Showing posts with label Five Eyes. Show all posts
Showing posts with label Five Eyes. Show all posts

Saturday, February 01, 2014

CSEC : Spy vs. WiFi


So what exactly have we learned here from this 2012 CSEC pilot project that tracked wireless devices across airports, hotels, conference centres, coffee shops, and libraries, starting from a "single Canadian airport WiFi IP address" and "two weeks worth of IP-ID data" from a "Special Canadian Source", using ">300,000 active IDs over two weeks" in a "modest size city" as a control group?

1.  As Defence Minister Rob Nicholson, CSEC, and CSEC watchdog commissioner Plouffe have all now explained to us, CSEC wasn't "tracking" these Canadians because that would be illegal and our privacy is important to them.

2. If you haven't been issued a special decoder ring providing a CSECret definition of the words "tracking" and "metadata", whose fault is that?

3. If you are a hypothetical kidnapper from a rural area coming to the big city to make your three ransom phone calls - carefully spaced exactly 40 hours apart as seen in the nice CSEC powerpoint spreadsheet - at least try to blend in with the rest of the internet by forwarding some cat pictures around as well so your lone ransom calls don't stick out like a sore thumb.
If you don't much care for forwarding cat pictures, use a friggin' payphone.
.
Sat AM update : For those of you wondering what the fuck Calandra meant in the House yesterday when he called Glenn Greenwald, co-journalist on the CBC exposé, "a porn spy" - it's the Canadian nonsense version of "espionage pornographer", used two weeks ago by American Enterprise Institute's Marc Thiessen to describe whistleblower Edward Snowden.  
I guess the PMO thought Thiessen's version sounded too elitist.    h/t Techdirt
.
Sun AM update : Ryan Gallagher, one of the three journos on the original CBC piece, parses the CSEC and gov reaction. 
.
The always incisive Lux Ex Umbra looks at how we should interpret CSEC's mandate now. 
If, as CSEC seems to maintain, its collection of metadata is both legally within its mandate and likely to be upheld by the courts, then it would appear :
  1. there is no upper limit to collection of that data
  2. the section of its mandate referring to not directing its operations "at Canadians or any person in Canada" does not apply, and  
  3. given that part 3 of CSEC's mandate is to assist CSIS, the RCMP, CBSA, and other intelligence agencies, do those agencies require a separate warrant to access CSEC's metadata collection?

And a question of my own - Does this metadata automatically get shared with FiveEyes?
Or to put it more dramatically - is Skynet operational now?

.

Wednesday, October 09, 2013

CSEC data mining Brazil's mining data


Amusing to see both NaPo and the G&M are hosting remarks from former CSIS deputy director Ray Boisvert dismissing the recent Snowden/Greenwald docs which revealed CSEC spied on Brazil's Mines and Energy Ministry
Snowden was present at the Five Eyes conference where the CSEC presentation on their Olympia spying program on Brazil took place.
Boisvert in both papers:
“We were all too busy chasing bad guys who can actually kill people. The idea that we spend a lot of time, or any time at all, on a country like Brazil is pretty low margin stuff, not likely to happen.”
The docs probably only represent "a war gaming exercise", says Boisvert, just “paper exercises” :
 'OK, let’s say our target in counter-terrorism lives in Mali and we have to go up against the Malian telecommunications system.’ They’ll go look at another country and say, ‘OK, well they have a similar network so let’s do a paper exercise and say ‘what do we need?’” he said. “I think that’s all this was.'
Because when you're "busy chasing bad guys who can actually kill people" and stuff, naturally your anti-terrorism war games will entail a cyber-espionage program searching for corporate secrets in a country where 40 of your own country's mining corporations are operating. 

Wouldn't have anything to do with looking for info on Brazil wanting to block a Canadian mining company from opening the largest open pit gold mine in Brazil, would it? Brazilian prosecutors say the company has failed to study the impact on local Indian communities and has advertized on its own website "plans to build a mine twice the size of the project first described in an environmental assessment it gave state officials."

