Showing posts with label Server in the Sky. Show all posts
Showing posts with label Server in the Sky. Show all posts

Wednesday, June 26, 2013

Did Canada spy on journos at the Toronto G8/20 summit?



Image from leaked UK Government Communications Headquarters briefing slide featuring the logos of Canadian, US, and UK signals intelligence spying agencies.

Ten days ago The Guardian published GCHQ briefing slides, courtesy of former NSA contractor turned whistleblower Edward Snowden, revealing :
Foreign politicians and officials who took part in two G20 summit meetings in London in 2009 had their computers monitored and their phone calls intercepted on the instructions of their British government hosts, according to documents seen by the Guardian. This included:
• Setting up internet cafes where they used an email interception programme and key-logging software to spy on delegates' use of computers;
• Penetrating the security on delegates' BlackBerrys to monitor their email messages and phone calls
The inclusion in the docs of the Communications Security Establishment Canada logo along side those of NSA and GCHQ, and the mention of bugged internet cafes and BlackBerrys, put me in mind of Canada's $2-million indoor fake lake built for the G8/20 the following year so that 3,000+ Canadian and foreign journos could, in Greg Weston's words at the time :
"file their reports ... their feet dangling in the water ... from only cottage dock in existence with bar service and high-speed Internet connections."
And according to Weston, they were all provided with free "special summit edition BlackBerrys" too.


Thursday, June 13, 2013

From Creekside to Cyveillance to PRISM-ID

Creekside is a really tiny insignificant Canadian blog, as I'm sure both of you know. I rarely venture into covering anything about the US unless it has a direct and immediate bearing on Canadian interests and hasn't been mentioned anywhere else. Consequently I don't get much US traffic unless I happen to blog something like State Dept. hires TransCanada consultant to approve Keystone pipeline, and it goes up some magical link chain via Think Progress to the New York Times.  

Then I get a wee spike in US traffic, some of which consists of the downloading of hundreds of pages over the course of a few hours from US data-mining firms like PSInet and Cyveillance who specialize in protecting the online reputations of their corporate clients. I can imagine the reason behind some of their search terms on Creekside - Carlyle Group, Manning Centre, CETA; but others make no sense at all - Kady O'Malley, Matt Taibbi, Stephen Harper.

Usually there are several different IP addresses from the same company working Creekside at the same time - some doing word or date searches while others download several posts per second. Must be some kind of metadata collecting program, thinks technodolt me. 
I google up Cyveillance; other bloggers have complained about them, but not recently. 
A 2009 news release says they were bought out by QinetiQ :
QinetiQ North America, of McLean, Va., is a subsidiary of British defense company QinetiQ Group PLC and ranks No, 24 on Washington Technology’s 2008 Top 100 list of the largest federal government prime contractors.
A Bloomberg story, China's Cyberspies Outwit Model for Bond's Q, notes "former CIA Director George Tenet was a director of the company from 2006 to 2008 and former Pentagon spy chief Stephen Cambone headed a major division." 

Which got me thinking about that corporate/government data-mining revolving door, and I wondered if there was a connection between Cyveillance and PRISM. 
There is - if PRISM-ID is related to PRISM. 

US Department of Homeland Security
Privacy Impact Assessment for the U.S. Secret Service Cyber Awareness Program (Cyveillance) December 14, 2012
Cyveillance, a subsidiary of QinetiQ of North America, is under contract by the Secret Service to search available information related to the Secret Service and its missions.The information captured by Cyveillance is reviewed by Cyveillance personnel to identify the results that appear to fall within the parameters of the Secret Service’s stated requirements. Potentially relevant information related to the Agency’s missions is forwarded to Secret Service personnel who determine whether further investigation is required to assess the content (e.g., to determine if it is a viable or potentially viable threat). If further investigation is deemed necessary, the information obtained through Cyveillance is incorporated into the Protective Research Information Management System (PRISM-ID)1, an existing Secret Service system.

And what is PRISM-ID?
PRISM-ID system records data on threats, inappropriate or unusual behavior, and incidents that may impact the Secret Service’s mission to protect persons, events, and facilities. The system also may contain PII [personally identifiable information] on subjects of an investigation. PRISM-ID does not include information on individuals merely seeking access to protected facilities or sites unless they are the subject of an investigation or otherwise came to the attention of the Secret Service for threatening, inappropriate, or unusual behavior. Information may include criminal history, health history, employment history, military service history, education history, immigration status, and other personal information provided by the subject or others familiar with the subject.
So does blogging about it count as "inappropriate or unusual behavior"? Asking for a friend.

