Theverge.com - The US Senate has voted to overturn consumer-friendly internet privacy rules that would have prevented internet providers from sharing your web browsing history without permission.
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts
Mar 26, 2017
Oct 26, 2015
Desember, Beli Kartu SIM Mesti Tunjukkan KTP
Kompas.com - Dalam dua bulan mendatang, tepatnya 15 Desember 2015, pemerintah akan mulai menertibkan pendaftaran kartu SIM baru untuk telepon seluler. Semua pembeli kartu SIM diwajibkan menunjukkan dan mencatatkan kartu identitasnya kepada penjual.
Aug 21, 2015
Is Windows 10 really a privacy nightmare?
Cnn.com - Microsoft just can't seem to shake the image that Windows 10 is spying on you. And Microsoft's lack of transparency about Windows 10's privacy isn't doing much to dispel the notion.
Aug 7, 2015
5 Hal yang Perlu Diwaspadai dari Windows 10
Kompas.com - Windows 10 baru saja diluncurkan dan tampaknya antusiasme masyarakat cukup memuaskan. Sistem operasi teranyar ini, pada 24 jam pertama peluncuran, sudah diunduh 14 juta kali.
Mar 5, 2015
Feb 10, 2015
Warning Over TV Which Listens In On Users
Sky.com - Samsung has warned people against discussing sensitive and private information in the vicinity of its new smart televisions - because it will be translated into text and stored in a central computer.
The new privacy policy for the voice-activated television allows the company and its partners to listen in on everything that people say.
The policy states: "Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of voice recognition.
"While Samsung will not collect your spoken word, Samsung may still collect associated texts and other usage data so that we can evaluate the performance of the feature and improve it."
Samsung insists that the data is encrypted to keep it safe, and points out that owners can disconnect their TV from wifi to keep their data secure.
In a statement it said: "In all of our Smart TVs we employ industry-standard security safeguards and practices, including data encryption, to secure consumers' personal information and prevent unauthorised collection or use."
However, without an internet connection the voice recognition feature stops working entirely.
While lots of voice-recognition devices use an internet connection to better translate sounds into actions, the storing and sharing with third parties is a particular privacy concern for some Samsung users.
The privacy policy was first highlighted by a Reddit user, and many of the comments compared the situation to the telescreens described in George Orwell novel 1984.
In the book, Orwell wrote: "Any sound that Winston made, above the level of a very low whisper, would be picked up by, moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard."
The new privacy policy for the voice-activated television allows the company and its partners to listen in on everything that people say.
The policy states: "Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of voice recognition.
"While Samsung will not collect your spoken word, Samsung may still collect associated texts and other usage data so that we can evaluate the performance of the feature and improve it."
Samsung insists that the data is encrypted to keep it safe, and points out that owners can disconnect their TV from wifi to keep their data secure.
In a statement it said: "In all of our Smart TVs we employ industry-standard security safeguards and practices, including data encryption, to secure consumers' personal information and prevent unauthorised collection or use."
However, without an internet connection the voice recognition feature stops working entirely.
While lots of voice-recognition devices use an internet connection to better translate sounds into actions, the storing and sharing with third parties is a particular privacy concern for some Samsung users.
The privacy policy was first highlighted by a Reddit user, and many of the comments compared the situation to the telescreens described in George Orwell novel 1984.
In the book, Orwell wrote: "Any sound that Winston made, above the level of a very low whisper, would be picked up by, moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard."
Jan 9, 2015
Android app stops smartphone spies
| They won't know that you know that they know. |
Foxnews.com - You're not paranoid if they really are listening. A new Android app can detect surveillance attempts on your smartphone, including IMSI catchers (also called "stingrays"), hidden text messages and attacks exploiting the telephone-signal protocol known as Signaling System 7 (SS7).
Called SnoopSnitch, the app launched for free on the Google Play store Dec. 29. It can't protect your phone from snooping, but it can tell you that the snooping is happening.
IMSI catchers disguise themselves as legitimate cell towers, tricking GSM mobile phones into connecting to them and forwarding outgoing calls to the legitimate phone network. IMSI catchers can eavesdrop on calls and texts, extract personal data from connected phones and track phones' physical locations.
Law-enforcement agencies, such as the FBI, use stingrays in investigations, and a recent informal survey revealed more than a dozen IMSI catchers spread across the United States. The devices are so frequently used that the StingRay brand name used by a top manufacturer of IMSI catchers already applies generically.
Enter SnoopSnitch. The app was developed by German mobile-phone security researchers Karsten Nohl, Tobias Engel and Alex Senier, all of Berlin-based security company SRLabs, and was introduced in their presentation at the Chaos Computer Congress security conference in Hamburg Dec. 27.
