Skip to main content

Home/ Socialism and the End of the American Dream/ Group items tagged Web

Rss Feed Group items tagged

Paul Merrell

Obama Promises Disappear from Web - Sunlight Foundation Blog - 1 views

  • Change.gov, the website created by the Obama transition team in 2008, has effectively disappeared sometime over the last month. While the front splash page for Change.gov has linked to the main White House website for years, until recently, you could still continue on to see the materials and agenda laid out by the administration. This was a particularly helpful resource for those looking to compare Obama's performance in office against his vision for reform, laid out in detail on Change.gov. According to the Internet Archive, the last time that content (beyond the splash page) was available was June 8th -- last month.
  • Here's one possibility, from the administration's ethics agenda: Protect Whistleblowers: Often the best source of information about waste, fraud, and abuse in government is an existing government employee committed to public integrity and willing to speak out. Such acts of courage and patriotism, which can sometimes save lives and often save taxpayer dollars, should be encouraged rather than stifled. We need to empower federal employees as watchdogs of wrongdoing and partners in performance. Barack Obama will strengthen whistleblower laws to protect federal workers who expose waste, fraud, and abuse of authority in government. Obama will ensure that federal agencies expedite the process for reviewing whistleblower claims and whistleblowers have full access to courts and due process.
Paul Merrell

DARPA seeks the Holy Grail of search engines - 0 views

  • The scientists at DARPA say the current methods of searching the Internet for all manner of information just won't cut it in the future. Today the agency announced a program that would aim to totally revamp Internet search and "revolutionize the discovery, organization and presentation of search results." Specifically, the goal of DARPA's Memex program is to develop software that will enable domain-specific indexing of public web content and domain-specific search capabilities. According to the agency the technologies developed in the program will also provide the mechanisms for content discovery, information extraction, information retrieval, user collaboration, and other areas needed to address distributed aggregation, analysis, and presentation of web content.
  • Memex also aims to produce search results that are more immediately useful to specific domains and tasks, and to improve the ability of military, government and commercial enterprises to find and organize mission-critical publically available information on the Internet. "The current one-size-fits-all approach to indexing and search of web content limits use to the business case of web-scale commercial providers," the agency stated. 
  • The Memex program will address the need to move beyond a largely manual process of searching for exact text in a centralized index, including overcoming shortcomings such as: Limited scope and richness of indexed content, which may not include relevant components of the deep web such as temporary pages, pages behind forms, etc.; an impoverished index, which may not include shared content across pages, normalized content, automatic annotations, content aggregation, analysis, etc. Basic search interfaces, where every session is independent, there is no collaboration or history beyond the search term, and nearly exact text input is required; standard practice for interacting with the majority of web content, which remains one-at-a-time manual queries that return federated lists of results. Memex would ultimately apply to any public domain content; initially, DARPA  said it intends to develop Memex to address a key Defense Department mission: fighting human trafficking. Human trafficking is a factor in many types of military, law enforcement and intelligence investigations and has a significant web presence to attract customers. The use of forums, chats, advertisements, job postings, hidden services, etc., continues to enable a growing industry of modern slavery. An index curated for the counter-trafficking domain, along with configurable interfaces for search and analysis, would enable new opportunities to uncover and defeat trafficking enterprises.
  • ...1 more annotation...
  • DARPA said the Memex program gets its name and inspiration from a hypothetical device described in "As We May Think," a 1945 article for The Atlantic Monthly written by Vannevar Bush, director of the U.S. Office of Scientific Research and Development (OSRD) during World War II. Envisioned as an analog computer to supplement human memory, the memex (a combination of "memory" and "index") would store and automatically cross-reference all of the user's books, records and other information. This cross-referencing, which Bush called associative indexing, would enable users to quickly and flexibly search huge amounts of information and more efficiently gain insights from it. The memex presaged and encouraged scientists and engineers to create hypertext, the Internet, personal computers, online encyclopedias and other major IT advances of the last seven decades, DARPA stated.
  •  
    DoD announces that they want to go beyond Google. Lots more detail in the proposal description linked from the article. Interesting tidbits: [i] the dark web is a specific target; [ii] they want the ability to crawl web pages blocked by robots.txt; [iii] they want to be able to search page source code and comments. 
Paul Merrell

ExposeFacts - For Whistleblowers, Journalism and Democracy - 0 views

  • Launched by the Institute for Public Accuracy in June 2014, ExposeFacts.org represents a new approach for encouraging whistleblowers to disclose information that citizens need to make truly informed decisions in a democracy. From the outset, our message is clear: “Whistleblowers Welcome at ExposeFacts.org.” ExposeFacts aims to shed light on concealed activities that are relevant to human rights, corporate malfeasance, the environment, civil liberties and war. At a time when key provisions of the First, Fourth and Fifth Amendments are under assault, we are standing up for a free press, privacy, transparency and due process as we seek to reveal official information—whether governmental or corporate—that the public has a right to know. While no software can provide an ironclad guarantee of confidentiality, ExposeFacts—assisted by the Freedom of the Press Foundation and its “SecureDrop” whistleblower submission system—is utilizing the latest technology on behalf of anonymity for anyone submitting materials via the ExposeFacts.org website. As journalists we are committed to the goal of protecting the identity of every source who wishes to remain anonymous.
  • The seasoned editorial board of ExposeFacts will be assessing all the submitted material and, when deemed appropriate, will arrange for journalistic release of information. In exercising its judgment, the editorial board is able to call on the expertise of the ExposeFacts advisory board, which includes more than 40 journalists, whistleblowers, former U.S. government officials and others with wide-ranging expertise. We are proud that Pentagon Papers whistleblower Daniel Ellsberg was the first person to become a member of the ExposeFacts advisory board. The icon below links to a SecureDrop implementation for ExposeFacts overseen by the Freedom of the Press Foundation and is only accessible using the Tor browser. As the Freedom of the Press Foundation notes, no one can guarantee 100 percent security, but this provides a “significantly more secure environment for sources to get information than exists through normal digital channels, but there are always risks.” ExposeFacts follows all guidelines as recommended by Freedom of the Press Foundation, and whistleblowers should too; the SecureDrop onion URL should only be accessed with the Tor browser — and, for added security, be running the Tails operating system. Whistleblowers should not log-in to SecureDrop from a home or office Internet connection, but rather from public wifi, preferably one you do not frequent. Whistleblowers should keep to a minimum interacting with whistleblowing-related websites unless they are using such secure software.
    • Gary Edwards
       
      Thanks Paul! Great article and I agree with you about switching. Rather than a USB, I would rather look into a SSD and try to isolate performance to an ISP bandwidth issue. FYI, I read your Diigo posts daily at this Web site: https://groups.diigo.com/group/socialism-and-the-end-of-the-american-dream/content/user/marbux Seems to be the best visual presentation of your research. I do however think Diigo could improve their hosting of this research by enabling more extensive comments. Notice that your comments are often clipped :( Still, I really do appreciate your sharing both your research and your commentary. Priceless stuff! Many thanks! ~ge~
  •  
    A new resource site for whistle-blowers. somewhat in the tradition of Wikileaks, but designed for encrypted communications between whistleblowers and journalists.  This one has an impressive board of advisors that includes several names I know and tend to trust, among them former whistle-blowers Daniel Ellsberg, Ray McGovern, Thomas Drake, William Binney, and Ann Wright. Leaked records can only be dropped from a web browser running the Tor anonymizer software and uses the SecureDrop system originally developed by Aaron Schwartz. They strongly recommend using the Tails secure operating system that can be installed to a thumb drive and leaves no tracks on the host machine. https://tails.boum.org/index.en.html Curious, I downloaded Tails and installed it to a virtual machine. It's a heavily customized version of Debian. It has a very nice Gnome desktop and blocks any attempt to connect to an external network by means other than installed software that demands encrypted communications. For example, web sites can only be viewed via the Tor anonymizing proxy network. It does take longer for web pages to load because they are moving over a chain of proxies, but even so it's faster than pages loaded in the dial-up modem days, even for web pages that are loaded with graphics, javascript, and other cruft. E.g., about 2 seconds for New York Times pages. All cookies are treated by default as session cookies so disappear when you close the page or the browser. I love my Linux Mint desktop, but I am thinking hard about switching that box to Tails. I've been looking for methods to send a lot more encrypted stuff down the pipe for NSA to store. Tails looks to make that not only easy, but unavoidable. From what I've gathered so far, if you want to install more software on Tails, it takes about an hour to create a customized version and then update your Tails installation from a new ISO file. Tails has a wonderful odor of having been designed for secure computing. Current
Paul Merrell