Ok, foreign media. The Guardian, today : 
Canadian spies met with energy firms, documents reveal
The Canadian government agency that allegedly hacked into the Brazilian mining and energy ministry has participated in secret meetings in Ottawa where Canadian security agencies briefed energy corporations.
According to freedom of information documents obtained by the Guardian, the meetings – conducted twice a year since 2005 – involved federal ministries, spy and police agencies, and representatives from scores of companies who obtained high-level security clearance. 
Meetings were officially billed to discuss "threats" to energy infrastructure but also covered "challenges to energy projects from environmental groups", "cyber security initiatives" and "economic and corporate espionage".
The documents – heavily redacted agendas – do not indicate that any international espionage was shared by CSEC officials, but the meetings were an opportunity for government agencies and companies to develop "ongoing trusting relations" that would help them exchange information "off the record", wrote an official from the Natural Resources ministry in 2010.
Thank you, Enbridge, for providing the snacks for the one in May 2013.  
Keith Stewart, an energy policy analyst with Greenpeace Canada, said:
"There seems to be no limit to what the Harper government will do to help their friends in the oil and mining industries. They've muzzled scientists, gutted environmental laws, reneged on our international climate commitments, labelled environmental critics as criminals and traitors, and have now been caught engaging in economic espionage in a friendly country. Canadians, and our allies, have a right to ask who exactly is receiving the gathered intelligence and whose interests are being served."
Good question. And did no Canadian media request these same FOIs?
You know, I think I blogged about government security briefings to energy companies a few years ago - I'll see if I can find it.

Meanwhile, would be interesting to hear Boisvert's explanation as to why the CSEC logo appeared on another NSA doc about intercepting phone calls and emails of ministers and diplomats at the 2009 G20 summit in London
More "paper exercises"? Filling in an empty spot on the page while chasing bad guys? 

And re the recent NSA spying on Brazil PM Dilma Rousseff and the state oil company Petrobras. Did CSEC help out its Five Eyes partner there too?
Back in 1983, CSEC spied on two of Margaret Thatcher's cabinet ministers on behalf of Thatcher and Britain's spy agency GCHQ, so this wouldn't exactly be new territory for CSEC.

Fun fact : The annual report on CSEC produced by its independent watchdog commissioner must first be vetted by CSEC "for national security reasons" before it can be released. [head/desk]
.
P.S. I pillaged the CSEC slide at top from Lux ex Umbra, where you can view the rest of them.

Friday update : Don't shrug at spying.
.

Thursday, September 26, 2013

Get Your NSA On, Romulans!


Techdirt: NSA Chief Begs His Public To Help Agency 'Get The Facts Out'
Apparently sitting in the captain's chair on the bridge of the USS Surveillance* has lost its thrill.  
Keith Alexander, the director of the National Security Agency, called Wednesday on the public to help defend his agency's powers as Congress mulls restrictions aimed at protecting privacy. 
He warned that if Congress hampers the NSA's ability to gather information, it could allow for terrorist attacks in the United States similar to last week's massacre in a mall in Nairobi, Kenya. 
"If you take those [surveillance powers] away, think about the last week and what will happen in the future," he said. "If you think it's bad now, wait until you get some of those things that happened in Nairobi." 
Yeah, just you wait. 'Some of those things' like the Boston Marathon bombing or the Navy Yard shooting - things like that. 


Meanwhile here at home, it has now been two weeks since Canadian media declined to make any mention whatsoever of an NSA agreement purporting to share raw data with Israel  - data which 
"includes, but is not limited to, unevaluated and unminimized transcripts, gists, facsimiles, telex, voice and Digital Network Intelligence metadata and content."
So - likely emails and phone calls as well then.
Not to worry though. 
The Israelis were required to “destroy upon recognition” any communication “that is either to or from an official of the US government“. Such communications included those of “officials of the executive branch (including the White House, cabinet departments, and independent agencies), the US House of Representatives and Senate (member and staff) and the US federal court system (including, but not limited to, the supreme court)”.
So that's the important USians taken care of. What about the rest of us?
The doc specifies that US citizens are not to be targeted and that the NSA has agreements with its Five Eyes partners - Canada, Australia, New Zealand, and the UK - to protect information on their citizens and that Israel should respect those privacy agreements when looking through the data.

That must be why our media wasn't fussed enough to mention it.


.