SnoopSnitch can tell when a mobile device is switching from a legitimate cell tower to IMSI catcher, the researchers explained in their talk entitled "Mobile Self-Defense (SnoopSnitch)." Nohl also described SnoopSnitch as a "catcher catcher" in an interview with tech news site Motherboard.
Though it is free on the Google Play Store, not all Android devices will work with SnoopSnitch, as the app requires a Qualcomm chipset such a Snapdragon system-on-a-chip. A list of tested SnoopSnitch compatible devices is on the SRLabs website.
Many Sony and Samsung smartphones have Qualcomm chipsets, including the Samsung Galaxy S5, although SRLabs hasn't tested most of them for compatibility. Compatible devices also need to be rooted, run stock Android 4.1 or later rather than manufacturer or carrier builds, and, naturally, use the GSM carrier protocol (AT&T and T-Mobile) instead of CDMA (Sprint and Verizon Wireless).
Called SnoopSnitch, the app launched for free on the Google Play store Dec. 29. It can't protect your phone from snooping, but it can tell you that the snooping is happening.
IMSI catchers disguise themselves as legitimate cell towers, tricking GSM mobile phones into connecting to them and forwarding outgoing calls to the legitimate phone network. IMSI catchers can eavesdrop on calls and texts, extract personal data from connected phones and track phones' physical locations.
Law-enforcement agencies, such as the FBI, use stingrays in investigations, and a recent informal survey revealed more than a dozen IMSI catchers spread across the United States. The devices are so frequently used that the StingRay brand name used by a top manufacturer of IMSI catchers already applies generically.
Enter SnoopSnitch. The app was developed by German mobile-phone security researchers Karsten Nohl, Tobias Engel and Alex Senier, all of Berlin-based security company SRLabs, and was introduced in their presentation at the Chaos Computer Congress security conference in Hamburg Dec. 27.
SnoopSnitch can tell when a mobile device is switching from a legitimate cell tower to IMSI catcher, the researchers explained in their talk entitled "Mobile Self-Defense (SnoopSnitch)." Nohl also described SnoopSnitch as a "catcher catcher" in an interview with tech news site Motherboard.
Though it is free on the Google Play Store, not all Android devices will work with SnoopSnitch, as the app requires a Qualcomm chipset such a Snapdragon system-on-a-chip. A list of tested SnoopSnitch compatible devices is on the SRLabs website.
Many Sony and Samsung smartphones have Qualcomm chipsets, including the Samsung Galaxy S5, although SRLabs hasn't tested most of them for compatibility. Compatible devices also need to be rooted, run stock Android 4.1 or later rather than manufacturer or carrier builds, and, naturally, use the GSM carrier protocol (AT&T and T-Mobile) instead of CDMA (Sprint and Verizon Wireless).
Oct 20, 2014
Jun 10, 2014
Hati-hati, Stiker Keluarga di Mobil Itu Berbahaya
Detik.com - Akhir-akhir di Jakarta pengguna mobil banyak yang menempelkan stiker keluarga mereka di kaca belakang mobil. Mungkin sekilas stiker yang menunjukkan anggota keluarga terlihat begitu unik dan lucu.
Namun tahukah Anda stiker tersebut bisa membahayakan Anda sebagai pengendara dan keluarga Anda sebagai penumpang.
Seperti diberitakan jalopnik, 7online, dan Ohio Search and Rescue Organization, stiker ini norak, dan sangat berbahaya.
Karena Anda sebagai pengendara jelas memberitahukan kepada penjahat informasi mengenai jumlah keluarga Anda, nama anak dan mungkin tempat anda bekerja.
Tidak sampai disitu, jika ada seorang penculik anak yang ingin mengetahui berapa jumlah anak yang Anda. Tentu hal ini sangat mudah untuk penculik untuk mengetahui berapa jumlah anak yang Anda miliki. Dan tentu masih banyak lagi kejahatan yang bisa saja terjadi, karena Anda memberitahukan informasi keluarga Anda begitu transparan.
Kepolisian di Amerika pun menyarankan orangtua untuk tidak memasang lagi stiker keluarga. Intinya jangan memberi penjahat informasi yang gratis mengenai keluarga Anda.
Namun tahukah Anda stiker tersebut bisa membahayakan Anda sebagai pengendara dan keluarga Anda sebagai penumpang.
Seperti diberitakan jalopnik, 7online, dan Ohio Search and Rescue Organization, stiker ini norak, dan sangat berbahaya.
Karena Anda sebagai pengendara jelas memberitahukan kepada penjahat informasi mengenai jumlah keluarga Anda, nama anak dan mungkin tempat anda bekerja.