China Steps In as World's New Bank - Bloomberg View - 0 views

  • Thanks to China, Christine Lagarde of the International Monetary Fund, Jim Yong Kim of the World Bank and Takehiko Nakao of the Asian Development Bank may no longer have much meaningful work to do. Beijing's move to bail out Russia, on top of its recent aid for Venezuela and Argentina, signals the death of the post-war Bretton Woods world. It’s also marks the beginning of the end for America's linchpin role in the global economy and Japan's influence in Asia. What is China's new Asian Infrastructure Investment Bank if not an ADB killer? If Japan, ADB's main benefactor, won't share the presidency with Asian peers, Beijing will just use its deep pockets to overpower it. Lagarde's and Kim’s shops also are looking at a future in which crisis-wracked governments call Beijing before Washington. 
  • China stepping up its role as lender of last resort upends an economic development game that's been decades in the making. The IMF, World Bank and ADB are bloated, change-adverse institutions.  When Ukraine received a $17 billion IMF-led bailout this year it was about shoring up a geopolitically important economy, not geopolitical blackmail. Chinese President Xi Jinping's government doesn't care about upgrading economies, the health of tax regimes or central bank reserves. It cares about loyalty. The quid pro quo: For our generous assistance we expect your full support on everything from Taiwan to territorial disputes to deadening the West’s pesky focus on human rights.
  • This may sound hyperbolic; Russia, Argentina and Venezuela are already at odds with the U.S. and its allies. But what about Europe? In 2011 and 2012, it looked to Beijing to save euro bond markets through massive purchases. Expect more of this dynamic in 2015 should fresh turmoil hit the euro zone, at which time Beijing will expect European leaders to pull their diplomatic punches. What happens if the Federal Reserve’s tapering slams economies from India to Indonesia and governments look to China for help? Why would Cambodia, Laos or Vietnam bother with the IMF’s conditions when China writes big checks with few strings attached? Beijing’s $24 billion currency swap program to help Russia is a sign of things to come. Russia, it's often said, is too nuclear to fail. As Moscow weathers the worst crisis since the 1998 default, it’s tempting to view China as a good global citizen. But Beijing is just enabling President Vladimir Putin, who’s now under zero pressure to diversify his economy away from oil. The same goes for China’s $2.3 billion currency swap with Argentina and its $4 billion loan to Venezuela. In the Chinese century, bad behavior has its rewards.
  •  
    Note that this article is in a Bloomberg publication. Is economic reality beginning to dent the MSM propaganda on Wall Street?
Paul Merrell

Whether to Go to War Against Russia Is Top Issue in U.S. Presidential Race | Global Res... - 0 views

  • The United States government has already declared that in regards to what it alleges to be a Russian cyberattack against the U.S. Democratic Party, the U.S. reserves the right to go to war against Russia. NATO has accordingly changed its policy so as to assert that a cyberattack (in this case actually cyber-espionage, such as the U.S. government itself perpetrates against even its own allies such as Angela Merkel by tapping her phone) constitutes an act of war by the alleged cyberattacker, and so requires all NATO member nations to join any cyberattacked NATO nation in war against its alleged (cyber)attacker, if the cyberattacked member declares war against its alleged cyberattacker. Excuses are being sought for a war against Russia; and expanding the definition of “invasion,” to include mere espionage, is one such excuse. But it’s not the only one that the Obama Administration has cooked up. U.S. Senator Mike Lee has asserted that President Barack Obama must obtain a declaration of war against Syria — which is allied with and defended by Russia — before invading Syria. Syria has, for the past few years, already been invaded by tens of thousands of foreign jihadists (financed mainly by the royal Sauds and Qataris, and armed mainly with U.S. weaponry) who are trying to overthrow and replace the Syrian government so that pipelines can be built through Syria into Europe to transport Saudi oil and Qatari gas into the EU, the world’s biggest energy-market, which now is dominated by Russia’s oil and gas. Since Syria is already being defended by Russia (those royals’ major competitor in the oil and gas markets), America’s invasion of Syria would necessarily place U.S. and Russia into an air-war against each other (for the benefit of those royal Arabs — who finance jihadist groups, as even Hillary Clinton acknowledges): Syria would thus become a battleground in a broader war against Russia. So: declaring war against Syria would be a second excuse for World War III, and one which would especially serve the desires not only of U.S. ‘defense’ firms but of the U.S. aristocracy’s royal Arabic allies, who buy much of those ‘defense’ firms’ exports (weaponry), and also U.S. oilfield services firms such as pipelines by Halliburton. (It’s good business for them, no one else. Taxpayers and war-victims pay, but those corporations — and royal families — would profit.)
  • The U.S. government also declares that Russia ‘conquered’ Crimea in 2014 and that Russia must restore it to Ukraine. The U.S. government wants Ukraine to be accepted into NATO, so that all NATO nations will be at war against Russia if Russia doesn’t return Crimea to Ukraine, of which Crimea had only briefly (1954-2014) been a part, until Crimeans voted on 16 March 2014 to rejoin Russia. This Crimean issue is already the basis for America’s economic sanctions against Russia, and thus Russia’s continuing refusal to coerce Crimeans to accept again being part of Ukraine would be yet a third excuse for WW III.
  • Hillary Clinton says “As President, I will make it clear, that the United States will treat cyber attacks just like any other attack.” She alleges that when information was unauthorizedly made public from Democratic National Committee computers, the cyberattacker was Russia. She can be counted as a strong proponent of that excuse for WW3. She’s with Barack Obama and the other neocons on that. She has furthermore said that the U.S. should shoot down any Russian and Syrian bombers in Syria — the phrase for that proposed U.S. policy is to “establish a no-fly zone” there. She makes clear: “I am advocating the no-fly zone.” It would be war against not only Syria, but Russia. (After all: a no-fly zone in which the U.S. is shooting down the government’s planes and Russia’s planes, would be war by the U.S. against both Syria and Russia, but that’s what she wants to do.) She can thus be counted as a strong proponent of those two excuses for WW3.
  • ...4 more annotations...
  • On the matter of Crimea, she has said that “Putin invaded and annexed Crimea,” and “In the wake of Russia’s illegal annexation of Crimea in early 2014, some have argued that NATO expansion either caused or exacerbated Russia’s aggression. I disagree with that argument.” She believes that the expansion of NATO right up to Russia’s borders is good, not horrific and terrifying (as it is to Russians — just like USSR’s conquering of Mexico would have been terrifying to Americans if USSR did that during the Cold War). Furthermore, because Ukraine is the main transit-route for Russian gas-pipelines into Europe, the coup that in 2014 overthrew the neutralist democratically elected President of Ukraine and replaced him by leaders who seek NATO membership for Ukraine and who have the power to cut off those pipelines, was strongly supported by both Obama and Clinton. She can thus be counted as a strong proponent of all three excuses for WW3. U.S. President Obama has made unequivocally clear that he regards Russia as being by far the world’s most “aggressive” nation; and Clinton, too, commonly uses the term “aggression” as describing Russia (such as she did by her denial that “NATO expansion either caused or exacerbated Russia’s aggression”). To her, Russia’s opposing real aggression by the U.S. (in this case, America’s 2014 coup that overthrew the democratically elected Ukrainian President for whom 75% of Crimeans had voted), constitutes ‘Russia’s aggression’, somehow. Furthermore, as regards whether Crimea’s rejoining Russia was ‘illegal’ as she says: does she also deny the right of self-determination of peoples regarding the residents of Catalonia though the Spanish government accepts it there, and also by the residents of Scotland though the British government accepts it there? Or is she simply determined to have as many excuses to invade Russia as she can have? She has never condemned the independence movements in Scotland or Catalonia. The United States is clearly on a path toward war with Russia. Donald Trump opposes all aspects of that policy.
  • That’s the main difference between the two U.S. Presidential candidates. Trump makes ridiculous statements about the ‘need’ to increase ‘defense’ spending during this period of soaring federal debt, but he has consistently condemned the moves toward war against Russia and said that America’s real enemy is jihadists, and that Russia is on our side in this war — the real war — not an enemy of America such as Hillary Clinton and Barack Obama claim. Both candidates (Trump and Clinton) are war-hawks, but Hillary wants to go to war against both jihadists and Russia, whereas Trump wants to go to war only against jihadists. Trump’s charge that Hillary would be a catastrophic President is borne out not only by her past record in public office, but by her present positions on these issues.
  • Americans are being offered, by this nation’s aristocracy, a choice between a marginally competent and deeply evil psychopath Hillary Clinton, versus an incompetent but far less evil psychopath Donald Trump, and the nation’s press are reporting instead a choice between two candidates of whom one (the actually evil Clinton) is presented as being far preferable to the other (the actually incompetent Trump), and possibly as being someone who might improve this nation if not the world. Virtually none of America’s Establishment is willing to report the truth: that the nation’s rotting will get worse under either person as President, but that only under Trump might this nation (and the world) stand a reasonable likelihood of surviving at all (i.e., nuclear war with Russia being averted). Things won’t get better, but they definitely could get a hell of a lot worse — and this is the issue, the real one, in the present election: WW3, yes or no on that. Hillary Clinton argues that she, with her neoconservative backing (consisting of the same people who cheer-led the invasion of Russia-friendly Iraq, and who shared her joy in doing the same to Russia-friendly Libya — “We came, we saw, he died, ha ha!”), is the better person to have her finger on the nuclear button with Russia. This U.S. Presidential election will be decided upon the WW3-issue, unless the American electorate are incredibly stupid (or else terribly deceived): Is she correct to allege that she and not Trump should have control over the nuclear button against Russia? She’s even more of a neoconservative than Obama is, and this is why she has the endorsement of neoconservatives in this election. And that is the issue.
  • The real question isn’t whether America and the world will be improved by the next U.S. President; it’s whether America and the world will be destroyed by the next U.S. President. All else is mere distraction, by comparison. And the U.S. public now are extremely distracted — unfortunately, even by the candidates themselves. The pathetic Presidential candidates that the U.S. aristocracy has provided to Americans, for the public’s votes in the final round, don’t focus on this reality. Anyone who thinks that the majority of billionaires can’t possibly believe in a ‘winnable’ nuclear war and can’t possibly be wanting WW3 should read this. That was published by the Council on Foreign Relations, Wall Street’s international-affairs think tank. They mean business. And that’s the source of neoconservatism — the top U.S.-based international corporations, mainly in ‘defense’ and oil and Wall Street. (Clinton’s career is based upon precisely those three segments, whereas Trump’s is based instead upon real estate and entertainment, neither of which segments is neoconservative.) It doesn’t come from nowhere; it comes from the people who buy and sell politicians.
  •  
    A must-read
Paul Merrell

