Pages

Wednesday, September 11, 2013

Project aims to map giant galactic clouds of gas where stars are born

from UPI.com: Australia say they've begun to map the location of the most massive and mysterious objects in our galaxy, giant gas clouds where stars are born. 

Using a giant radio telescope in southeastern Australia, the researchers have identified the galactic clouds of molecular gas -- some up to 100 light-years across -- from the carbon monoxide they contain.

"On Earth, carbon monoxide is poisonous -- a silent killer. But in space, it is the second most abundant molecule and the easiest to see," project leader Michael Burton of the University of New South Wales said.

The carbon monoxide survey of the Southern Milky Way is being carried out with a 72-foot radio telescope in Coonabarabran.

"One of the largest unresolved mysteries in galactic astronomy is how these giant, diffuse clouds form in the interstellar medium," Burton said. "This process plays a key role in the cosmic cycle of birth and death of stars."

The project is part of an international effort also searching for "dark" galactic gas clouds, unseen clouds that contain very little carbon monoxide.

It is assumed these clouds are mostly made up of molecular hydrogen too cold to detect, and astronomers are using telescopes in Antarctica and Chile to search for these dark clouds based on the presence of carbon atoms rather than carbon molecules. 
"Taken together, these three surveys will provide us with a picture of the distribution and movement of gas clouds in our galaxy," Burton said.

#NSA 'routinely' shares Americans' data with #Israel

from RT.com: The NSA regularly shares raw US intelligence data with Israel without even removing information about American citizens, according to the latest revelation published by the Guardian. The report is based on a document leaked by Edward Snowden.

On Tuesday, September 11, the Guardian published a previously undisclosed document which revealed top-secret policies in place since 2009 that are used to share personal phone and Internet data pertaining to United States citizens with American ally Israel. 

The document, a five-page memorandum authorized by the National Security Agency near the beginning of US President Barack Obama’s first administration, outlines a deal between the NSA and Israel’s SIGINT National Unit, or ISNU. 

“This agreement,” the memo begins, “prescribes procedures and responsibilities for ensuring” privacy safeguards are implemented to protect the Fourth Amendment rights of US citizens with regards to the direct sharing of raw intelligence collected by the NSA with its Israeli counterpart.

That data, the document later explains, includes raw traffic picked up by the American spy office such as “unevaluated and unminimized transcripts, gists, facsimiles, telex, voice and Digital Network Intelligence (DNI) metadata and content” which is never necessarily scrutinized by US officials before sent to Israeli agents. 

Related:
Israel's secret intel unit spawns high-tech tycoons

But while the contents of emails and phone calls involving most US persons are fair game to be collected by Israeli intelligence, a select group of Americans are sparred from international surveillance: elected officials. The memo mandates that the Israelis must "destroy upon recognition" any communication "that is either to or from an official of the US government.” That pool of exempt persons is defined as "officials of the executive branch (including the White House, cabinet departments, and independent agencies), the US House of Representatives and Senate (member and staff) and the US federal court system (including, but not limited to, the Supreme Court)."

The Guardian notes, however, that other leaked documents uncovered as of late indicate that the US intelligence community may have reservations nonetheless with sharing info with even an ally as tried and true as Israel. 

"On the one hand, the Israelis are extraordinarily good Sigint partners for us, but on the other, they target us to learn our positions on Middle East problems," a senior NSA official says in a 2008 NSA document seen by the Guardian but not published in Wednesday’s piece. "A NIE [National Intelligence Estimate] ranked them as the third most aggressive intelligence service against the US." 

"One of NSA's biggest threats is actually from friendly intelligence services, like Israel. There are parameters on what NSA shares with them, but the exchange is so robust, we sometimes share more than we intended,” the Guardian quotes from the ’08 document. 

According to Guardian journalists Glenn Greenwald, Laura Poitras and Ewen MacAskill, a NSA spokesperson pressed for comment wouldn’t deny the validity of the leaked document’s contents, but assured the British newspaper that "Any US person information that is acquired as a result of NSA's surveillance activities is handled under procedures that are designed to protect privacy rights.” 

The latest leak comes on the 12-year anniversary of the September 11, 2001 terrorist attacks that many high-ranking US officials have used to justify the surveillance measures enacted in the decade-plus since. It also marks just more than three months since the Guardian first began published leaked NSA documents attributed to Snowden, a 30-year-old former intelligence contractor who has since relocated to Russia where he was granted asylum while avoiding espionage charges in the US.

Tuesday, September 10, 2013

Declassified files detail blatant violations, abuse of #NSA domestic spying program

from RT.com: For years the National Security Agency has been violating restrictions and misusing the US domestic spying program that collected private data from US citizens, newly released declassified documents show.