Tidak sampai disitu, jika ada seorang penculik anak yang ingin mengetahui berapa jumlah anak yang Anda. Tentu hal ini sangat mudah untuk penculik untuk mengetahui berapa jumlah anak yang Anda miliki. Dan tentu masih banyak lagi kejahatan yang bisa saja terjadi, karena Anda memberitahukan informasi keluarga Anda begitu transparan.
Kepolisian di Amerika pun menyarankan orangtua untuk tidak memasang lagi stiker keluarga. Intinya jangan memberi penjahat informasi yang gratis mengenai keluarga Anda.
Nov 7, 2013
Apple Says It Isn't Interested in Your Data: Here's What Apple Does and Doesn't Know About You
Vice.com - Tucked inside Apple's first-ever transparency report, published yesterday, was a not-so-subtle dig at the tech giant's competitors. "Our business does not depend on collecting personal data," Apple wrote. "We have no interest in amassing personal information about our customers."
It's no secret that for social web companies like Google or Facebook, collecting, storing, and analyzing data about every aspect of your life translates into cold, hard cash—the more sensitive and personal, the better. But in the emerging post-NSA new world order, the unwritten privacy-for-cool services agreement that drives the internet ecosystem is making netizens increasingly uneasy.
So in its report on the number requests for information it gets from government agencies, Apple took the opportunity to go on the offensive and remind its customers that it doesn't know as much about you as some others do. To a certain extent that's true. But it doesn't mean Apple doesn't collect personal data on its users. It sure does—a lot.
I went looking for the devil in the details to parse just how much Apple knows about you, and to what extent the company really does protect user privacy.
I'll start with the good news. Shortly after the details of the NSA's Prism program were leaked, Apple published a privacy statement explaining the user information it can't retrieve for the authorities, either because they're encrypted or not stored on the company's servers. It reminded users of this again in yesterday's report: "We protect personal conversations by providing end-to-end encryption over iMessage and FaceTime. We do not store location data, Maps searches, or Siri requests in any identifiable form."
So what information does it have? Apple's privacy policy breaks it down into two categories. Obviously, the company knows your name, address, email, and credit card information, and so forth. It uses that personal information "for internal purposes such as auditing, data analysis, and research to improve Apple’s products, services, and customer communications" and "to help us develop, deliver, and improve our products, services, content, and advertising."
Things get more interesting with the second category: "non-personal" information, which is any user data that isn't associated with a specific individual. We're talking about details like customers' jobs, real-time location, habits, and the like. That data, the company says, is collected anonymously. Apple has free reign to share, sell, or store it however it damn pleases.
Apple also, like all internet companies, relies on cookies to track user activity. It knows your shopping habits in the Apple Store and where you go when surfing the web in the Safari browser, and uses that insight for advertising and marketing.
Then there's Siri. The company stated that it doesn't store Siri communications in an "identifiable form." But what's happening behind the scenes when you use the voice recognition feature comes awfully close to being a tell-all about your private life. Per the company's user agreement:
It's no secret that for social web companies like Google or Facebook, collecting, storing, and analyzing data about every aspect of your life translates into cold, hard cash—the more sensitive and personal, the better. But in the emerging post-NSA new world order, the unwritten privacy-for-cool services agreement that drives the internet ecosystem is making netizens increasingly uneasy.
So in its report on the number requests for information it gets from government agencies, Apple took the opportunity to go on the offensive and remind its customers that it doesn't know as much about you as some others do. To a certain extent that's true. But it doesn't mean Apple doesn't collect personal data on its users. It sure does—a lot.
I went looking for the devil in the details to parse just how much Apple knows about you, and to what extent the company really does protect user privacy.
I'll start with the good news. Shortly after the details of the NSA's Prism program were leaked, Apple published a privacy statement explaining the user information it can't retrieve for the authorities, either because they're encrypted or not stored on the company's servers. It reminded users of this again in yesterday's report: "We protect personal conversations by providing end-to-end encryption over iMessage and FaceTime. We do not store location data, Maps searches, or Siri requests in any identifiable form."
So what information does it have? Apple's privacy policy breaks it down into two categories. Obviously, the company knows your name, address, email, and credit card information, and so forth. It uses that personal information "for internal purposes such as auditing, data analysis, and research to improve Apple’s products, services, and customer communications" and "to help us develop, deliver, and improve our products, services, content, and advertising."
Things get more interesting with the second category: "non-personal" information, which is any user data that isn't associated with a specific individual. We're talking about details like customers' jobs, real-time location, habits, and the like. That data, the company says, is collected anonymously. Apple has free reign to share, sell, or store it however it damn pleases.
Apple also, like all internet companies, relies on cookies to track user activity. It knows your shopping habits in the Apple Store and where you go when surfing the web in the Safari browser, and uses that insight for advertising and marketing.