HTTPS Deployment Growing by Leaps and Bounds: 2016 in Review | Electronic Frontier Foun... - 0 views

  • This was a great year for adoption of HTTPS encryption for secure connections to websites. HTTPS is an essential technology for security and privacy on the Web, and we've long been asking sites to turn it on to protect their users from spying (and from censorship and tampering with site content). This year, lots of factors came together to make it happen, including ongoing news about surveillance, advances in Web server capacity, nudges from industry, government, and Web browsers, and the Let's Encrypt certificate authority. By some measures, more than half of page loads in Firefox and in Chrome are now secured with HTTPS—the first time this has ever happened in the Web's history. That's right: for the first time ever, most pages viewed on the Web were encrypted! (As another year-in-review post will discuss, browsers are also experimenting with and rolling out stronger encryption technologies to better protect those connections.)
  • Sites large and small took turned on HTTPS in 2016, often using certificates from the Let's Encrypt certificate authority (sometimes with EFF's Certbot software, or a range of other options). In just a single year of broad public availability, Let's Encrypt has now helped enable secure connections for over 21 million websites, most of which never had certificates before.
  • A sizeable part of the growth in HTTPS came from very large hosting providers that decided to make HTTPS a default for sites that they host, including OVH, Wordpress.com, Shopify, Tumblr, Squarespace, and many others. Sites they host, and visitors to those sites, can get a boost in security without having to do anything. (And we're getting ongoing benefits from providers like CloudFlare who made the switch in previous years.) A single hosting provider's decision can result in enabling encryption for hundreds of thousands or millions of customers; we hope others will take the plunge too! U.S. government sites also made significant progress adopting HTTPS this year, responding to the administration's guidance in support of HTTPS—a clear and practical explanation of why secure connections should be the default. A caveat: data from Google shows that use of HTTPS varies significantly from country to country, remaining especially uncommon in Japan. We've also heard that it's still uncommon across much of East and Southeast Asia. Next year, we'll have to find ways to bridge those gaps.
Paul Merrell

Dutch intelligence agency AIVD hacks internet forums - nrc.nl - 0 views

  • The Dutch intelligence service - AIVD - hacks internet web forums to collect the data of all users. The majority of these people are unknown to the intelligence services and are not specified as targets when the hacking and data-collection process starts. A secret document of former NSA-contractor Edward Snowden shows that the AIVD use a technology called Computer Network Exploitation – CNE – to hack the web forums and collect the data.
  • Nico van Eijk, a Dutch professor in Information Law, is of the opinion that the Dutch intelligence service has crossed the boundaries of Dutch legislation. “They use sweeps to collect data from all users of web forums. The use of these techniques could easily lead to mass surveillance by the government.” IT specialist Matthijs Koot says that the exploitation of this technology can lead to a blurring of the lines between normal citizens and legitimate targets of the intelligence services. The document summarizes a meeting held on February 14, 2013 between officials of the NSA and the Dutch intelligence services - AIVD and MIVD. During this meeting Dutch officials briefed their American counterparts on the way they target web forums with the CNE technique. “They acquire MySQL databases via CNE access”, the document reads. MySQL is free open source software used to build databases for web forums. These databases contain all the posts of all the users of the forum and their personal data. During the meeting Dutch intelligence officers explained how they use the information in the database. In order to identify targets. According to the document the Dutch “are looking at marrying the forum data with other social network info, and trying to figure out good ways to mine the data that they have.”
  • A group of Dutch members of parliament have called for a parliamentary inquiry into the way the secret services are collecting and using data. The Dutch intelligence services have been previously criticised by an oversight committee for the way in which they have used legally intercepted data. According to this committee the search queries the intelligence services used to filter the data, were not specific enough. The use of generic queries, the committee concluded, was “not in accordance with Dutch law”. A spokesperson for the Dutch government refused to comment on the use of data from web forums by the AIVD, but stated that the intelligence services are allowed to hack computers. A spokesperson for the American government stated that the publication of classified information is a threat to US national security.
  •  
    Oooh ... Entire social media SQL databases. Content, user security stuff, the works. Big, big, big haystacks.
Paul Merrell

Verizon's New, Encrypted Calling App Plays Nice With the NSA - Businessweek - 0 views