Friday, September 06, 2013

NSA is breaking the internet

Testifying before the US Senate last month, NSA Deputy Director John Inglis conceded that the bulk collection of phone records of millions of Americans under Section 215 of the Patriot Act has been key in stopping only one terror plot.

But then it never was just about phones and national security, was it?

In his 2013 Budget Intelligence Request, NSA director James Clapper - who lied to the US Congress under oath about the scope of secret surveillance and was then appointed by Obama to an independent review board to investigate his own agency - advised :
“We are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit Internet traffic." 
"The SIGINT Enabling Project actively engages the US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs. These design changes make the systems in question exploitable through SIGINT collection with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact."
"the consumer and other adversaries"

Under a section for release to Five Eyes - that's us!
Insert vulnerabilities into commercial encryption systems, IT systems, networks ...
Collect target network data and metadata via cooperative network carriers...
The joint Guardian NYTimes ProPublica release yesterday doesn't tell us who those "co-operative" network carriers and IT systems are - publish the names! - but the NSA is pretty clear about their own role - weakening encryption standards and writing code with backdoors in them for security vendors . 
The NSA/GCHQ help them build the locks to keep your data safe; then the government gets one key and you get the other one.

The possibility for corruption and breaches of security built into a system that includes scoping out cell phones, tablets, Facebook, emails, web searches, medical and banking data are endless - industrial espionage, blackmailing political figures, fixing elections, corrupting markets, internet scams ...
"Snowden, one of 850,000 people in the US with top-secret clearance..."
And have any of these other 850,000 top-secret clearance people in what is already a massively corrupted security system taken it one stage farther and facilitated an internal black market for information about stocks, patents, trade deals, etc. within the larger market? Would there be any way of knowing? The NSA wouldn't know - they've already admitted to having no clue what Snowden took.

9/11 changed everything.  The Five Eyes govs upped the spying on their own citizens and started locking up whistleblowers while simultaneously supplying AlQaeda et al with arms, training, and money.

Nothing in the Canadian media about yesterday's release yet.
Update : National Post : NSA has now cracked common Internet encryption, including personal email and online banking
CBC : NSA cracked most online encryption says report

My fear is that we'll agree to ignore this assault on our privacy as long as the roving supply of cat videos doesn't dry up.

Ok - gotta go.  Some adversarial consumer Windows security patches have just automatically downloaded themselves onto my computer and I have to reboot for them to take effect. hey wait a minute ...
.

Tuesday, June 11, 2013

PRISM : Everyone is a foreigner somewhere

                                              Image from Prism/US Overview PowerPoint slide

While DefMin Airshow MacKay prevaricates in the House about the extent to which Canada is complicit in the NSA 'foreigner' surveillance program PRISM outed by whistleblower Edward Snowden, former NSA and other foreign government officials are more forthcoming :

Guardian : NSA 'offers intelligence to British counterparts to skirt UK law'
The US National Security Agency circumvents UK law by offering, rather than being asked for, intelligence from global websites to their British counterparts, according to David Blunkett, who was home secretary at the time of the 9/11 attacks. British agents have to seek ministerial approval to request information from the US.
DutchNews : Dutch security service has received information via PRISM:  [h/t Min Reyes]
Dutch security service AIVD has also received information on email and social media traffic via US spy system PRISM, the Telegraaf reports on Tuesday. 
If the AIVD lists an American address as suspicious, it is supplied all the information within five minutes.
Der Spiegel : Prism Exposed: Data Surveillance with Global Implications
Former NSA employees Thomas Drake and Bill Binney told SPIEGEL in March that the facility would soon store personal data on people from all over the world and keep it for decades. This includes emails, Skype conversations, Google searches, YouTube videos, Facebook posts, bank transfers -- electronic data of every kind. 
The NSA's research projects aim to forecast, on the basis of telephone data and Twitter and Facebook posts, when uprisings, social protests and other events will occur. 
Gus Hunt, the CIA's chief technology officer, made a forthright admission in March: "We fundamentally try to collect everything and hang onto it forever." What he meant by "everything," Hunt also made clear: "It is really very nearly within our grasp to be able to compute on all human-generated information," he said.
Seen on twitter : Prism is currently reported to be searching for Sara Connor.
.

Blog Archive