Then there's Siri. The company stated that it doesn't store Siri communications in an "identifiable form." But what's happening behind the scenes when you use the voice recognition feature comes awfully close to being a tell-all about your private life. Per the company's user agreement:
When you use Siri or Dictation, the things you say will be recorded and sent to Apple in order to convert what you say into text and, for Siri, to also process your requests. Your device will also send Apple other information, such as your first name and nickname; the names, nicknames, and relationship with you (e.g., “my dad”) of your address book contacts; and song names in your collection (collectively, your “User Data”). All of this data is used to help Siri and Dictation understand you better and recognize what you say. It is not linked to other data that Apple may have from your use of other Apple services.
To sum it up, Apple gathers up about as much personal information on users as any other big tech company. The main difference is, it says it doesn't connect the dots. It may know everything about you, but it doesn't know you're you.
It might, however, know where you are. The most controversial part of Apple's data collection practices is real-time location tracking. There was a big to-do made about iPhone location tracking a couple years ago, when it was revealed that Apple collects and stores as much as 12 years worth of user geodata on its devices, unencrypted. That can, and was, hacked into and accessed and used to create this very creepy map of exactly where your iPhone is in real-time.
Smartphones are regularly transmitting user locations back to Apple, which is amassing a database of anonymous location data. Google's Android does this too. Apple addressed privacy concerns by assuring users the data is encrypted when it's sent to the company, so Apple doesn't actually know where you, specifically, are at all points in time.
But concerns about location tracking haven't entirely gone away, and now it seems the company is doubling down on real-time GPS information with a mind to future product features. Yesterday, the company was awarded a patent for a technology that "can adaptively track a user's location and use the data to intelligently control secondary devices at another locale, such as home appliances," Apple Insider reported.
Apple—like other tech firms—wants to build a home automation system to connect the growing plethora of smart objects lying around the house. According to the patent, its idea is to take the user out of the process and have it all center around a "first device" that sends back specific details about your real-time location and habits to automatically control the other devices.
In other words, if the iPhone in your pocket knows you're almost home, it could trigger the garage door to open. Apple knows your current location and guesses your future actions based on that.
Tech companies are fond of saying they work hard to balance user privacy with the ability to provide innovative services and products. Taken at face value, Apple's statements and policies suggest the company's balancing on a tiny tightrope. Even if it does anonymize non-personal information, separate the sensitive life details you reveal to Siri or Safari from the company's user profile of you, and not associate your always-tracked device with your real identity, there's no question that personal user data big part of any technology company's business model these days. Even Apple.
But concerns about location tracking haven't entirely gone away, and now it seems the company is doubling down on real-time GPS information with a mind to future product features. Yesterday, the company was awarded a patent for a technology that "can adaptively track a user's location and use the data to intelligently control secondary devices at another locale, such as home appliances," Apple Insider reported.
Apple—like other tech firms—wants to build a home automation system to connect the growing plethora of smart objects lying around the house. According to the patent, its idea is to take the user out of the process and have it all center around a "first device" that sends back specific details about your real-time location and habits to automatically control the other devices.
In other words, if the iPhone in your pocket knows you're almost home, it could trigger the garage door to open. Apple knows your current location and guesses your future actions based on that.
Tech companies are fond of saying they work hard to balance user privacy with the ability to provide innovative services and products. Taken at face value, Apple's statements and policies suggest the company's balancing on a tiny tightrope. Even if it does anonymize non-personal information, separate the sensitive life details you reveal to Siri or Safari from the company's user profile of you, and not associate your always-tracked device with your real identity, there's no question that personal user data big part of any technology company's business model these days. Even Apple.
Oct 8, 2013
Russia to monitor 'all communications' at Winter Olympics in Sochi
Theguardian.com - Exclusive: Investigation uncovers FSB surveillance system – branded 'Prism on steroids' – to listen to all athletes and visitors.
Athletes and spectators attending the Winter Olympics in Sochi in February will face some of the most invasive and systematic spying and surveillance in the history of the Games, documents shared with the Guardian show.
Russia's powerful FSB security service plans to ensure that no communication by competitors or spectators goes unmonitored during the event, according to a dossier compiled by a team of Russian investigative journalists looking into preparations for the 2014 Games.
In a ceremony on Red Square on Sunday afternoon, the president, Vladimir Putin, held the Olympic flame aloft and sent it on its epic journey around the country, saying Russia and its people had always been imbued with the qualities of "openness and friendship", making Sochi the perfect destination for the Olympics.
But government procurement documents and tenders from Russian communication companies indicate that newly installed telephone and internet spying capabilities will give the FSB free rein to intercept any telephony or data traffic and even track the use of sensitive words or phrases mentioned in emails, webchats and on social media.