  • Verizon is the latest big company to enter the post-Snowden market for secure communication, and it's doing so with an encryption standard that comes with a way for law enforcement to access ostensibly secure phone conversations.Verizon Voice Cypher, the product introduced on Thursday with the encryption company Cellcrypt, offers business and government customers end-to-end encryption for voice calls on iOS, Android, or BlackBerry devices equipped with a special app. The encryption software provides secure communications for people speaking on devices with the app, regardless of their wireless carrier, and it can also connect to an organization's secure phone system. Cellcrypt and Verizon both say that law enforcement agencies will be able to access communications that take place over Voice Cypher, so long as they're able to prove that there's a legitimate law enforcement reason for doing so. Seth Polansky, Cellcrypt's vice president for North America, disputes the idea that building technology to allow wiretapping is a security risk. "It's only creating a weakness for government agencies," he says. "Just because a government access option exists, it doesn't mean other companies can access it." 
  • Phone carriers like Verizon are required by U.S. law to build networks that can be wiretapped. But the legislation known as the Communications Assistance for Law Enforcement Act requires phone carriers to decrypt communications for the government only if they have designed their technology to make it possible to do so. If Verizon and Cellcrypt had structured their encryption so that neither company had the information necessary to decrypt the calls, they would not have been breaking the law.
  • There has been increased interest in encryption from individual consumers, too, largely thanks to the NSA revelations leaked by Edward Snowden. Yahoo and Google began offering end-to-end encrypted e-mail services this year. Silent Circle, a startup catering to consumer and enterprise clients, has been developing end-to-end voice encryption for phones calls. Verizon's service, with a monthly price of $45 per device, isn't targeting individual buyers and won't be offered to average consumers in the near future.But Verizon's partner, Cellcrypt, looks upon selling to large organizations as the first step toward bringing down the price before eventually offering a consumer-level encryption service. "At the end of the day, we'd love to have this be a line item on your Verizon bill," says Polansky.
  • ...2 more annotations...
  • Other companies have designed their encryption in this way, including AT&T, which offers encrypted phone service for business customers. Apple and Android recently began protecting content stored on users's phones in a way that would keep the tech companies from being able to comply with requests from law enforcement. The move drew public criticism from FBI Director James Comey, and some security experts expect that a renewed effort to stir passage of legislation banning such encryption will accompany Silicon Valley's increased interest in developing these services. Verizon believes major demand for its new encryption service will come from governmental agencies conveying sensitive but unclassified information over the phone, says Tim Petsky, a senior product manager for Verizon Wireless. Corporate customers who are concerned about corporate espionage are also itching for answers. "You read about breaches in security almost every week in the press," says Petsky. "Enterprise customers have been asking about ways to secure their communications and up until this point, we didn't have a solution." 
  • Many people in the security industry believe that a designed access point creates a vulnerability for criminals or spies to exploit. Last year reports surfaced that the FBI was pushing legislation that would require many forms of Internet communication to be wiretap-ready. A group of prominent security experts responded strongly: "Requiring software vendors to build intercept functionality into their products is unwise and will be ineffective, with the result being serious consequences (PDF) for the economic well-being and national security of the United States," they wrote in a report issued in May. 
Paul Merrell

No, Obama, Russia's Economy Isn't 'in Tatters' - Bloomberg View - 0 views

  • Western politicians and pundits should be more careful with their predictions for the Russian economy: Reports of its demise may prove to be premature. Bashing the Russian economy has lately become a popular pastime. In his state of the nation address last month, U.S. President Barack Obama said it was "in tatters." And yesterday, Anders Aslund of the Peterson Institute for International Economics published an article predicting a 10 percent drop in gross domestic product this year -- more or less in line with the apocalyptic predictions that prevailed when the oil price reached its nadir late last year and the ruble was in free fall. Aslund's forecast focuses on Russia's shrinking currency reserves, some of which have been earmarked for supporting government spending in difficult times. At $364.6 billion, they are down 26 percent from a year ago and $21.6 billion from the beginning of this year. Aslund expects $166 billion to be spent on infrastructure investments and bailing out companies, and another $100 billion to exit via capital flight and other currency outflows. As a result, given foreign debts of almost $600 billion, "Russia's reserve situation is approaching a critical limit," he says.
  • What this argument ignores is that Russia's foreign debts are declining along with its reserves -- that's what happens when the money is used to pay down state companies' obligations. Last year, for example, the combined foreign liabilities of the Russian government and companies dropped by $129.4 billion, compared with a $124.3 billion decline in foreign reserves. Beyond that, a large portion of Russian companies' remaining foreign debt is really part of a tax-evasion scheme: By lending themselves money from abroad, the companies transfer profits to lower-tax jurisdictions. Such loans can easily be extended if sanctions prevent the Russian side from paying. The declining price of oil is also less of a threat than many have warned. True, the Russian government's revenues from energy exports will fall in dollar terms. But because Russia's central bank has allowed the ruble's value against the dollar to decline, the ruble value of the revenues will be higher than they otherwise would be. As a result, Russia no longer requires $100 oil to balance its budget -- and the effect of lower oil prices on the broader economy will be muted.
  • Economists at the respected Gaidar Institute, for example, expect the floating of the ruble to roughly halve the negative GDP impact of the decline in oil prices. They estimate that Russian GDP will shrink by a moderate 2.7 percent this year, even if Brent oil trades at $40 (it traded at $61 today). That's just a bit more optimistic than the consensus among 39 economists polled by Bloomberg between Feb. 20 and Feb. 25: On average, they see a decline of 4 percent. Economic sanctions, which most forecasts assume will continue this year, are having less impact that many in the West would like to believe. Sergei Tsukhlo of the Gaidar Institute estimates that the sanctions have affected only 6 percent of Russian industrial enterprises. "Their effect remains quite insignificant despite all that's being said about them," he wrote, noting that trade disruptions with Ukraine have been more important.
  • ...1 more annotation...
  • Granted, there's no avoiding a significant drop in Russians' living standards because of accelerating inflation. The economics ministry in Moscow predicts real wages will fall by 9 percent this year -- which, Aslund wrote, means that "for the first time after 15 years in power," Russian President Vladimir Putin "will have to face a majority of the Russian people experiencing a sharply declining standard of living." So far, though, Russians have taken the initial shock of devaluation and accompanying inflation largely in stride. The latest poll from the independent Levada Center, conducted between Feb. 20 and Feb. 23, actually shows an uptick in Putin's approval rating -- to 86 percent from 85 percent in January.  It's time to bury the expectation that Russia will fall apart economically under pressure from falling oil prices and economic sanctions, and that Russians, angered by a drop in their living standards, will rise up and sweep Putin out of office. Western powers face a tough choice: Settle for a lengthy siege and ratchet up the sanctions despite the progress in Ukraine, or start looking for ways to restart dialogue with Russia, a country that just won't go away.
Paul Merrell

Launching in 2015: A Certificate Authority to Encrypt the Entire Web | Electronic Front... - 0 views