Back to the Homeland Security Privacy Impact Assessment, which follows a Q&A format regarding the access and retention of "personally identifiable information" and how it is purged within 10 working days if not deemed relevant to further inquiry. All very reassuring, however :
While the general purpose of Cyveillance is not to collect PII, the collected information may contain PII. As Cyveillance’s function is not to collect PII, it is not possible for the Secret Service to know what PII, if any, may be contained in the collected information.
And this just blew me away : 
4.3 Privacy Impact Analysis: Related to Notice
Privacy Risk: Individuals may not be aware of the existence of Cyveillance and the data its collects and reports to the Secret Service. 
Mitigation: This PIA serves as public notice of the existence of Cyveillance in support of the Secret Service missions.
Ah but you'll only see it if you happen to be browsing through the pages of Homeland Security.
Suddenly I feel like Arthur Dent : "Yes, it was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the leopard'."

6.1 Is information shared outside of DHS as part of the normal agency operations? 

Identified information that becomes part of an investigative or criminal case file may be shared on a need-to-know basis with federal, state, and local law enforcement agencies, other foreign and domestic government units, or private entities in accordance with the routine uses outlined in the applicable SORN.



And just to destroy whatever tiny shreds of respect you were holding out for me not being totally tinfoil ....
After four days of Cyveillance hanging out at Creekside in January, I shut down my computer for 24 hours, checked in on my stats from a blackberry, and they had gone. The next day I logged back onto my computer and within seconds they were back again. 

I know, I know, but there you go - coincidence or not, it's what happened.
Beware of the leopard.

Update : 
Firedoglake : NSA Swaps Information On You With Private Companies For More Information On You
.

Tuesday, June 11, 2013

PRISM : Everyone is a foreigner somewhere

                                              Image from Prism/US Overview PowerPoint slide

While DefMin Airshow MacKay prevaricates in the House about the extent to which Canada is complicit in the NSA 'foreigner' surveillance program PRISM outed by whistleblower Edward Snowden, former NSA and other foreign government officials are more forthcoming :

Guardian : NSA 'offers intelligence to British counterparts to skirt UK law'
The US National Security Agency circumvents UK law by offering, rather than being asked for, intelligence from global websites to their British counterparts, according to David Blunkett, who was home secretary at the time of the 9/11 attacks. British agents have to seek ministerial approval to request information from the US.
DutchNews : Dutch security service has received information via PRISM:  [h/t Min Reyes]
Dutch security service AIVD has also received information on email and social media traffic via US spy system PRISM, the Telegraaf reports on Tuesday. 
If the AIVD lists an American address as suspicious, it is supplied all the information within five minutes.
Der Spiegel : Prism Exposed: Data Surveillance with Global Implications
Former NSA employees Thomas Drake and Bill Binney told SPIEGEL in March that the facility would soon store personal data on people from all over the world and keep it for decades. This includes emails, Skype conversations, Google searches, YouTube videos, Facebook posts, bank transfers -- electronic data of every kind. 
The NSA's research projects aim to forecast, on the basis of telephone data and Twitter and Facebook posts, when uprisings, social protests and other events will occur. 
Gus Hunt, the CIA's chief technology officer, made a forthright admission in March: "We fundamentally try to collect everything and hang onto it forever." What he meant by "everything," Hunt also made clear: "It is really very nearly within our grasp to be able to compute on all human-generated information," he said.
Seen on twitter : Prism is currently reported to be searching for Sara Connor.
.

Tuesday, February 21, 2012

Skynet : Connecting the dots

So remember how the Cons withdrew their just-tabled internet surveillance bill, the Lawful Access Act, on Feb 14 and replaced it an hour and 15 minutes later with the identical but renamed Protecting Children from Internet Predators Act , a bill which mentions neither children nor predators?

Coincidentally, the US Protecting Children from Internet Pornographers Act of 2011 - sponsored by Texas teabaggin' Rep Lamar Smith who also sponsored the Stop Online Piracy Act, another internet spying bill - has 39 co-sponsors and is heading off to the US House of Representatives for debate.

Good thing ours has that one-word difference in the title, the better to provide for Canadian independence and sovereignty.

Theirs :
House Panel Votes to Require ISPs to Keep Customer Records
"The Protecting Children From Internet Pornographers Act would require ISPs to retain all customer IP addresses [for 12 months, amended down from 18] so that law enforcement agents can use the information to investigate online child pornography. Law enforcement agents would gain access to the IP information with subpoenas they issue, not court-ordered warrants."
Hey, ours does that too!
Michael Geist yesterday :
Toews has not talked about a provision in Bill C-30 that creates a voluntary warrantless system that would allow police to ask for the content of emails or web surfing habits and allow ISPs to comply with the request without fear of liability.
Hey, Section 6 of the theirs does that too! As does SOPA.