The journalists, Andrei Soldatov and Irina Borogan, who are experts on the Russian security services, collated dozens of open source technical documents published on the Zakupki government procurement agency website, as well as public records of government oversight agencies. They found that major amendments have been made to telephone and Wi-Fi networks in the Black Sea resort to ensure extensive and all-permeating monitoring and filtering of all traffic, using Sorm, Russia's system for intercepting phone and internet communications.
The Sorm system is being modernised across Russia, but particular attention has been paid to Sochi given the large number of foreign visitors expected next year. Technical specifications set out by the Russian state telecoms agency also show that a controversial technology known as deep packet inspection, which allows intelligence agencies to filter users by particular keywords, is being installed across Russia's networks, and is required to be compatible with the Sorm system.
"For example you can use the keyword Navalny, and work out which people in a particular region are using the word Navalny," says Soldatov, referring to Alexei Navalny, Russia's best-known opposition politician. "Then, those people can be tracked further."
Ron Deibert, a professor at the University of Toronto and director of Citizen Lab, which co-operated with the Sochi research, describes the Sorm amendments as "Prism on steroids", referring to the programme used by the NSA in the US and revealed to the Guardian by the whistleblower Edward Snowden. "The scope and scale of Russian surveillance are similar to the disclosures about the US programme but there are subtle differences to the regulations," says Deibert. "We know from Snowden's disclosures that many of the checks were weak or sidestepped in the US, but in the Russian system permanent access for Sorm is a requirement of building the infrastructure."
"Even as recently as the Beijing Olympics, the sophistication of surveillance and tracking capabilities were nowhere near where they are today."
Gus Hosein, executive director of Privacy International, which also co-operated with the research, said: "Since 2008, more people are travelling with smartphones with far more data than back then, so there is more to spy on."
Wary of Sorm's capabilities, earlier this year a leaflet from the US state department's bureau of diplomatic security warned anyone travelling to the Games to be extremely cautious with communications.
"Business travellers should be particularly aware that trade secrets, negotiating positions, and other sensitive information may be taken and shared with competitors, counterparts, and/or Russian regulatory and legal entities," the document reads. The advice contains an extraordinary list of precautions for visitors who wish to ensure safe communications, such as removing batteries from phones when not in use and only travelling with "clean" devices.
Soldatov and Borogan have discovered that the FSB has been working since 2010 to upgrade the Sorm system to ensure it can cope with the extra traffic during the Games. All telephone and ISP providers have to install Sorm boxes in their technology by law, and once installed, the FSB can access data without the provider ever knowing, meaning every phone call or internet communication can be logged. Although the FSB technically requires a warrant to intercept a communication, it is not obliged to show it to anyone.
Tellingly, the FSB has appointed one of its top counterintelligence chiefs, Oleg Syromolotov, to be in charge at Sochi: security will thus be overseen by someone who has spent his career chasing foreign spies rather than terrorists.
Another target may well be gay rights, likely to be one of the biggest issues of the Games. Putin has said that competitors who wear rainbow pins, for example, will not be arrested under the country's controversial new law that bans "homosexual propaganda". However, it is likely that any attempts to stage any kind of rally or gathering to support gay rights will be ruthlessly broken up by police, as has been the case on numerous occasions in Russian cities in the past. Using DPI, Russian authorities will be able to identify, tag and follow all visitors to the Olympics, both Russian and foreign, who are discussing gay issues, and possibly planning to organise protests.
"Athletes may have particular political views, or they may be openly gay," says Deibert. "I think given recent developments in Russia, we have to be worried about these issues."
At a rare FSB press conference this week, an official, Alexei Lavrishchev, denied security and surveillance at the Games would be excessive, and said that the London Olympics featured far more intrusive measures. "There, they even put CCTV cameras in, excuse me for saying it, the toilets," said Lavrishchev. "We are not taking this kind of measure."
The FSB did not respond to a request for comment from the Guardian, while a spokesperson for the Sochi Olympics referred all requests to the security services. But Russian authorities often express a belief that NGOs working on human rights and other issues have subversive agendas dictated from abroad, and the FSB apparently feels that with so many potentially dangerous foreigners descending on the Black Sea resort for the Olympics, it has a duty to keep an eye on them.
In the end, the goal is overarching, but simple, says Soldatov: "Russian authorities want to make sure that every connection and every move made online in Sochi during the Olympics will be absolutely transparent to the secret services of the country."
Athletes and spectators attending the Winter Olympics in Sochi in February will face some of the most invasive and systematic spying and surveillance in the history of the Games, documents shared with the Guardian show.
Russia's powerful FSB security service plans to ensure that no communication by competitors or spectators goes unmonitored during the event, according to a dossier compiled by a team of Russian investigative journalists looking into preparations for the 2014 Games.