  • Today EFF is pleased to announce Let’s Encrypt, a new certificate authority (CA) initiative that we have put together with Mozilla, Cisco, Akamai, IdenTrust, and researchers at the University of Michigan that aims to clear the remaining roadblocks to transition the Web from HTTP to HTTPS.Although the HTTP protocol has been hugely successful, it is inherently insecure. Whenever you use an HTTP website, you are always vulnerable to problems, including account hijacking and identity theft; surveillance and tracking by governments, companies, and both in concert; injection of malicious scripts into pages; and censorship that targets specific keywords or specific pages on sites. The HTTPS protocol, though it is not yet flawless, is a vast improvement on all of these fronts, and we need to move to a future where every website is HTTPS by default.With a launch scheduled for summer 2015, the Let’s Encrypt CA will automatically issue and manage free certificates for any website that needs them. Switching a webserver from HTTP to HTTPS with this CA will be as easy as issuing one command, or clicking one button.
  • The biggest obstacle to HTTPS deployment has been the complexity, bureaucracy, and cost of the certificates that HTTPS requires. We’re all familiar with the warnings and error messages produced by misconfigured certificates. These warnings are a hint that HTTPS (and other uses of TLS/SSL) is dependent on a horrifyingly complex and often structurally dysfunctional bureaucracy for authentication.
  • The need to obtain, install, and manage certificates from that bureaucracy is the largest reason that sites keep using HTTP instead of HTTPS. In our tests, it typically takes a web developer 1-3 hours to enable encryption for the first time. The Let’s Encrypt project is aiming to fix that by reducing setup time to 20-30 seconds. You can help test and hack on the developer preview of our Let's Encrypt agent software or watch a video of it in action here:
  • ...1 more annotation...
  • Let’s Encrypt will employ a number of new technologies to manage secure automated verification of domains and issuance of certificates. We will use a protocol we’re developing called ACME between web servers and the CA, which includes support for new and stronger forms of domain validation. We will also employ Internet-wide datasets of certificates, such as EFF’s own Decentralized SSL Observatory, the University of Michigan’s scans.io, and Google's Certificate Transparency logs, to make higher-security decisions about when a certificate is safe to issue.The Let’s Encrypt CA will be operated by a new non-profit organization called the Internet Security Research Group (ISRG). EFF helped to put together this initiative with Mozilla and the University of Michigan, and it has been joined for launch by partners including Cisco, Akamai, and Identrust.
Paul Merrell

Britain has passed the 'most extreme surveillance law ever passed in a democracy' | ZDNet - 0 views

  • It's 2016 going on 1984. The UK has just passed a massive expansion in surveillance powers, which critics have called "terrifying" and "dangerous".
  • The new law, dubbed the "snoopers' charter", was introduced by then-home secretary Theresa May in 2012, and took two attempts to get passed into law following breakdowns in the previous coalition government. Four years and a general election later -- May is now prime minister -- the bill was finalized and passed on Wednesday by both parliamentary houses. But civil liberties groups have long criticized the bill, with some arguing that the law will let the UK government "document everything we do online". It's no wonder, because it basically does. The law will force internet providers to record every internet customer's top-level web history in real-time for up to a year, which can be accessed by numerous government departments; force companies to decrypt data on demand -- though the government has never been that clear on exactly how it forces foreign firms to do that that; and even disclose any new security features in products before they launch.
  • Not only that, the law also gives the intelligence agencies the power to hack into computers and devices of citizens (known as equipment interference), although some protected professions -- such as journalists and medical staff -- are layered with marginally better protections. In other words, it's the "most extreme surveillance law ever passed in a democracy," according to Jim Killock, director of the Open Rights Group. The bill was opposed by representatives of the United Nations, all major UK and many leading global privacy and rights groups, and a host of Silicon Valley tech companies alike. Even the parliamentary committee tasked with scrutinizing the bill called some of its provisions "vague".
  • ...1 more annotation...
  • And that doesn't even account for the three-quarters of people who think privacy, which this law almost entirely erodes, is a human right. There are some safeguards, however, such as a "double lock" system so that the secretary of state and an independent judicial commissioner must agree on a decision to carry out search warrants (though one member of the House of Lords disputed that claim). A new investigatory powers commissioner will also oversee the use of the powers. Despite the uproar, the government's opposition failed to scrutinize any significant amendments and abstained from the final vote. Killock said recently that the opposition Labour party spent its time "simply failing to hold the government to account". But the government has downplayed much of the controversy surrounding the bill. The government has consistently argued that the bill isn't drastically new, but instead reworks the old and outdated Regulation of Investigatory Powers Act (RIPA). This was brought into law in 2000, to "legitimize" new powers that were conducted or ruled on in secret, like collecting data in bulk and hacking into networks, which was revealed during the Edward Snowden affair. Much of those activities were only possible thanks to litigation by one advocacy group, Privacy International, which helped push these secret practices into the public domain while forcing the government to scramble to explain why these practices were legal. The law will be ratified by royal assent in the coming weeks.
Paul Merrell

Is the Justice Department Protecting An Anti-Iran Smear Campaign? « LobeLog - 0 views

  • A new wrinkle in an already bizarre lawsuit is shaping up to potentially embarrass the Obama administration. If allegations made in a recent court filing are true, then the US Department of Justice, with an unprecedented assertion of the state secrets privilege, might be shielding from any accountability a group actively engaged in spreading false information. The lawsuit revolves around United Against Nuclear Iran (UANI), an anti-Iran, pro-sanctions outfit that takes a hard line against Iran and lodges name-and-shame campaigns against companies it says are doing business with the country. The group is made up of former officials from the Bush and Obama administrations, as well as a host of academics, former diplomats and former intelligence officials from foreign countries, including Israel.
  • Last week, things got even weirder: in a motion filed on Wednesday, Restis’s lawyers suggested that UANI had leaked information to the Jerusalem Post that resulted in a piece accusing Restis of doing more illegal business in Iran. The Post later retracted the article, citing “new information” that indicated the purportedly illegal shipping had been “legitimate and permitted,” and scrubbed the article from its website. “Defendants appear to have provided The Jerusalem Post with false information purporting to show an American company’s legal and humanitarian cargo of soya beans to Iran aboard Plaintiffs’ vessel violated sanctions against Iran,” said a footnote in the filing from Restis’s lawyers. “Although it printed Defendants’ false allegations against Plaintiffs, The Jerusalem Post recognized the falsity of the allegations and issued a retraction and apology.”
  • If true, the alleged UANI leak of false information to the Jerusalem Post would contradict UANI’s lawyers’ assertion in an October hearing that “UANI has made no statements whatsoever about Victor Restis or his companies, about any subject, doing business with Iran or any subject since February of 2014.” The Jerusalem Post article also said that the information it revealed would be “raised… in an upcoming hearing in a US federal court.” UANI’s lawyers brought up the purported revelations the following day in the October 8 hearing. It has not been proven that UANI leaked information to the Post.
  • ...4 more annotations...
  • In a separate filing last Wednesday, lawyers from the American Civil Liberties Union, the Center for Constitutional Rights, the Electronic Frontier Foundation and other groups spelled out how unusual the Justice Department intervention was. The groups submitted a friend of the court briefing—itself an unusual move, since amicus briefs are usually filed when cases reach the appellate stage—agreeing with Restis’s team. “Never before has the government sought dismissal of a suit between private parties on state secrets grounds without providing the parties and the public any information about the government’s interest in the case,” the lawyers from the groups wrote. “It is hard to see why, unlike in every other state secrets case in history, meaningful public disclosure to the parties is not possible in this case.”
  • The October 7 Jerusalem Post article in question, headlined “Evidence obtained by JPost shows alleged ongoing violation of Iran sanctions” and written by legal correspondent Yonah Jeremy Bob, went through several iterations online before being retracted. (Bob did not respond to requests for comment.) The original version of the article purported to present evidence that Restis’s companies were continuing to violate Iran sanctions by pointing to information that a ship owned by Restis docked in Iran on September 27. (The article was amended without notice before being captured by a web archive on October 8.) Lowell, the lawyer for Restis, denied the charges to the Post at the time. “In September 2014, a major US-based food company made a legal shipment of soya beans from Argentina to Iran aboard the Helvetia One, a vessel owned by the Restis family,” Lowell told the paper. “The provision of food cargo to Iran is entirely legal and encouraged under the humanitarian carve-outs to international sanctions regimes.”
  • The original version of the article purported to present evidence that Restis’s companies were continuing to violate Iran sanctions by pointing to information that a ship owned by Restis docked in Iran on September 27. (The article was amended without notice before being captured by a web archive on October 8.) Lowell, the lawyer for Restis, denied the charges to the Post at the time. “In September 2014, a major US-based food company made a legal shipment of soya beans from Argentina to Iran aboard the Helvetia One, a vessel owned by the Restis family,” Lowell told the paper. “The provision of food cargo to Iran is entirely legal and encouraged under the humanitarian carve-outs to international sanctions regimes.”
  • On October 22, the Post came around to Lowell’s perspective, scrubbing the story and issuing a “clarification and correction” that expressed regret for publishing the story. The Post said its assertions of illegal business were “contradicted by new information provided to us and therefore no allegations of misconduct should be concluded from the above article.”
  •  
    The strange Restis case just keeps getting more strange.
Paul Merrell

