Showing posts with label skynet. Show all posts
Showing posts with label skynet. Show all posts

Saturday, March 15, 2014

Dragnet Nation


A lengthy excerpt from Dragnet Nation: A Quest for Privacy, Security and Freedom in a World of Relentless Surveillance by Julia Angwin, Pulitzer Prize winner, WSJ biz and tech writer, and now an investigative reporter for Pro Publica :
 Here’s How You May Already Be Getting Hacked

It's one thing to take for granted that we are all now being tracked via our cel phones, online banking and forums, voter lists, health file records, Google searches, Whole Foods digital signs that are actually facial recognition scanners,  etc.
Verizon even sells a product that allows businesses to track cell phone users in malls.

But it's quite another to read the stories of innocent people including minors who have found themselves outed, in virtual police line-ups, photographed in their bathrooms and while they were sleeping, blackmailed - all without their knowledge or being sloppy about their online privacy. 
The teenagers who were spied on at home by their school via webcam spyware installed on the laptops given out by the school - neither they nor their parents signed up for or knew about it.

News to me was that if you go online price shopping, retailers vary their prices to you depending on their assessment of your financial worth based on your geographic location.




Angwin's book primarily addresses privacy considerations in the US but as Steve is fond of saying - the War on Drugs and the GWOT, those bullshit policies and programs which fueled these invasions of our privacy right alongside the tech that made that made them possible, know no national boundaries.

The Canadian Civil Liberties Association is hosting a symposium : "Helping Canadians Find Pathways to Privacy" at UofT on March 20 and 21. Free to public but you have to register. To be webcast later.
.

Friday, February 14, 2014

CSEC : Get Your Plouffe On!


CBC : CSEC exoneration a 'mockery of public accountability'
"The CSEC watchdog, headed on a part-time basis by a semi-retired judge, Jean-Pierre Plouffe, concluded:  “No CSEC activity was directed at Canadians or persons in Canada…that would be illegal.” 
Plouffe’s office says its investigation exonerating CSEC consisted almost entirely of talking to CSEC."
Lux ex Umbra : Q: Why did CSEC spy on Canadian wi-fi?  A: It's all good!
.

Monday, February 03, 2014

Edward Snowden interview


Wed. Feb 5 Update : Video removed at source from Vimeo last night, leaving the above note in its place on Creekside. Alternate copy of Snowden interview can be seen here.

Great interview recorded a week ago, including a few choice words applicable to recent revelations about CSEC scooping up Canadians' IP IDs and tracking them across airports, hotels, conference centres, coffee shops, and libraries, and DefMin Rob Nicholson's response.
"What we saw initially in response to the revelations was sort of a circling of the wagons of government ...  Instead of circling around the public and protecting their rights, the political class circled around the security state and protected their rights."
"The Five Eyes alliance is sort of an artefact of the post-WW2 era where the anglophone countries of the major powers banded together to co-operate and share the costs of intelligence gathering infrastructure. So we have the UK's GCHQ, we have the US NSA, we have Canada's CSEC, we have Australia's Signals Intelligence Directorate and we have New Zealand's DSD. What the result of this was over decades and decades was a supranational intelligence organization that doesn't answer to the laws of its own countries." 
"The key is to remember that the surveillance and the abuse doesn't occur when people look at the data, it occurs when people gather the data in the first place."
There have been complaints of this interview disappearing off Vimeo and being entirely erased from Youtube, the latter possibly for copyright reasons. Should this one go down however, here's an alternate copy.
.

Saturday, February 01, 2014

CSEC : Spy vs. WiFi


So what exactly have we learned here from this 2012 CSEC pilot project that tracked wireless devices across airports, hotels, conference centres, coffee shops, and libraries, starting from a "single Canadian airport WiFi IP address" and "two weeks worth of IP-ID data" from a "Special Canadian Source", using ">300,000 active IDs over two weeks" in a "modest size city" as a control group?

1.  As Defence Minister Rob Nicholson, CSEC, and CSEC watchdog commissioner Plouffe have all now explained to us, CSEC wasn't "tracking" these Canadians because that would be illegal and our privacy is important to them.

2. If you haven't been issued a special decoder ring providing a CSECret definition of the words "tracking" and "metadata", whose fault is that?

