Showing posts with label PRISM. Show all posts
Showing posts with label PRISM. Show all posts

Friday, July 12, 2013

NSA : At Microsoft, your privacy is our "team sport"



Feel free to drop by this Microsoft ad and give it a thumbs down.
"At Microsoft, your privacy is our priority." 

Indeed. About that ...

Guardian : How Microsoft handed the NSA access to encrypted messages

 Secret files show scale of Silicon Valley co-operation on Prism  
 Outlook.com encryption including Hotmail unlocked even before official launch 
 Skype worked to enable Prism collection of video calls 
Microsoft has collaborated closely with US intelligence services to allow users' communications to be intercepted, including helping the National Security Agency to circumvent the company's own encryption, according to top-secret documents obtained by the Guardian. 
 In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
 Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
US lawmakers, along with Microsoft, Skype, Apple, Google, Facebook, and Yahoo all initially attempted to deny knowledge of PRISM or that the intelligence agencies have back doors into their systems, explaining they are very occasionally under a legal compulsion to cough up customer data to comply with "existing and future lawful demands" in Microsoft's happy phrase, but this tiny ISP company bucked it and won.

Meanwhile ...

NSA Writes Code Used in Google Phone  [h/t West End Bob]
The tech giant Google has confirmed the National Security Agency furnished some of the code installed in its new Android phone. The NSA says the code is intended to enhance security against hackers and marketers, but will not confirm whether it also aids the agency’s PRISM program monitoring the global Internet.
Back to the Guardian :
"Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time."
That's us.

Michael Geist Feb 15 2012 on the situation in Canada
"[W]ith ISPs and telcos providing subscriber data without a warrant 95 percent of the time, there is a huge information disclosure issue with no reporting and no oversight. This is a major issue on its own, particularly since it is not clear whether these figures also include requests to Internet companies like Google and social media sites such as Facebook and Twitter.  
The RCMP alone made over 28,000 requests for customer name and address information in 2010. These requests go unreported - subscribers don't know their information has been disclosed and the ISPs and telecom companies aren't talking either."

If you'd like to opt out of the NSA and their "team sport", there are other options :

.
Related from Saskboy : PRISM : Oliver Stone vs NSA and Checkpoints
"The question is not Do you have something to hide? The question is whether we control government or the government controls us."
.

Thursday, June 13, 2013

From Creekside to Cyveillance to PRISM-ID

Creekside is a really tiny insignificant Canadian blog, as I'm sure both of you know. I rarely venture into covering anything about the US unless it has a direct and immediate bearing on Canadian interests and hasn't been mentioned anywhere else. Consequently I don't get much US traffic unless I happen to blog something like State Dept. hires TransCanada consultant to approve Keystone pipeline, and it goes up some magical link chain via Think Progress to the New York Times.  

Then I get a wee spike in US traffic, some of which consists of the downloading of hundreds of pages over the course of a few hours from US data-mining firms like PSInet and Cyveillance who specialize in protecting the online reputations of their corporate clients. I can imagine the reason behind some of their search terms on Creekside - Carlyle Group, Manning Centre, CETA; but others make no sense at all - Kady O'Malley, Matt Taibbi, Stephen Harper.

Usually there are several different IP addresses from the same company working Creekside at the same time - some doing word or date searches while others download several posts per second. Must be some kind of metadata collecting program, thinks technodolt me. 
I google up Cyveillance; other bloggers have complained about them, but not recently. 
A 2009 news release says they were bought out by QinetiQ :
QinetiQ North America, of McLean, Va., is a subsidiary of British defense company QinetiQ Group PLC and ranks No, 24 on Washington Technology’s 2008 Top 100 list of the largest federal government prime contractors.
A Bloomberg story, China's Cyberspies Outwit Model for Bond's Q, notes "former CIA Director George Tenet was a director of the company from 2006 to 2008 and former Pentagon spy chief Stephen Cambone headed a major division." 

Which got me thinking about that corporate/government data-mining revolving door, and I wondered if there was a connection between Cyveillance and PRISM. 
There is - if PRISM-ID is related to PRISM. 

US Department of Homeland Security
Privacy Impact Assessment for the U.S. Secret Service Cyber Awareness Program (Cyveillance) December 14, 2012
Cyveillance, a subsidiary of QinetiQ of North America, is under contract by the Secret Service to search available information related to the Secret Service and its missions.The information captured by Cyveillance is reviewed by Cyveillance personnel to identify the results that appear to fall within the parameters of the Secret Service’s stated requirements. Potentially relevant information related to the Agency’s missions is forwarded to Secret Service personnel who determine whether further investigation is required to assess the content (e.g., to determine if it is a viable or potentially viable threat). If further investigation is deemed necessary, the information obtained through Cyveillance is incorporated into the Protective Research Information Management System (PRISM-ID)1, an existing Secret Service system.