Inside the Battle Over the CIA Torture Report - Bloomberg View - 0 views

  • After months of internal wrangling, the Senate Intelligence Committee is finally set to release its report on President George W. Bush-era CIA practices, which among other details will contain information about foreign countries that aided in the secret detention and interrogation of suspected terrorists. Several U.S. officials told us that the negotiations are nearly complete between the Central Intelligence Agency and the committee's Democratic staff, which prepared the classified 6,300-page report and its 600-page, soon-to-be-released declassified executive summary. Dianne Feinstein, the committee's chairman, is set to release the summary early next week. Her staff members had objected vigorously to hundreds of redactions the CIA had proposed in the executive summary. After an often-contentious process to resolve the disputes, managed by top White House officials, Feinstein was able to roll back the majority of the disputed CIA redactions.
  • Among the most significant of Feinstein’s victories, the report will retain information on countries that aided the CIA program by hosting black sites or otherwise participating in the secret rendition of suspected terrorists. The countries will not be identified by name, but in other ways, such as code names like “Country A.” This falls short of Feinstein’s original desire, which was to name the countries explicitly, but represents a big victory for the committee nonetheless. In a victory for the CIA, Feinstein reluctantly agreed to allow the redactions of the pseudonyms of agency personnel mentioned in the report. The CIA maintained that any reference to individuals working under cover that offered clues to their identities could place them in harm’s way. “We need to understand the role that particular countries played across time. Even having pseudonyms for countries in the report is important for a full accounting,” said Raha Wala, senior counsel at Human Rights First, which advocated on behalf of the report’s declassification.
  • The CIA and some Republican senators had argued that even such masked identifications could be deciphered, leading to compromised relationships with those countries’ governments. In June 2013, the top intelligence official at the State Department, Philip Goldberg, wrote a classified letter to Congress warning against the disclosure of the names of countries who had participated in the program.
  • ...4 more annotations...
  • John Rizzo, who served as the CIA's acting general counsel during the black-site program and later wrote a memoir, "Company Man," said the agency has long fought against declassifying any information on the locations of the secret prisons overseas. "That was something we had fought for years and years," Rizzo told us. "Up to now one of the only remaining classified facts about the program was the names of countries where there were black sites." Rizzo said the concern about even referencing the locations of the black sites is that one could piece together the locations with other information that is likely to be in the final public report. One Republican Senate staffer familiar with the negotiations over the report said Feinstein's office relented on some concerns about redacting information that could identify countries hosting the black sites. "Do you scrub enough information to prevent that information from being released?" the staffer said. "It ended up as a half-step in-between, some of the stuff she wanted released and some of the information identifying the countries has been redacted."
  • There is also a risk that any information about foreign countries that aided the CIA programs, even using code names,  could be matched against public reporting that already exists to make them more identifiable. There have been news reports about cooperation by the governments of Poland,  Lithuania, Romania, Thailand and others. "Just because something is leaked doesn’t mean it’s still not secret," Rizzo said. "A national security secret is still a national security secret until the government says otherwise."
  • Originally there had been bipartisan support for the majority staff’s investigation, and the committee’s Republican staff was initially part of the investigation -- but it withdrew early in the process. Even after the Republican staff disowned the investigation, some Republican senators continued to support declassification, including John McCain and Lindsey Graham.
  • The release will not include internal CIA documents that the agency accused Feinstein’s staff of improperly removing from a CIA facility that had been set up for the investigators to work at. Feinstein said that her staff had removed the documents, including a review by Panetta, only after CIA officials tried to surreptitiously remove them from computers being used by the committee’s staff. “What was unique and interesting about the internal documents was not their classification level, but rather their analysis and acknowledgement of significant CIA wrongdoing,” Feinstein said on the Senate floor in July. “The interrogations and the conditions of confinement at the CIA detention sites were far different and far more harsh than the way the CIA had described them to us.”
  •  
    Nations that knowingly hosted the CIA "black sites" won't be named, as though their own citizens should be deprived of that information. I still maintain that there would be no need for redacting CIA agents' names who participated in the torture if they were named in criminal complaints as they are required to be by the Convention Against Torture, which -- through the Constitution's Treaty Clause, is "the law of this land." 
Gary Edwards

Security, the Edward Snowden Way - Datamation - 0 views

  • NoScript NoScript is a free extension for Mozilla-based web browsers, including Firefox. It blocks executable web content by default. This blocking includes JavaScript, Java, Flash and Silverlight. You can whitelist sites if you want to use such content on a site-by-site basis. Or, if you choose, you can make all sites active by default and choose to blacklist sites you think might be dangerous. A visual button tells you if active content has been blocked on the current site.
  • PGP In the first chapter of his book “No Place to Hide,” journalist Glenn Greenwald wrote that Edward Snowden contacted him using the alias “Cincinnatus,” and said he would tell Greenwald some highly newsworthy facts, but only if he installed Pretty Good Privacy (PGP) first. (Greenwald didn’t know the magnitude of the scoop being offered to him and didn’t get around to installing PGP for months, thus delaying the leak.) PGP, of course, is a 23-year-old encryption program that can be used for email, as well as files and other things.
  • Tor Tor is a free application that routes your Internet traffic through a global volunteer network of thousands of relays that play a shell game with your data so your location and Internet travels are concealed. Tor, which used to stand for “The Onion router” in a reference to layers of encryption, encrypts data in multiple layers that prevents snoops from being able to figure out any details about your web travels, such as where you are or what you’re looking at. Tor was developed in part by US government funding as a way to enable citizens in repressive countries to communicate safely. And the NSA has a lot of respect for it. But in a recent controversy, two Carnegie Mellon researchers said they would give a talk at the Black Hat USA 2014 conference next month telling how to identify Tor users inexpensively (for only $3,000). The session was cut from the lineup because university lawyers didn’t approve it. The institute that the researchers work for is funded by the Pentagon, but the Department of Homeland Security said they did not request that the talk be cancelled.
  •  
    "Whether you think NSA whistleblower Edward Snowden is a hero or a traitor, you have to admit: The guy knows how to keep his information secure. The fact that Snowden isn't sitting in Guantanamo right now with ankle cuffs and a bag over his head demonstrates his ability to avoid detection. Snowden spoke at the Hope X conference in New York this month via a Google+ Hangout from Russia, and called on developers to build privacy and security into everyday products. He also hinted that he planned to work on building such technology. If you look into the details of what's been happening with tracking, surveillance, spying, hacking and global cyber industrial espionage, you can see that Snowden is right. We all need a lot better protection from snoops of all stripes. But how does the non-expert get started? One option is to listen to Snowden himself. Over the past year, Snowden has in one format or another, made specific product recommendations. Here are the products Snowden has explicitly recommended since the trove of documents on the NSA has been publicly revealed. (The list is in alphabetical order.) Ghostery Ghostery, made by a company called Evidon, is a browser extension for Chrome, Firefox, Safari and Internet Explorer. It exists for two purposes. The first is to block tracking code, which makes browsing the web both more private and also faster. The second purpose is, somewhat contradictory -- Evidon collects data from you to help advertisers avoid being blocked. It also enables website owners to gain insights into the tracking code deployed on their site by third-party advertising companies. Note that Snowden recommended Ghostery some time ago. But this month, the Electronic Frontier Foundation launched a competing product that I would imagine Snowden would recommend called Privacy Badger."
  •  
    I'd back Snowden in 2016 as a write-in candidate for President.
Gary Edwards