The new information from Intelligence Community Documents Regarding Collection under Section 501 of the Foreign Intelligence Surveillance Act (FISA) shows that the government on a daily basis spied on Americans’ telephone numbers, calling patterns as well as users IP addresses during the surveillance of foreign terror suspects.  

The information shows that between 2006 and 2009 the NSA violated the court restrictions by spying on telephone calls and lying to judges about how the data was deployed. The spying agency crossed referenced a selected list of some 16,000 phone numbers against databases which contained millions of records, thus violating the law, two senior intelligence officials told Bloomberg. 

The metadata program which started in 2006 enabled the NSA to gather more information about a specific number that the agency claimed could be linked to terrorist activity. The agency also kept an alert list that was cross-referenced with new numbers to consider whether they should be added to a list of "reasonable articulable suspicion." 

The NSA gathered the bulk phone records under Section 215 of the USA Patriot Act, which requires private companies to turn over evidence that is relevant to a terrorism investigation. However, the Foreign Intelligence Surveillance Court ruled that the NSA must have “reasonable, articulable suspicion” to run that number against a larger database. Only about 2,000 numbers on the list in 2009 met that legal condition, according to sources. 

The released documents according to Director of National Intelligence James Clapper relate to “compliance incidents that were discovered by the NSA, reported to the FISC and the Congress, and resolved four years ago.”
 
The documents were released as part of a lawsuit filed by the Electronic Frontier Foundation and under growing pressure for the administration to shed light on its surveillance activities following Edward Snowden’s leaks.

New iPhone Has TouchID Fingerprint Authentication

from wired.com: When Apple bought AuthenTec for its biometrics technology — reported as one of its most expensive purchases — there was a lot of speculation about how the company would incorporate biometrics in its product line. Many speculate(d) that the new Apple iPhone...will come with a fingerprint authentication system, and there are several ways it could work, such as swiping your finger over a slit-sized reader to have the phone recognize you.

Thursday, September 5, 2013

US and UK spy agencies defeat privacy and security on the internet

from guardian.co.uk: US and British intelligence agencies have successfully cracked much of the online encryption relied upon by hundreds of millions of people to protect the privacy of their personal data, online transactions and emails, according to top-secret documents revealed by former contractor Edward Snowden.

The files show that the National Security Agency and its UK counterpart GCHQ have broadly compromised the guarantees that internet companies have given consumers to reassure them that their communications, online banking and medical records would be indecipherable to criminals or governments.

The agencies, the documents reveal, have adopted a battery of methods in their systematic and ongoing assault on what they see as one of the biggest threats to their ability to access huge swathes of internet traffic – "the use of ubiquitous encryption across the internet".

Those methods include covert measures to ensure NSA control over setting of international encryption standards, the use of supercomputers to break encryption with "brute force", and – the most closely guarded secret of all – collaboration with technology companies and internet service providers themselves.

Through these covert partnerships, the agencies have inserted secret vulnerabilities – known as backdoors or trapdoors – into commercial encryption software.

The files, from both the NSA and GCHQ, were obtained by the Guardian, and the details are being published today in partnership with the New York Times and ProPublica. They reveal:

• A 10-year NSA program against encryption technologies made a breakthrough in 2010 which made "vast amounts" of data collected through internet cable taps newly "exploitable".

• The NSA spends $250m a year on a program which, among other goals, works with technology companies to "covertly influence" their product designs.

• The secrecy of their capabilities against encryption is closely guarded, with analysts warned: "Do not ask about or speculate on sources or methods."

• The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace".

• A GCHQ team has been working to develop ways into encrypted traffic on the "big four" service providers, named as Hotmail, Google, Yahoo and Facebook.

The agencies insist that the ability to defeat encryption is vital to their core missions of counter-terrorism and foreign intelligence gathering.

But security experts accused them of attacking the internet itself and the privacy of all users. 

"Cryptography forms the basis for trust online," said Bruce Schneier, an encryption specialist and fellow at Harvard's Berkman Center for Internet and Society. "By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet." Classified briefings between the agencies celebrate their success at "defeating network security and privacy".



"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies," stated a 2010 GCHQ document. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."

An internal agency memo noted that among British analysts shown a presentation on the NSA's progress: "Those not already briefed were gobsmacked!"

The breakthrough, which was not described in detail in the documents, meant the intelligence agencies were able to monitor "large amounts" of data flowing through the world's fibre-optic cables and break its encryption, despite assurances from internet company executives that this data was beyond the reach of government.

The key component of the NSA's battle against encryption, its collaboration with technology companies, is detailed in the US intelligence community's top-secret 2013 budget request under the heading "Sigint [signals intelligence] enabling".