So who else is looking to spy on us online?
From the Whitehouse National Northern Border Counternarcotics Strategy, January 2012 , pages 33-34:
"It is imperative that Canada and the United States work together to expedite the sharing of information from electronic communication service providers; and share information necessary to lay the foundation for intercepting internet and voice communications under their respective laws in a timely manner."
Meanwhile, across the pond, the UK isn't hiding their internet spying bill behind any malarkey about protecting children. Same basic mo though :
UK government to demand access to all phone and internet user data
"The British government is in the process of developing a scheme whereby all phone companies and broadband internet providers will be required to store customer transaction data for a year and hand it over to security services upon request."
Doesn't seem like it much matters who these various government online spying bills are purported to target - pornographers, copyright infringers, drug traffickers, drugbiz mirror sites, terrorists - or who they are supposed to protect - children, Hollywood, the recording industry, drug companies, the public at large. They'll just keep reframing and renaming those suckers until one of them sticks - a law we can't access the inner workings of that entrenches their access to our private info while simultaneously throttling the free flow of shared info out here.


In opposing the US pornography bill, Rep. John Conyers said
"This is not protecting children from internet pornography. It's creating a database for everybody in this country with a lot of other purposes."
Democrat Rep. Zoe Lofgren proposed an amendment to rename it the Keep Every Americans' Digital Data for Submission to the Federal Government Without a Warrant Act but sadly this did not accrue the required votes. Unlikely such a further name change would succeed here either, even with a one-word title change.
.

Monday, February 13, 2012

Skynet - It's all about the children apparently



Net, cellphones; Police could probe without warrant
"Public Safety Minister Vic ["Torture Lite"] Toews said the law will give the tools to police to adequately deal with 21st-century technology, and said anyone opposing the laws favours "the rights of child pornographers and organized crime ahead of the rights of law abiding citizens."
Actually, Vic, we do favour the rights of child pornographers.  And organized crime. We have to if we favour the rights of everyone equally - which, if I recall correctly, is a bedrock conservative value.


Petition : STOP GOVERNMENT ONLINE SPYING
.



Update : Write your MP
Dear [your MP here] : 
Vic Toews says our choice is between child pornographers and online surveillance. 
Fine. 
Your choice is between voting against the awful access bill and losing your seat in the next election. 
Sincerely, [You]
.
Update 2 : U.S. seeks to mine social media
The U.S. government is seeking software that can mine social media to predict everything from future terrorist attacks to foreign uprisings, according to requests posted online by federal law enforcement and intelligence agencies. 
In a formal "request for information" from potential contractors, the FBI recently outlined its desire for a digital tool to scan the entire universe of social media - more data than humans could ever crunch.
The system sought by the research arm of the national intelligence director's office would fuse together everything from Web searches to Wikipedia edits to traffic webcams. 
.

Thursday, October 09, 2008

SPP : "We're getting better all the time."

Stockwell Day, the RCMP, Bell Canada and Microsoft will be partnering on "a national cyber-security strategy that will seek to protect key infrastructure as well as Canadians' identities".
"A high-level security conference being hosted by the Conference Board of Canada" will take place on Nov 5 and 6th.
The Conference Board of Canada, you may recall, partnered with the U.S. Center for Strategic and International Studies (CSIS) to launch the North American Future 2025 Project , "to help guide the ongoing Security and Prosperity Partnership". At their conference in Calgary last April their agenda noted : "the overriding future goal of North America is to achieve joint optimum utilization of the available water."

So you'll excuse me if I cast a jaundiced eye on whatever new plan to protect my "Canadian identity" they might be hosting this time round. One of the original objectives of the SPP was "improving the coordination of intelligence-sharing, cross-border law enforcement".

At least Canada's Privacy Commissioner, Jennifer Stoddart, has been invited this time and will be addressing the conference on "Balancing Privacy with Cyber Security".
In May there was a "Server in the Sky" meet-up in San Francisco to discuss the FBI's proposed shared database of biometric information - our fingerprints, palm prints, and iris scan data to be exchanged among the International Information Consortium of US, Canada, UK, Australia, New Zealand, and eventually the EU. Ms Stoddart first heard about the conference by reading about it in the British press.

As Ms Stoddart said on CBC in response to that meeting in May : "Canada has a very weak 25 year old Privacy Act with no human rights standards built in to our agreements with other countries." Additionally she was alarmed by "the conflating of criminals and suspected terrorists", the lack of oversight of the biometric info once it passes to other countries, and the rise of "a surveillance society".

One of our partners in the International Information Consortium is already well on the way to becoming a surveillance society:
The Daily Mail via Statism Watch :
"Every person in Britain could have their internet history, email records and telephone calls tracked under a proposed £12 billion plan by ministers.
The system would see hundreds of hidden devices planted to tap into communications on the internet and via mobile phone providers.
And a national database would be created to store the information which officials say would help in the fight against terrorism and organised crime."
I thought we already had Facebook for that.