3. If you are a hypothetical kidnapper from a rural area coming to the big city to make your three ransom phone calls - carefully spaced exactly 40 hours apart as seen in the nice CSEC powerpoint spreadsheet - at least try to blend in with the rest of the internet by forwarding some cat pictures around as well so your lone ransom calls don't stick out like a sore thumb.
If you don't much care for forwarding cat pictures, use a friggin' payphone.
.
Sat AM update : For those of you wondering what the fuck Calandra meant in the House yesterday when he called Glenn Greenwald, co-journalist on the CBC exposé, "a porn spy" - it's the Canadian nonsense version of "espionage pornographer", used two weeks ago by American Enterprise Institute's Marc Thiessen to describe whistleblower Edward Snowden.  
I guess the PMO thought Thiessen's version sounded too elitist.    h/t Techdirt
.
Sun AM update : Ryan Gallagher, one of the three journos on the original CBC piece, parses the CSEC and gov reaction. 
.
The always incisive Lux Ex Umbra looks at how we should interpret CSEC's mandate now. 
If, as CSEC seems to maintain, its collection of metadata is both legally within its mandate and likely to be upheld by the courts, then it would appear :
  1. there is no upper limit to collection of that data
  2. the section of its mandate referring to not directing its operations "at Canadians or any person in Canada" does not apply, and  
  3. given that part 3 of CSEC's mandate is to assist CSIS, the RCMP, CBSA, and other intelligence agencies, do those agencies require a separate warrant to access CSEC's metadata collection?

And a question of my own - Does this metadata automatically get shared with FiveEyes?
Or to put it more dramatically - is Skynet operational now?

.

Wednesday, August 21, 2013

If everything is under surveillance ...



A powerful two minutes with Jacob Appelbaum of Tor Project and Der Spiegel. 
Mr. Appelbaum has been flagged and detained many times like Glenn Greenwald's partner David Miranda was at Heathrow three days ago. An American citizen, he no longer travels to the US.

Wall Street Journal, Aug 20 2013 :
"The NSA, in conjunction with telecommunications companies, has built a system that can reach deep into the U.S. Internet backbone and cover 75% of traffic in the country, including not only metadata but the content of online communications."
The Guardian, Aug 1 2013
"The US government has paid at least £100m to the UK spy agency GCHQ over the last three years to secure access to and influence over Britain's intelligence gathering programmes. The top secret payments are set out in documents which make clear that the Americans expect a return on the investment, and that GCHQ has to work hard to meet their demands. 
Ministers have denied that GCHQ does the NSA's "dirty work", but in the documents GCHQ describes Britain's surveillance laws and regulatory regime as a "selling point" for the Americans.

Appelbaum transcript:
"I think at its core what is at stake is the ability for a human being to have dignity and for journalists to have integrity with their sources, and from that I believe that it threatens the whole concept of a free democracy.
This is I think in a sense being shown in the last 48 hours to the extreme and I don't mean that as hyperbole but if everything is under surveillance, how is it that you can have a democracy? 
How is it that you can organize a political function or have confidentiality with a constituent or with a source or with a friend or with the lover?
That's fundamentally an erasure of fundamental things that we have had for quite some time.

And planetary surveillance has very serious concerns, not the least of which is economic espionage and not the least of which I think for me personally is about journalistic source protection.
I mean how is it that we will be able to protect our sources if there's no way to securely meet, no way to communicate about having a meeting, no way to actually communicate about basic facts? 
There's no such thing as on or off the record when in fact you don't control the record.

And it's not merely a matter of whether or not we have something to hide because it is not us that will decide whether we have something to hide - it is an analyst somewhere, it is a machine learning algorithm somewhere. And this is the thing that is perhaps the most terrifying : because people are flagged, then other people are dispatched. Each person plays their role and more and more a machine plays that role, a machine that does not understand constitutional protections, does not understand the Magna Carta or the Bill of Rights, does not understand humanity. It's a machine and the humans they behave like machines too - which is a great fear - that humans will start to behave like machines. 

And so what is at stake is in fact democracy where we still have it."


Pink Floyd, 1975
"Welcome, my son, welcome to the machine.
Where have you been? It's alright we know where you've been."

h/t West End Bob for Democracy Now link.
.

Sunday, August 18, 2013

These aren't the drones you're looking for

The RCAF has determined it doesn't require permission from civilian authorities to fly its drones through domestic airspace, according to a 2011 briefing note obtained by David Pugliese. The US, Europe, and Israel require civilian oversight but Canada does not.  

Having leased some Heron drones for use in Afghanistan from Israel, the world's largest drone manufacturer, the Cons want to purchase 18 UAVs for $1.5-billion plus.
Here's a short vid inside the Heron plant in Israel from two weeks ago .
  