NSA Bullrun 1  
Classified briefings between the NSA and GCHQ celebrate their success at 'defeating network security and privacy'. Photograph: Guardian 
 
Funding for the program – $254.9m for this year – dwarfs that of the Prism program, which operates at a cost of $20m a year, according to previous NSA documents. Since 2011, the total spending on Sigint enabling has topped $800m. The program "actively engages US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs", the document states. None of the companies involved in such partnerships are named; these details are guarded by still higher levels of classification.

Among other things, the program is designed to "insert vulnerabilities into commercial encryption systems". These would be known to the NSA, but to no one else, including ordinary customers, who are tellingly referred to in the document as "adversaries".

"These design changes make the systems in question exploitable through Sigint collection … with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact."
The document sets out in clear terms the program's broad aims, including making commercial encryption software "more tractable" to NSA attacks by "shaping" the worldwide marketplace and continuing efforts to break into the encryption used by the next generation of 4G phones.

Among the specific accomplishments for 2013, the NSA expects the program to obtain access to "data flowing through a hub for a major communications provider" and to a "major internet peer-to-peer voice and text communications system". 


Technology companies maintain that they work with the intelligence agencies only when legally compelled to do so. The Guardian has previously reported that Microsoft co-operated with the NSA to circumvent encryption on the Outlook.com email and chat services. The company insisted that it was obliged to comply with "existing or future lawful demands" when designing its products.
The documents show that the agency has already achieved another of the goals laid out in the budget request: to influence the international standards upon which encryption systems rely.

Independent security experts have long suspected that the NSA has been introducing weaknesses into security standards, a fact confirmed for the first time by another secret document. It shows the agency worked covertly to get its own version of a draft security standard issued by the US National Institute of Standards and Technology approved for worldwide use in 2006. 


"Eventually, NSA became the sole editor," the document states.

The NSA's codeword for its decryption program, Bullrun, is taken from a major battle of the American civil war. Its British counterpart, Edgehill, is named after the first major engagement of the English civil war, more than 200 years earlier.

A classification guide for NSA employees and contractors on Bullrun outlines in broad terms its goals.

"Project Bullrun deals with NSA's abilities to defeat the encryption used in specific network communication technologies. Bullrun involves multiple sources, all of which are extremely sensitive." The document reveals that the agency has capabilities against widely used online protocols, such as HTTPS, voice-over-IP and Secure Sockets Layer (SSL), used to protect online shopping and banking.
The document also shows that the NSA's Commercial Solutions Center, ostensibly the body through which technology companies can have their security products assessed and presented to prospective government buyers, has another, more clandestine role. 


It is used by the NSA to "to leverage sensitive, co-operative relationships with specific industry partners" to insert vulnerabilities into security products. Operatives were warned that this information must be kept top secret "at a minimum".

A more general NSA classification guide reveals more detail on the agency's deep partnerships with industry, and its ability to modify products. It cautions analysts that two facts must remain top secret: that NSA makes modifications to commercial encryption software and devices "to make them exploitable", and that NSA "obtains cryptographic details of commercial cryptographic information security systems through industry relationships".
The agencies have not yet cracked all encryption technologies, however, the documents suggest. Snowden appeared to confirm this during a live Q&A with Guardian readers in June. "Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on," he said before warning that NSA can frequently find ways around it as a result of weak security on the computers at either end of the communication. 


The documents are scattered with warnings over the importance of maintaining absolute secrecy around decryption capabilities.


NSA Bullrun 2  
A slide showing that the secrecy of the agencies' capabilities against encryption is closely guarded. Photograph: Guardian 
 
Strict guidelines were laid down at the GCHQ complex in Cheltenham, Gloucestershire, on how to discuss projects relating to decryption. Analysts were instructed: "Do not ask about or speculate on sources or methods underpinning Bullrun." This informaton was so closely guarded, according to one document, that even those with access to aspects of the program were warned: "There will be no 'need to know'."

The agencies were supposed to be "selective in which contractors are given exposure to this information", but it was ultimately seen by Snowden, one of 850,000 people in the US with top-secret clearance. A 2009 GCHQ document spells out the significant potential consequences of any leaks, including "damage to industry relationships".
"Loss of confidence in our ability to adhere to confidentiality agreements would lead to loss of access to proprietary information that can save time when developing new capability," intelligence workers were told. Somewhat less important to GCHQ was the public's trust which was marked as a moderate risk, the document stated.


"Some exploitable products are used by the general public; some exploitable weaknesses are well known eg possibility of recovering poorly chosen passwords," it said. "Knowledge that GCHQ exploits these products and the scale of our capability would raise public awareness generating unwelcome publicity for us and our political masters."