We Call a Top NSA Whistleblower … And Get the REAL SCOOP on Spying | Washingt... - 0 views

  •  
    "NSA whistleblower Thomas Drake corroborated Klein's assertions, testifying that while the NSA is using Israeli-made NARUS hardware to "seize and save all personal electronic communications." ..................... I then asked the NSA veteran Binney if the government's claim that it is only spying on metadata - and not content - was correct. We have extensively documented that the government is likely recording content as well. (And the government has previously admitted to "accidentally" collecting more information on Americans than was legal, and then gagged the judges so they couldn't disclose the nature or extent of the violations.) Binney said that was not true; the government is gathering everything, including content. Binney explained - as he has many times before - that the government is storing everything, and creating a searchable database … to be used whenever it wants, for any purpose it wants (even just going after someone it doesn't like). ..................... Binney said that former FBI counter-terrorism agent Tim Clemente is correct when he says that no digital data is safe (Clemente says that all digital communications are being recorded). Both Verint and Narus were founded in Israel in the 1990s. *** Binney next confirmed the statement of the author of the Patriot Act - Congressman Jim Sensenbrenner - that the NSA spying programs violate the Patriot Act. After all, the Patriot Act is focused on spying on external threats … not on Americans. Binney asked rhetorically: "How can an American court [FISA or otherwise] tell telecoms to cough up all domestic data?!" Update: Binney sent the following clarifying email about content collection: It's clear to me that they are collecting most e-mail in full plus other text type data on the web. As for phone calls, I don't think they would record/transcribe the approximately 3 billion US-to-US calls every day. It's more likely that they are reco
Gary Edwards

Take A Break From The Snowden Drama For A Reminder Of What He's Revealed So Far - Forbes - 0 views

  • Here’s a recap of Snowden’s leaked documents published so far, in my own highly subjective order of importance.
  • The publication of Snowden’s leaks began with a top secret order from the Foreign Intelligence Surveillance Court (FISC) sent to Verizon on behalf of the NSA, demanding the cell phone records of all of Verizon Business Network Services’ American customers for the three month period ending in July. The order, obtained by the Guardian, sought only the metadata of those millions of users’ calls–who called whom when and from what locations–but specifically requested Americans’ records, disregarding foreigners despite the NSA’s legal restrictions that it may only surveil non-U.S. persons. Senators Saxby Chambliss and Diane Feinstein defended the program and said it was in fact a three-month renewal of surveillance practices that had gone for seven years.
  • In a congressional hearing, NSA director Keith Alexander argued that the kind of surveillance of Americans’ data revealed in that Verizon order was necessary to for archiving purposes, but was rarely accessed and only with strict oversight from Foreign Intelligence Surveillance Court judges. But another secret document published by the Guardian revealed the NSA’s own rules for when it makes broad exceptions to its foreign vs. U.S. persons distinction, accessing Americans’ data and holding onto it indefinitely. Those exceptions include anytime Americans’ data is judged to be “significant foreign intelligence” information or information about a crime that has been or is about to be committed, any data “involved in the unauthorized disclosure of national security information,” or necessary to “assess a communications security vulnerability.” Any encrypted data that the NSA wants to crack can also be held indefinitely, regardless of whether its American or foreign origin.
  • ...6 more annotations...
  • Another leaked slide deck revealed a software tool called Boundless Informant, which the NSA appears to use for tracking the origin of data it collects. The leaked materials included a map produced by the program showing the frequency of data collection in countries around the world. While Iran, Pakistan and Jordan appeared to be the most surveilled countries according to the map, it also pointed to significant data collection from the United States.
  • A leaked executive order from President Obama shows the administration asked intelligence agencies to draw up a list of potential offensive cyberattack targets around the world. The order, which suggests targeting “systems, processes and infrastructure” states that such offensive hacking operations “can offer unique and unconventional capabilities to advance U.S. national objectives around the world with little or no warning to the adversary or target and with potential effects ranging from subtle to severely damaging.” The order followed repeated accusations by the U.S. government that China has engaged in state-sponsored hacking operations, and was timed just a day before President Obama’s summit with Chinese President Xi Jinping.
  • Documents leaked to the Guardian revealed a five-year-old British intelligence scheme to tap transatlantic fiberoptic cables to gather data. A program known as Tempora, created by the U.K.’s NSA equivalent Government Communications Headquarters (GCHQ) has for the last 18 months been able to store huge amounts of that raw data for up to 30 days. Much of the data is shared with the NSA, which had assigned 250 analysts to sift through it as of May of last year.
  • Another GCHQ project revealed to the Guardian through leaked documents intercepted the communications of delegates to the G20 summit of world leaders in London in 2009. The scheme included monitoring the attendees’ phone calls and emails by accessing their Blackberrys, and even setting up fake Internet cafes that used keylogging software to surveil them.
  • Snowden showed the Hong Kong newspaper the South China Morning Post documents that it said outlined extensive hacking of Chinese and Hong Kong targets by the NSA since 2009, with 61,000 targets globally and “hundreds” in China. Other SCMP stories based on Snowden’s revelations stated that the NSA had gained access to the Chinese fiberoptic network operator Pacnet as well as Chinese mobile phone carriers, and had gathered large quantities of Chinese SMS messages.
  • The Guardian’s Glenn Greenwald has said that Snowden provided him “thousands” of documents, of which “dozens” are newsworthy. And Snowden himself has said he’d like to expose his trove of leaks to the global media so that each country’s reporters can decide whether “U.S. network operations against their people should be published.” So regardless of where Snowden ends up, expect more of his revelations to follow.
  •  
    Nice tight summary
Gary Edwards

FBI Source: Clinton Foundation Can Bring Down Entire Government » Alex Jones'... - 1 views

  •  
    "The Clinton Foundation is a "massive spider web of connections and money laundering implicating hundreds of high-level people," according to an anonymous insider who revealed why the FBI stopped short of indicting Hillary Clinton. Before FBI Director James Comey announced the FBI wouldn't recommend pressing charges against Clinton, an insider with "intimate knowledge of the inner workings of the Clinton case" hosted an little-publicized AMA session on 4Chan, and the statements he made on July 2 corroborate with later developments of the scandal. "There is enough for her and the entire government to be brought down," he revealed. "People do not realize how enormous this whole situation actually is." "Whether she will be [indicted] or not depends on how much info others involved gets out, and there are a lot of people involved." Since then, both the FBI and the DOJ declined to press charges against Clinton, and other sources revealed the Clinton Foundation is now under scrutiny. "The problem is with the Clinton Foundation as I mentioned, which you should just imagine as a massive spider web of connections and money laundering implicating hundreds of high-level people," the source said. "Though I do not have a high opinion of Hillary, she is just a piece - albeit a big piece - of this massive sh*tstorm." Those implicated extends to the Justice Dept. "The DOJ is most likely looking to save itself," he continued. "Find everyone involved in the Clinton Foundation, from its donors to its Board of Directors, and imagine they are all implicated." This would explain why Bill Clinton forced himself on Attorney General Loretta Lynch's plane at the Phoenix Sky Harbor International Airport last week; Clinton insider Larry Nichols said blackmail was likely involved. "Bill Clinton met with Lynch, and he was there to assure her that when Hillary gets to be president she'll be able to keep her job," said Nichols on the Alex Jones Sh
Gary Edwards