So we already have the tech to build Skynet, we just haven't told it not to bother us with details yet.
An Israeli drone rep in the vid predicts that by the year 2035, drones will comprise 95% of the airborne fighting force, although the narrator explains :
"For all the claims of precision supporters of the use of drones make, a recent study found that strikes carried out by drones are 10 times more deadly to civilians than strikes by manned aircraft."
Well, what's a little collateral damage between military client states, eh?

And what about safety issues when you aren't trying to target anyone? Or as the US Congressional Research Bureau put it in 2010: "UAV accidents are “multiple times higher” than their piloted counterparts." 
The RCAF docs from 2011 do outline a concern with developing the tech not to bash unmanned into civilian things by accident :
"An autonomous ‘sense and avoid’ capability will be pursued to permit ever increasing access to Canadian Airspace"
but an RCAF spokesy advised Pugliese two days ago that :
while aerospace firms are working on a sense and avoid system for UAVs, that is not considered an essential requirement for the Canadian military’s planned purchase of such aircraft.
Three months ago, Israel ditched one of its Heron drones into the Mediterranian due to an engine problem and grounded all the rest pending investigation.

Notable that we don't have enough money to keep the Kitsilano marine rescue station open or fund the ELA or build a school in Attawapiskat or look into missing aboriginal women or house the homeless or make foreign aid independent of corporate interests or begin shifting our petrostate economy into something that permits the continuation of life on earth, but somehow there's always $1.5 billion lying around for the military to buy stuff like unmanned surveillance with the option to make things go boom.
Or, as I like to consider sometimes, if we were starting our society over from scratch, is this how we'd choose to organize it?
.

Friday, July 12, 2013

NSA : At Microsoft, your privacy is our "team sport"



Feel free to drop by this Microsoft ad and give it a thumbs down.
"At Microsoft, your privacy is our priority." 

Indeed. About that ...

Guardian : How Microsoft handed the NSA access to encrypted messages

 Secret files show scale of Silicon Valley co-operation on Prism  
 Outlook.com encryption including Hotmail unlocked even before official launch 
 Skype worked to enable Prism collection of video calls 
Microsoft has collaborated closely with US intelligence services to allow users' communications to be intercepted, including helping the National Security Agency to circumvent the company's own encryption, according to top-secret documents obtained by the Guardian. 
 In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
 Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
US lawmakers, along with Microsoft, Skype, Apple, Google, Facebook, and Yahoo all initially attempted to deny knowledge of PRISM or that the intelligence agencies have back doors into their systems, explaining they are very occasionally under a legal compulsion to cough up customer data to comply with "existing and future lawful demands" in Microsoft's happy phrase, but this tiny ISP company bucked it and won.

Meanwhile ...

NSA Writes Code Used in Google Phone  [h/t West End Bob]
The tech giant Google has confirmed the National Security Agency furnished some of the code installed in its new Android phone. The NSA says the code is intended to enhance security against hackers and marketers, but will not confirm whether it also aids the agency’s PRISM program monitoring the global Internet.
Back to the Guardian :
"Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time."
That's us.

Michael Geist Feb 15 2012 on the situation in Canada
"[W]ith ISPs and telcos providing subscriber data without a warrant 95 percent of the time, there is a huge information disclosure issue with no reporting and no oversight. This is a major issue on its own, particularly since it is not clear whether these figures also include requests to Internet companies like Google and social media sites such as Facebook and Twitter.  
The RCMP alone made over 28,000 requests for customer name and address information in 2010. These requests go unreported - subscribers don't know their information has been disclosed and the ISPs and telecom companies aren't talking either."

If you'd like to opt out of the NSA and their "team sport", there are other options :

.
Related from Saskboy : PRISM : Oliver Stone vs NSA and Checkpoints
"The question is not Do you have something to hide? The question is whether we control government or the government controls us."
.

Thursday, June 13, 2013

From Creekside to Cyveillance to PRISM-ID

Creekside is a really tiny insignificant Canadian blog, as I'm sure both of you know. I rarely venture into covering anything about the US unless it has a direct and immediate bearing on Canadian interests and hasn't been mentioned anywhere else. Consequently I don't get much US traffic unless I happen to blog something like State Dept. hires TransCanada consultant to approve Keystone pipeline, and it goes up some magical link chain via Think Progress to the New York Times.  