In a ceremony on Red Square on Sunday afternoon, the president, Vladimir Putin, held the Olympic flame aloft and sent it on its epic journey around the country, saying Russia and its people had always been imbued with the qualities of "openness and friendship", making Sochi the perfect destination for the Olympics.
But government procurement documents and tenders from Russian communication companies indicate that newly installed telephone and internet spying capabilities will give the FSB free rein to intercept any telephony or data traffic and even track the use of sensitive words or phrases mentioned in emails, webchats and on social media.
The journalists, Andrei Soldatov and Irina Borogan, who are experts on the Russian security services, collated dozens of open source technical documents published on the Zakupki government procurement agency website, as well as public records of government oversight agencies. They found that major amendments have been made to telephone and Wi-Fi networks in the Black Sea resort to ensure extensive and all-permeating monitoring and filtering of all traffic, using Sorm, Russia's system for intercepting phone and internet communications.
The Sorm system is being modernised across Russia, but particular attention has been paid to Sochi given the large number of foreign visitors expected next year. Technical specifications set out by the Russian state telecoms agency also show that a controversial technology known as deep packet inspection, which allows intelligence agencies to filter users by particular keywords, is being installed across Russia's networks, and is required to be compatible with the Sorm system.
"For example you can use the keyword Navalny, and work out which people in a particular region are using the word Navalny," says Soldatov, referring to Alexei Navalny, Russia's best-known opposition politician. "Then, those people can be tracked further."
Ron Deibert, a professor at the University of Toronto and director of Citizen Lab, which co-operated with the Sochi research, describes the Sorm amendments as "Prism on steroids", referring to the programme used by the NSA in the US and revealed to the Guardian by the whistleblower Edward Snowden. "The scope and scale of Russian surveillance are similar to the disclosures about the US programme but there are subtle differences to the regulations," says Deibert. "We know from Snowden's disclosures that many of the checks were weak or sidestepped in the US, but in the Russian system permanent access for Sorm is a requirement of building the infrastructure."
"Even as recently as the Beijing Olympics, the sophistication of surveillance and tracking capabilities were nowhere near where they are today."
Gus Hosein, executive director of Privacy International, which also co-operated with the research, said: "Since 2008, more people are travelling with smartphones with far more data than back then, so there is more to spy on."
Wary of Sorm's capabilities, earlier this year a leaflet from the US state department's bureau of diplomatic security warned anyone travelling to the Games to be extremely cautious with communications.
"Business travellers should be particularly aware that trade secrets, negotiating positions, and other sensitive information may be taken and shared with competitors, counterparts, and/or Russian regulatory and legal entities," the document reads. The advice contains an extraordinary list of precautions for visitors who wish to ensure safe communications, such as removing batteries from phones when not in use and only travelling with "clean" devices.
Soldatov and Borogan have discovered that the FSB has been working since 2010 to upgrade the Sorm system to ensure it can cope with the extra traffic during the Games. All telephone and ISP providers have to install Sorm boxes in their technology by law, and once installed, the FSB can access data without the provider ever knowing, meaning every phone call or internet communication can be logged. Although the FSB technically requires a warrant to intercept a communication, it is not obliged to show it to anyone.
Tellingly, the FSB has appointed one of its top counterintelligence chiefs, Oleg Syromolotov, to be in charge at Sochi: security will thus be overseen by someone who has spent his career chasing foreign spies rather than terrorists.
Another target may well be gay rights, likely to be one of the biggest issues of the Games. Putin has said that competitors who wear rainbow pins, for example, will not be arrested under the country's controversial new law that bans "homosexual propaganda". However, it is likely that any attempts to stage any kind of rally or gathering to support gay rights will be ruthlessly broken up by police, as has been the case on numerous occasions in Russian cities in the past. Using DPI, Russian authorities will be able to identify, tag and follow all visitors to the Olympics, both Russian and foreign, who are discussing gay issues, and possibly planning to organise protests.
"Athletes may have particular political views, or they may be openly gay," says Deibert. "I think given recent developments in Russia, we have to be worried about these issues."
At a rare FSB press conference this week, an official, Alexei Lavrishchev, denied security and surveillance at the Games would be excessive, and said that the London Olympics featured far more intrusive measures. "There, they even put CCTV cameras in, excuse me for saying it, the toilets," said Lavrishchev. "We are not taking this kind of measure."
The FSB did not respond to a request for comment from the Guardian, while a spokesperson for the Sochi Olympics referred all requests to the security services. But Russian authorities often express a belief that NGOs working on human rights and other issues have subversive agendas dictated from abroad, and the FSB apparently feels that with so many potentially dangerous foreigners descending on the Black Sea resort for the Olympics, it has a duty to keep an eye on them.