'Clinton death list': 33 spine-tingling cases - 0 views

  •  
    "(Editor's note: This list was originally published in August 2016 and has gone viral on the web. WND is running it again as American voters cast their ballots for the nation's next president on Election Day.) How many people do you personally know who have died mysteriously? How about in plane crashes or car wrecks? Bizarre suicides? People beaten to death or murdered in a hail of bullets? And what about violent freak accidents - like separate mountain biking and skiing collisions in Aspen, Colorado? Or barbells crushing a person's throat? Bill and Hillary Clinton attend a funeral Apparently, if you're Bill or Hillary Clinton, the answer to that question is at least 33 - and possibly many more. Talk-radio star Rush Limbaugh addressed the issue of the "Clinton body count" during an August show. "I swear, I could swear I saw these stories back in 1992, back in 1993, 1994," Limbaugh said. He cited a report from Rachel Alexander at Townhall.com titled, "Clinton body count or left-wing conspiracy? Three with ties to DNC mysteriously die." Limbaugh said he recalled Ted Koppel, then-anchor of ABC News' "Nightline," routinely having discussions on the issue following the July 20, 1993, death of White House Deputy Counsel Vince Foster. In fact, Limbaugh said, he appeared on Koppel's show. "One of the things I said was, 'Who knows what happened here? But let me ask you a question.' I said, 'Ted, how many people do you know in your life who've been murdered? Ted, how many people do you know in your life that have died under suspicious circumstances?' "Of course, the answer is zilch, zero, nada, none, very few," Limbaugh chuckled. "Ask the Clintons that question. And it's a significant number. It's a lot of people that they know who have died, who've been murdered. "And the same question here from Rachel Alexander. It's amazing the cycle that exists with the Clintons. [Citing Townhall]: 'What it
Gary Edwards

KeepTheWebOpen.com - 0 views

  •  
    Keep the Web Open and out of the hands of Agenda 21 UN socialists and the tyranny of ACTA. California Representative Darryl Issa has proposed  OPEN - the Online Protection & ENforcement of Ditital Trade Act.  Join the movement to keep the Web Open and sign on today. The background to this urgency is that Obama is trying to run an end around Congress, claiming that he has the authority to sign ACTA: From the Vanguard of Freedom: The Anti-Counterfeiting Trade Agreement. ACTA is supposed to strengthen intellectual property rights; that is, the rights of artists to protect their creations from being copied and counterfeited, essentially stolen and reproduced without consent. However, many including Congressman Darrel Issa (via his website on this subject) has called ACTA "an unconstitutional power grab started by President George W. Bush and completed by President Barack Obama - despite the White House's January 14 criticism of legislative solutions that harm the Internet and erode individual rights." Says Issa: "…The Constitution gives Congress the power to pass intellectual property legislation - like SOPA and PIPA - and gives the Senate the power to ratify treaties. But the Obama Administration maintains that ACTA is not even a treaty, justifying the exclusion of both American citizens and their elected representatives. It is a practice Vice President Joe Biden decried as a U.S. Senator…" Maira Sutton and Parker Higgins, writing for the Electronic Frontier Foundation, an "electronics" rights advocacy organization, say in an article they authored, that "…We Have Every Right to Be Furious About ACTA." Sutton and Higgins write: "…Negotiated in secret, ACTA bypassed checks and balances of existing international IP norm-setting bodies, without any meaningful input from national parliaments, policymakers, or their citizens. Worse still, the agreement creates a new global institution, an 'ACTA Committee' to ove
Paul Merrell

N.S.A. Able to Foil Basic Safeguards of Privacy on Web - NYTimes.com - 1 views

  • The National Security Agency is winning its long-running secret war on encryption, using supercomputers, technical trickery, court orders and behind-the-scenes persuasion to undermine the major tools protecting the privacy of everyday communications in the Internet age, according to newly disclosed documents.
  • The documents are among more than 50,000 shared by The Guardian with The New York Times and ProPublica, the nonprofit news organization. They focus on GCHQ but include thousands from or about the N.S.A. Intelligence officials asked The Times and ProPublica not to publish this article, saying it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. The news organizations removed some specific facts but decided to publish the article because of the value of a public debate about government actions that weaken the most powerful privacy tools.
  • The N.S.A. hacked into target computers to snare messages before they were encrypted. In some cases, companies say they were coerced by the government into handing over their master encryption keys or building in a back door. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world.
  • ...11 more annotations...
  • “For the past decade, N.S.A. has led an aggressive, multipronged effort to break widely used Internet encryption technologies,” said a 2010 memo describing a briefing about N.S.A. accomplishments for employees of its British counterpart, Government Communications Headquarters, or GCHQ. “Cryptanalytic capabilities are now coming online. Vast amounts of encrypted Internet data which have up till now been discarded are now exploitable.”
  • Some of the agency’s most intensive efforts have focused on the encryption in universal use in the United States, including Secure Sockets Layer, or SSL; virtual private networks, or VPNs; and the protection used on fourth-generation, or 4G, smartphones. Many Americans, often without realizing it, rely on such protection every time they send an e-mail, buy something online, consult with colleagues via their company’s computer network, or use a phone or a tablet on a 4G network.
  • For at least three years, one document says, GCHQ, almost certainly in collaboration with the N.S.A., has been looking for ways into protected traffic of popular Internet companies: Google, Yahoo, Facebook and Microsoft’s Hotmail. By 2012, GCHQ had developed “new access opportunities” into Google’s systems, according to the document. (Google denied giving any government access and said it had no evidence its systems had been breached).
  • Paul Kocher, a leading cryptographer who helped design the SSL protocol, recalled how the N.S.A. lost the heated national debate in the 1990s about inserting into all encryption a government back door called the Clipper Chip. “And they went and did it anyway, without telling anyone,” Mr. Kocher said. He said he understood the agency’s mission but was concerned about the danger of allowing it unbridled access to private information.
  • The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.
  • The files show that the agency is still stymied by some encryption, as Mr. Snowden suggested in a question-and-answer session on The Guardian’s Web site in June. “Properly implemented strong crypto systems are one of the few things that you can rely on,” he said, though cautioning that the N.S.A. often bypasses the encryption altogether by targeting the computers at one end or the other and grabbing text before it is encrypted or after it is decrypted.
  • Because strong encryption can be so effective, classified N.S.A. documents make clear, the agency’s success depends on working with Internet companies — by getting their voluntary collaboration, forcing their cooperation with court orders or surreptitiously stealing their encryption keys or altering their software or hardware.
  • At Microsoft, as The Guardian has reported, the N.S.A. worked with company officials to get pre-encryption access to Microsoft’s most popular services, including Outlook e-mail, Skype Internet phone calls and chats, and SkyDrive, the company’s cloud storage service.
  • Simultaneously, the N.S.A. has been deliberately weakening the international encryption standards adopted by developers. One goal in the agency’s 2013 budget request was to “influence policies, standards and specifications for commercial public key technologies,” the most common encryption method. Cryptographers have long suspected that the agency planted vulnerabilities in a standard adopted in 2006 by the National Institute of Standards and Technology and later by the International Organization for Standardization, which has 163 countries as members. Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency. The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.” “Eventually, N.S.A. became the sole editor,” the memo says.
  • But the agencies’ goal was to move away from decrypting targets’ tools one by one and instead decode, in real time, all of the information flying over the world’s fiber optic cables and through its Internet hubs, only afterward searching the decrypted material for valuable intelligence. A 2010 document calls for “a new approach for opportunistic decryption, rather than targeted.” By that year, a Bullrun briefing document claims that the agency had developed “groundbreaking capabilities” against encrypted Web chats and phone calls. Its successes against Secure Sockets Layer and virtual private networks were gaining momentum.
  • Ladar Levison, the founder of Lavabit, wrote a public letter to his disappointed customers, offering an ominous warning. “Without Congressional action or a strong judicial precedent,” he wrote, “I would strongly recommend against anyone trusting their private data to a company with physical ties to the United States.”
  •  
    Lengthy article, lots of new information on NSA decryption capabilities, none of it good for those who value their data privacy.
  •  
    Thanks Paul - nice job cutting this monster down to size :)
1 - 20 of 291 Next › Last »
Showing 20 items per page