30 June 2013
Browse Internet

Slides published by The Washington Post appear to confirm that the NSA and FBI have the ability to perform real-time surveillance of e-mail and stored content.

The slides also seem to contradict denials from tech companies such as Google, Apple, Yahoo, and Microsoft about their level of participation in the program.

Microsoft was the first company to join the program in September 2007, according to one slide, followed by Yahoo about six months later and Google in early 2009, according to one of the slides.

Trust nobody. That's always the best approach. The only way to fight this massive surveillance is either to avoid the Internet and phone networks, or to use strong encryption. We've seen that officials and companies will lie to you, so even if they promise a change nobody can trust them. You need to take your privacy into your own hands and an essential key is easy to use encryption. So easy that even your grandmother can use it. In fact, everybody needs to use it so that there is as much encrypted data as possible. If only a few enthusiasts use it their data can be stored for later; but if there is too much data to handle it will become useless.

Encryption Has Foiled Wiretaps for First Time Ever, Feds Say

Found on Wired on Saturday, 29 June 2013
Browse Internet

For the first time, encryption is thwarting government surveillance efforts through court-approved wiretaps, U.S. officials said today.

Consider that, when federal law enforcement officials were clamoring for legislation authorizing a backdoor into most all electronic communication methods during the President Bill Clinton administration, FBI Director Louis Freeh told Congress in 1997, “all of law enforcement is also in total agreement on one aspect of encryption. The widespread use of uncrackable encryption will devastate our ability to fight crime and prevent terrorism.”

Sweet. Now encryption needs to be so simple that even your grandma can use it.

GCHQ taps fibre-optic cables for secret access to world's communications

Found on The Guardian on Saturday, 22 June 2013
Browse Internet

Britain's spy agency GCHQ has secretly gained access to the network of cables which carry the world's phone calls and internet traffic and has started to process vast streams of sensitive personal information which it is sharing with its American partner, the National Security Agency (NSA).

The documents reveal that by last year GCHQ was handling 600m "telephone events" each day, had tapped more than 200 fibre-optic cables and was able to process data from at least 46 of them at a time.

The source with knowledge of intelligence said on Friday the companies were obliged to co-operate in this operation. They are forbidden from revealing the existence of warrants compelling them to allow GCHQ access to the cables.

This get more and more ugly. It feels like a house that's infested with cockroaches and everytime a little light hits the floor they hurry to hide in the shadows again.

Street View: Google given 35 days to delete wi-fi data

Found on BBC News on Friday, 21 June 2013
Browse Internet

Google has been given 35 days to delete any remaining data it "mistakenly collected" while taking pictures for its Street View service, or face criminal proceedings.

Google had previously pledged to destroy all data it had collected, but admitted last year that it had "accidentally" retained the additional discs.

"People will rightly look at the UK's approach to this issue and ask why, given regulators in the US and Germany have fined Google for exactly the same infringement, it is being allowed to escape with a slap on the wrist in Britain."

There are quite a lot accidents and mistakes happening at Googleplex. One wonders how Google managed to succeed with all those errors.