Then I get a wee spike in US traffic, some of which consists of the downloading of hundreds of pages over the course of a few hours from US data-mining firms like PSInet and Cyveillance who specialize in protecting the online reputations of their corporate clients. I can imagine the reason behind some of their search terms on Creekside - Carlyle Group, Manning Centre, CETA; but others make no sense at all - Kady O'Malley, Matt Taibbi, Stephen Harper.

Usually there are several different IP addresses from the same company working Creekside at the same time - some doing word or date searches while others download several posts per second. Must be some kind of metadata collecting program, thinks technodolt me. 
I google up Cyveillance; other bloggers have complained about them, but not recently. 
A 2009 news release says they were bought out by QinetiQ :
QinetiQ North America, of McLean, Va., is a subsidiary of British defense company QinetiQ Group PLC and ranks No, 24 on Washington Technology’s 2008 Top 100 list of the largest federal government prime contractors.
A Bloomberg story, China's Cyberspies Outwit Model for Bond's Q, notes "former CIA Director George Tenet was a director of the company from 2006 to 2008 and former Pentagon spy chief Stephen Cambone headed a major division." 

Which got me thinking about that corporate/government data-mining revolving door, and I wondered if there was a connection between Cyveillance and PRISM. 
There is - if PRISM-ID is related to PRISM. 

US Department of Homeland Security
Privacy Impact Assessment for the U.S. Secret Service Cyber Awareness Program (Cyveillance) December 14, 2012
Cyveillance, a subsidiary of QinetiQ of North America, is under contract by the Secret Service to search available information related to the Secret Service and its missions.The information captured by Cyveillance is reviewed by Cyveillance personnel to identify the results that appear to fall within the parameters of the Secret Service’s stated requirements. Potentially relevant information related to the Agency’s missions is forwarded to Secret Service personnel who determine whether further investigation is required to assess the content (e.g., to determine if it is a viable or potentially viable threat). If further investigation is deemed necessary, the information obtained through Cyveillance is incorporated into the Protective Research Information Management System (PRISM-ID)1, an existing Secret Service system.

And what is PRISM-ID?
PRISM-ID system records data on threats, inappropriate or unusual behavior, and incidents that may impact the Secret Service’s mission to protect persons, events, and facilities. The system also may contain PII [personally identifiable information] on subjects of an investigation. PRISM-ID does not include information on individuals merely seeking access to protected facilities or sites unless they are the subject of an investigation or otherwise came to the attention of the Secret Service for threatening, inappropriate, or unusual behavior. Information may include criminal history, health history, employment history, military service history, education history, immigration status, and other personal information provided by the subject or others familiar with the subject.
So does blogging about it count as "inappropriate or unusual behavior"? Asking for a friend.

Back to the Homeland Security Privacy Impact Assessment, which follows a Q&A format regarding the access and retention of "personally identifiable information" and how it is purged within 10 working days if not deemed relevant to further inquiry. All very reassuring, however :
While the general purpose of Cyveillance is not to collect PII, the collected information may contain PII. As Cyveillance’s function is not to collect PII, it is not possible for the Secret Service to know what PII, if any, may be contained in the collected information.
And this just blew me away : 
4.3 Privacy Impact Analysis: Related to Notice
Privacy Risk: Individuals may not be aware of the existence of Cyveillance and the data its collects and reports to the Secret Service. 
Mitigation: This PIA serves as public notice of the existence of Cyveillance in support of the Secret Service missions.
Ah but you'll only see it if you happen to be browsing through the pages of Homeland Security.
Suddenly I feel like Arthur Dent : "Yes, it was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the leopard'."

6.1 Is information shared outside of DHS as part of the normal agency operations? 

Identified information that becomes part of an investigative or criminal case file may be shared on a need-to-know basis with federal, state, and local law enforcement agencies, other foreign and domestic government units, or private entities in accordance with the routine uses outlined in the applicable SORN.



And just to destroy whatever tiny shreds of respect you were holding out for me not being totally tinfoil ....
After four days of Cyveillance hanging out at Creekside in January, I shut down my computer for 24 hours, checked in on my stats from a blackberry, and they had gone. The next day I logged back onto my computer and within seconds they were back again. 

I know, I know, but there you go - coincidence or not, it's what happened.
Beware of the leopard.

Update : 
Firedoglake : NSA Swaps Information On You With Private Companies For More Information On You
.