In the end, the goal is overarching, but simple, says Soldatov: "Russian authorities want to make sure that every connection and every move made online in Sochi during the Olympics will be absolutely transparent to the secret services of the country."
Aug 29, 2013
JustDelete.me helps you wash away your digital life
Foxnews.com - Deleting your unused or unwanted online accounts can be a giant pain – and, in some cases, is literally impossible. But a new Web directory, JustDelete.me, makes the process a little less daunting.
Launched last week by developer Robb Lewis and designed by Ed Poole, JustDelete.me provides a growing list of Internet-connected services, with links and information about the account deletion process. When available, direct links to account delete pages are provided. JustDelete.me also categorizes each service into "easy," "medium," "hard," and "impossible," depending on the difficulty of deleting an account from that service. The site also provides tidbits of information about account deletion for each service.
Google and Instagram, for example, both land in the "easy" category, since these companies only require that users login and opt to delete their accounts. Amazon, on the other hand, gets a "hard" tag due to the fact that you have to send an email to the company requesting to have your account deleted; JustDelete.me links directly to Amazon’s appropriate contact form for doing so.
Other services, like Craigslist and Evernote, land in the “impossible” category. Evernote only allows users to temporarily deactivate their accounts, notes JustDelete.me, while Craigslist offers no way for users to delete accounts, "not even by contacting support."
In a post on his blog, Lewis says he came up with the idea for JustDelete.me after hearing how difficult it is to delete a Skype or Netflix account.
JustDelete.me went live on August 19, with 16 services in its directory. The list has since grown to nearly 130 services, at the time of this writing. And fellow Web developer Mike Rogers created a Google Chrome extension to make the account deletion process even easier.
Poole says he believes the booming popularity JustDelete.me has received – more than 500,000 page views in its first week – stems from growing discontent with Internet-connected services, in light of the recent revelations about NSA surveillance. The "honeymoon period" for the Web, says Poole, has ended.
"Five years ago, when things like Facebook and MySpace were still in their infancy, people didn’t see the harm in sharing their personal information," said Poole in an email to Digital Trends. "Recently, with the drama surrounding the NSA and stories of large companies selling personal information, I think the public has realized we can’t just put anything online, as nobody really knows what information is 'safe' anymore."
According to Poole, the creation of JustDelete.me has simply "emphasized how much online privacy and security is in the public consciousness."
Launched last week by developer Robb Lewis and designed by Ed Poole, JustDelete.me provides a growing list of Internet-connected services, with links and information about the account deletion process. When available, direct links to account delete pages are provided. JustDelete.me also categorizes each service into "easy," "medium," "hard," and "impossible," depending on the difficulty of deleting an account from that service. The site also provides tidbits of information about account deletion for each service.
Google and Instagram, for example, both land in the "easy" category, since these companies only require that users login and opt to delete their accounts. Amazon, on the other hand, gets a "hard" tag due to the fact that you have to send an email to the company requesting to have your account deleted; JustDelete.me links directly to Amazon’s appropriate contact form for doing so.
Other services, like Craigslist and Evernote, land in the “impossible” category. Evernote only allows users to temporarily deactivate their accounts, notes JustDelete.me, while Craigslist offers no way for users to delete accounts, "not even by contacting support."
In a post on his blog, Lewis says he came up with the idea for JustDelete.me after hearing how difficult it is to delete a Skype or Netflix account.
JustDelete.me went live on August 19, with 16 services in its directory. The list has since grown to nearly 130 services, at the time of this writing. And fellow Web developer Mike Rogers created a Google Chrome extension to make the account deletion process even easier.
Poole says he believes the booming popularity JustDelete.me has received – more than 500,000 page views in its first week – stems from growing discontent with Internet-connected services, in light of the recent revelations about NSA surveillance. The "honeymoon period" for the Web, says Poole, has ended.
"Five years ago, when things like Facebook and MySpace were still in their infancy, people didn’t see the harm in sharing their personal information," said Poole in an email to Digital Trends. "Recently, with the drama surrounding the NSA and stories of large companies selling personal information, I think the public has realized we can’t just put anything online, as nobody really knows what information is 'safe' anymore."
According to Poole, the creation of JustDelete.me has simply "emphasized how much online privacy and security is in the public consciousness."
Aug 2, 2013
NSA program reportedly allows analysts to track emails, chats, web searches
Foxnews.com - The National Security Agency is operating a massive database system that allows analysts to scour individuals' emails, chats and Internet browsing histories at will, according to a new report from The Guardian based on leaked documents.
The article was quickly challenged by the NSA. In a statement forwarded to Fox News, the agency said "allegations of widespread, unchecked analyst access to NSA collection data are simply not true."