"In terms of Canadian participation [in Server in the Sky], our citizens rightfully expect that their personal information remains safeguarded and understandably, could be reluctant to see that information freely shared with two countries that were ranked near the bottom of Privacy International’s ratings of privacy protection around the world."

David Black, manager of the RCMP's cyber infrastructure protection section, says of the Bell/Microsoft/RCMP plan for "the protection of critical cyber infrastructure and the convergence of technological and physical security", presumably to be shared in due course with the other members of the FBI's International Information Consortium :
"We're getting better all the time."

Friday, April 11, 2008

SPP and Server in the Sky

CP : U.S. security chief says fingerprints not private
"The U.S. homeland security czar says Canadians shouldn't fear plans to expand international sharing of biometric information such as fingerprints.
Michael Chertoff says a person's fingerprints are like footprints.
"They're not particularly private," Chertoff said in an interview Wednesday during a brief visit to Ottawa.
"Your fingerprint's hardly personal data, because you leave it on glasses and silverware and articles all over the world."

Well that's just crap. Having a glass of wine in a public restaurant is not at all like having your fingerprints fed into a database like Server in the Sky.
You remember Server in the Sky, don't you? It's the FBI's proposed shared database of biometric information - our fingerprints, palm prints, and iris scan data - to be exchanged among the US, Canada, UK, Australia, and New Zealand.
The International Information Consortium, as the five founding nations including Canada call themselves, will meet behind closed doors in May in San Francisco to plan their strategy.

CP : "An internal RCMP briefing note on the Server in the Sky project recommends the national police force continue to support the initiative."

As noted back here, one of Server in the Sky's most alarming aspects is that Canada's Privacy Commissioner, Jennifer Stoddart, heard of it for the first time in January by reading about it in a UK newspaper.
No Canadian officials had informed her of the project.

Stockwell Day met with Chertoff on Wednesday to discuss SPP initiatives in advance of the Leaders' Summit in New Orleans on April 21.


Integrate This! on the new biometric BC Enhanced Driver's License developed in conjunction with Washington state. Jennifer Stoddart describes it as creating a de facto national ID card in both countries.
IT : "The EDLs require biometric and other personal information on Canadians and Americans to be stored in a common database that is accessible by security agencies in both countries. Because Canada’s Public Safety department is insisting on all provinces developing a similar EDL to B.C.’s, and all of them will be compatible with the REAL ID program in the U.S., the Harper government is essentially working on a de facto North American ID card behind closed doors through the SPP."

Tuesday, January 22, 2008

Server in the Sky

"Server in the Sky" is the FBI's proposed shared database of biometric information - our fingerprints, palm prints, and iris scan data - to be exchanged among the US, Canada, UK, Australia, New Zealand, and eventually the EU, to catch criminals and terrorists. The International Information Consortium, as the five founding nations including Canada call themselves, will meet behind closed doors in May in San Francisco to plan their strategy.

Tom Bush, the FBI Assistant Director of the Criminal Justice Information Services Division was on CBC's The Current last week. "It's to catch the worst of the worst", he said, "murderers and rapists".
However an RCMP statement carried in the Globe and Mail instead placed greater importance on the sharing of "information on terrorist files".

Perhaps one of Server in the Sky's most alarming aspects is that Canada's Privacy Commissioner, Jennifer Stoddart, heard of it for the first time last week by reading about it in a UK newspaper. No Canadian officials had informed her of the project.

From The Guardian : "The FBI is proposing to establish three categories of suspects in the shared system :
  • "internationally recognised terrorists and felons",
  • those who are "major felons and suspected terrorists", and finally
  • those who the subjects of terrorist investigations or criminals with international links."
Suspected terrorists? Subjects of terrorist investigations?
A few paragraphs into the FBI's explanation and we're already into Maher Arar territory.
Stoddart agrees and says so on CBC's The Current.: Canada has a very weak 25 year old Privacy Act, she says, with no human rights standards built in to our agreements with other countries. Additionally she is alarmed by "the conflating of criminals and suspected terrorists", the lack of oversight of the biometric info once it passes to other countries, and the rise of "a survellance society".

Also, as Council of Canadians points out, despite Canadian horror at the grotesque misuse of intelligence data in the Arar case and the subsequent support for recommendations for greater paper-trail accountability, getting rid of any legal impediments to cross-border intelligence information-sharing was one of the primary security aims of, yes you guessed correctly, the SPP.

UPDATE : The Office of the Privacy Commissioner of Canada has a blog! :
"In terms of Canadian participation, our citizens rightfully expect that their personal information remains safeguarded and understandably, could be reluctant to see that information freely shared with two countries that were ranked near the bottom of Privacy International’s ratings of privacy protection around the world."
Go, Ms Stoddart!

Blog Archive