The decryption effort is particularly important to GCHQ. Its strategic advantage from its Tempora program – direct taps on transatlantic fibre-optic cables of major telecommunications corporations – was in danger of eroding as more and more big internet companies encrypted their traffic, responding to customer demands for guaranteed privacy.

Without attention, the 2010 GCHQ document warned, the UK's "Sigint utility will degrade as information flows changes, new applications are developed (and deployed) at pace and widespread encryption becomes more commonplace." Documents show that Edgehill's initial aim was to decode the encrypted traffic certified by three major (unnamed) internet companies and 30 types of Virtual Private Network (VPN) – used by businesses to provide secure remote access to their systems. By 2015, GCHQ hoped to have cracked the codes used by 15 major internet companies, and 300 VPNs.
Another program, codenamed Cheesy Name, was aimed at singling out encryption keys, known as 'certificates', that might be vulnerable to being cracked by GCHQ supercomputers.


Analysts on the Edgehill project were working on ways into the networks of major webmail providers as part of the decryption project. A quarterly update from 2012 notes the project's team "continue to work on understanding" the big four communication providers, named in the document as Hotmail, Google, Yahoo and Facebook, adding "work has predominantly been focused this quarter on Google due to new access opportunities being developed".

To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents. 

This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry."

"This enables GCHQ to tackle some of its most challenging targets," the report said. The efforts made by the NSA and GCHQ against encryption technologies may have negative consequences for all internet users, experts warn.

"Backdoors are fundamentally in conflict with good security," said Christopher Soghoian, principal technologist and senior policy analyst at the American Civil Liberties Union. "Backdoors expose all users of a backdoored system, not just intelligence agency targets, to heightened risk of data compromise." This is because the insertion of backdoors in a software product, particularly those that can be used to obtain unencrypted user communications or data, significantly increases the difficulty of designing a secure product."

This was a view echoed in a recent paper by Stephanie Pell, a former prosecutor at the US Department of Justice and non-resident fellow at the Center for Internet and Security at Stanford Law School.

"[An] encrypted communications system with a lawful interception back door is far more likely to result in the catastrophic loss of communications confidentiality than a system that never has access to the unencrypted communications of its users," she states.

Intelligence officials asked the Guardian, New York Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. 

The three organisations removed some specific facts but decided to publish the story because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of internet users in the US and worldwide.

Tuesday, September 3, 2013

Vietnam Bans Free Speech Online with Decree 72

from libertyblitzkrieg.com / by Micheal Kreiger: I’ve been watching the progressive erosion of civil liberties in Vietnam with a watchful eye for some time now. The country first appeared on my radar due to its particularly aggressive measures against the citizenry’s gold buying. As the progression usually goes, first a country will lash out against its own people for buying protection against the leadership’s mismanagement of the economy by blaming gold. Once that fails, a country will usually then start cracking down on civil liberties. Shortly after that we usually see the cracking of heads. It appears Vietnam has taken a frightening and dangerous step forward in the progression with Decree 72.

From the BBC:

A controversial law banning Vietnamese online users from discussing current affairs has come into effect.

The decree, known as Decree 72, says blogs and social websites should not be used to share news articles, but only personal information.

Dozens of activists, including bloggers, have been convicted for anti-state activity in the country this year.

The new law specifies that social networking sites such as Twitter and Facebook should only be used “to provide and exchange personal information”.

It also prohibits the online publication of material that “opposes” the Vietnamese government or “harms national security.”

Last month the US embassy in Hanoi said it was “deeply concerned by the decree’s provisions”, arguing that “fundamental freedoms apply online just as they do offline”.
 
Oh please. The rogue leadership in the USA is one financial crisis away from trying to do the exact same thing.

Syria, Egypt Strife Sparks Surge In Cyber Attacks

Syria, Egypt Strife Sparks Surge In Cyber Attacks
from reuters.com: Syria's civil war and political strife in Egypt have thrown up new battlegrounds on the Web and driven a surge in cyber attacks in the Middle East, according to a leading Internet security company. More than half of incidents in the Gulf this year were so-called "hacktivist" attacks - which account for only a quarter of cybercrime globally - as politically motivated programmers sabotaged opposing groups or institutions, executives from Intel Corp's software security division McAfee said on Tuesday. "It's mostly bringing down websites and defacing them with political messages - there has been a huge increase in cyber attacks in the Middle East," Christiaan Beek, McAfee director for incident response forensics in Europe, Middle East and Africa (EMEA), told Reuters. He attributed the attacks to the conflict in Syria, political turmoil in Egypt and the activities of hacking collective Anonymous. "It's difficult for people to protest in the street in the Middle East and so defacing websites and denial of service (DOS) attacks are a way to protest instead," said Beek.