The agency acknowledged the existence of the program -- called XKeyscore -- but said access is limited and suggested it was mainly aimed at foreign intelligence targets.
The Guardian article described it differently. According to the piece, the XKeyscore program is the "widest-reaching" system the agency has and allows analysts without prior authorization to dig around the database by filling out an on-screen form giving a basic justification.
According to the report, the program covers "nearly everything a typical user does on the internet" including emails and websites visited. It also reportedly allows analysts to intercept Internet activity in "real time."
The Guardian report seems to make a distinction between what is technically possible under this program and what is legally allowed. It notes that U.S. law requires the NSA to get a warrant if the target is a U.S. individual -- but says the XKeyscore program provides "the technological capability, if not the legal authority" to go after Americans without a warrant as long as an analyst knows information like an email or IP address.
The NSA, in its statement, pushed back on these assertions.
"The implication that NSA's collection is arbitrary and unconstrained is false," the agency said. "NSA's activities are focused and specifically deployed against -- and only against -- legitimate foreign intelligence targets in response to requirements that our leaders need for information necessary to protect our nation and its interests."
The agency said those with access to the system are trained on their "ethical and legal obligations." The agency complained that the ongoing leaks continue to jeopardize security.
The statement said the programs as a whole have helped defend the nation, and that as of 2008, "there were over 300 terrorists captured using intelligence generated from XKEYSCORE."
The report was based on documents by NSA leaker Edward Snowden, who continues to evade capture by the U.S.
Journalist Glenn Greenwald, who wrote the Guardian article, had claimed over the weekend that he had evidence to back up Snowden's past claims that low-level workers and other officials could tap into almost anyone's communications.
The report comes after several intelligence officials testified Wednesday on Capitol Hill about the surveillance programs, defending them as vital to national security.
President Obama also told Democratic lawmakers on Wednesday that he's open to some changes in NSA programs, according to those present at the meeting.
Meanwhile, the Office of the Director of National Intelligence declassified a set of documents on Wednesday that begin to shed light on the authorization and rules behind the agency's phone and Internet record collection.
The documents stress that these programs allow the government to collect basic information about phone calls and email communications, but not the content of those messages. They say most of the information "is never reviewed," while describing the programs as vital to the "early warning system" for detecting terror plots.
The article was quickly challenged by the NSA. In a statement forwarded to Fox News, the agency said "allegations of widespread, unchecked analyst access to NSA collection data are simply not true."
The agency acknowledged the existence of the program -- called XKeyscore -- but said access is limited and suggested it was mainly aimed at foreign intelligence targets.
The Guardian article described it differently. According to the piece, the XKeyscore program is the "widest-reaching" system the agency has and allows analysts without prior authorization to dig around the database by filling out an on-screen form giving a basic justification.
According to the report, the program covers "nearly everything a typical user does on the internet" including emails and websites visited. It also reportedly allows analysts to intercept Internet activity in "real time."
The Guardian report seems to make a distinction between what is technically possible under this program and what is legally allowed. It notes that U.S. law requires the NSA to get a warrant if the target is a U.S. individual -- but says the XKeyscore program provides "the technological capability, if not the legal authority" to go after Americans without a warrant as long as an analyst knows information like an email or IP address.
The NSA, in its statement, pushed back on these assertions.
"The implication that NSA's collection is arbitrary and unconstrained is false," the agency said. "NSA's activities are focused and specifically deployed against -- and only against -- legitimate foreign intelligence targets in response to requirements that our leaders need for information necessary to protect our nation and its interests."
The agency said those with access to the system are trained on their "ethical and legal obligations." The agency complained that the ongoing leaks continue to jeopardize security.
The statement said the programs as a whole have helped defend the nation, and that as of 2008, "there were over 300 terrorists captured using intelligence generated from XKEYSCORE."
The report was based on documents by NSA leaker Edward Snowden, who continues to evade capture by the U.S.
Journalist Glenn Greenwald, who wrote the Guardian article, had claimed over the weekend that he had evidence to back up Snowden's past claims that low-level workers and other officials could tap into almost anyone's communications.
The report comes after several intelligence officials testified Wednesday on Capitol Hill about the surveillance programs, defending them as vital to national security.
President Obama also told Democratic lawmakers on Wednesday that he's open to some changes in NSA programs, according to those present at the meeting.
Meanwhile, the Office of the Director of National Intelligence declassified a set of documents on Wednesday that begin to shed light on the authorization and rules behind the agency's phone and Internet record collection.
The documents stress that these programs allow the government to collect basic information about phone calls and email communications, but not the content of those messages. They say most of the information "is never reviewed," while describing the programs as vital to the "early warning system" for detecting terror plots.
Subscribe to:
Posts (Atom)