Tuesday, June 11, 2013

PRISM : Everyone is a foreigner somewhere

                                              Image from Prism/US Overview PowerPoint slide

While DefMin Airshow MacKay prevaricates in the House about the extent to which Canada is complicit in the NSA 'foreigner' surveillance program PRISM outed by whistleblower Edward Snowden, former NSA and other foreign government officials are more forthcoming :

Guardian : NSA 'offers intelligence to British counterparts to skirt UK law'
The US National Security Agency circumvents UK law by offering, rather than being asked for, intelligence from global websites to their British counterparts, according to David Blunkett, who was home secretary at the time of the 9/11 attacks. British agents have to seek ministerial approval to request information from the US.
DutchNews : Dutch security service has received information via PRISM:  [h/t Min Reyes]
Dutch security service AIVD has also received information on email and social media traffic via US spy system PRISM, the Telegraaf reports on Tuesday. 
If the AIVD lists an American address as suspicious, it is supplied all the information within five minutes.
Der Spiegel : Prism Exposed: Data Surveillance with Global Implications
Former NSA employees Thomas Drake and Bill Binney told SPIEGEL in March that the facility would soon store personal data on people from all over the world and keep it for decades. This includes emails, Skype conversations, Google searches, YouTube videos, Facebook posts, bank transfers -- electronic data of every kind. 
The NSA's research projects aim to forecast, on the basis of telephone data and Twitter and Facebook posts, when uprisings, social protests and other events will occur. 
Gus Hunt, the CIA's chief technology officer, made a forthright admission in March: "We fundamentally try to collect everything and hang onto it forever." What he meant by "everything," Hunt also made clear: "It is really very nearly within our grasp to be able to compute on all human-generated information," he said.
Seen on twitter : Prism is currently reported to be searching for Sara Connor.
.

Tuesday, February 21, 2012

Skynet : Connecting the dots

So remember how the Cons withdrew their just-tabled internet surveillance bill, the Lawful Access Act, on Feb 14 and replaced it an hour and 15 minutes later with the identical but renamed Protecting Children from Internet Predators Act , a bill which mentions neither children nor predators?

Coincidentally, the US Protecting Children from Internet Pornographers Act of 2011 - sponsored by Texas teabaggin' Rep Lamar Smith who also sponsored the Stop Online Piracy Act, another internet spying bill - has 39 co-sponsors and is heading off to the US House of Representatives for debate.

Good thing ours has that one-word difference in the title, the better to provide for Canadian independence and sovereignty.

Theirs :
House Panel Votes to Require ISPs to Keep Customer Records
"The Protecting Children From Internet Pornographers Act would require ISPs to retain all customer IP addresses [for 12 months, amended down from 18] so that law enforcement agents can use the information to investigate online child pornography. Law enforcement agents would gain access to the IP information with subpoenas they issue, not court-ordered warrants."
Hey, ours does that too!
Michael Geist yesterday :
Toews has not talked about a provision in Bill C-30 that creates a voluntary warrantless system that would allow police to ask for the content of emails or web surfing habits and allow ISPs to comply with the request without fear of liability.
Hey, Section 6 of the theirs does that too! As does SOPA.


So who else is looking to spy on us online?
From the Whitehouse National Northern Border Counternarcotics Strategy, January 2012 , pages 33-34:
"It is imperative that Canada and the United States work together to expedite the sharing of information from electronic communication service providers; and share information necessary to lay the foundation for intercepting internet and voice communications under their respective laws in a timely manner."
Meanwhile, across the pond, the UK isn't hiding their internet spying bill behind any malarkey about protecting children. Same basic mo though :
UK government to demand access to all phone and internet user data
"The British government is in the process of developing a scheme whereby all phone companies and broadband internet providers will be required to store customer transaction data for a year and hand it over to security services upon request."
Doesn't seem like it much matters who these various government online spying bills are purported to target - pornographers, copyright infringers, drug traffickers, drugbiz mirror sites, terrorists - or who they are supposed to protect - children, Hollywood, the recording industry, drug companies, the public at large. They'll just keep reframing and renaming those suckers until one of them sticks - a law we can't access the inner workings of that entrenches their access to our private info while simultaneously throttling the free flow of shared info out here.


In opposing the US pornography bill, Rep. John Conyers said
"This is not protecting children from internet pornography. It's creating a database for everybody in this country with a lot of other purposes."
Democrat Rep. Zoe Lofgren proposed an amendment to rename it the Keep Every Americans' Digital Data for Submission to the Federal Government Without a Warrant Act but sadly this did not accrue the required votes. Unlikely such a further name change would succeed here either, even with a one-word title change.
.

Blog Archive