And what is PRISM-ID?
PRISM-ID system records data on threats, inappropriate or unusual behavior, and incidents that may impact the Secret Service’s mission to protect persons, events, and facilities. The system also may contain PII [personally identifiable information] on subjects of an investigation. PRISM-ID does not include information on individuals merely seeking access to protected facilities or sites unless they are the subject of an investigation or otherwise came to the attention of the Secret Service for threatening, inappropriate, or unusual behavior. Information may include criminal history, health history, employment history, military service history, education history, immigration status, and other personal information provided by the subject or others familiar with the subject.
So does blogging about it count as "inappropriate or unusual behavior"? Asking for a friend.

Back to the Homeland Security Privacy Impact Assessment, which follows a Q&A format regarding the access and retention of "personally identifiable information" and how it is purged within 10 working days if not deemed relevant to further inquiry. All very reassuring, however :
While the general purpose of Cyveillance is not to collect PII, the collected information may contain PII. As Cyveillance’s function is not to collect PII, it is not possible for the Secret Service to know what PII, if any, may be contained in the collected information.
And this just blew me away : 
4.3 Privacy Impact Analysis: Related to Notice
Privacy Risk: Individuals may not be aware of the existence of Cyveillance and the data its collects and reports to the Secret Service. 
Mitigation: This PIA serves as public notice of the existence of Cyveillance in support of the Secret Service missions.
Ah but you'll only see it if you happen to be browsing through the pages of Homeland Security.
Suddenly I feel like Arthur Dent : "Yes, it was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the leopard'."

6.1 Is information shared outside of DHS as part of the normal agency operations? 

Identified information that becomes part of an investigative or criminal case file may be shared on a need-to-know basis with federal, state, and local law enforcement agencies, other foreign and domestic government units, or private entities in accordance with the routine uses outlined in the applicable SORN.



And just to destroy whatever tiny shreds of respect you were holding out for me not being totally tinfoil ....
After four days of Cyveillance hanging out at Creekside in January, I shut down my computer for 24 hours, checked in on my stats from a blackberry, and they had gone. The next day I logged back onto my computer and within seconds they were back again. 

I know, I know, but there you go - coincidence or not, it's what happened.
Beware of the leopard.

Update : 
Firedoglake : NSA Swaps Information On You With Private Companies For More Information On You
.

Tuesday, June 11, 2013

PRISM : Everyone is a foreigner somewhere

                                              Image from Prism/US Overview PowerPoint slide

While DefMin Airshow MacKay prevaricates in the House about the extent to which Canada is complicit in the NSA 'foreigner' surveillance program PRISM outed by whistleblower Edward Snowden, former NSA and other foreign government officials are more forthcoming :

Guardian : NSA 'offers intelligence to British counterparts to skirt UK law'
The US National Security Agency circumvents UK law by offering, rather than being asked for, intelligence from global websites to their British counterparts, according to David Blunkett, who was home secretary at the time of the 9/11 attacks. British agents have to seek ministerial approval to request information from the US.
DutchNews : Dutch security service has received information via PRISM:  [h/t Min Reyes]
Dutch security service AIVD has also received information on email and social media traffic via US spy system PRISM, the Telegraaf reports on Tuesday. 
If the AIVD lists an American address as suspicious, it is supplied all the information within five minutes.
Der Spiegel : Prism Exposed: Data Surveillance with Global Implications
Former NSA employees Thomas Drake and Bill Binney told SPIEGEL in March that the facility would soon store personal data on people from all over the world and keep it for decades. This includes emails, Skype conversations, Google searches, YouTube videos, Facebook posts, bank transfers -- electronic data of every kind. 
The NSA's research projects aim to forecast, on the basis of telephone data and Twitter and Facebook posts, when uprisings, social protests and other events will occur. 
Gus Hunt, the CIA's chief technology officer, made a forthright admission in March: "We fundamentally try to collect everything and hang onto it forever." What he meant by "everything," Hunt also made clear: "It is really very nearly within our grasp to be able to compute on all human-generated information," he said.
Seen on twitter : Prism is currently reported to be searching for Sara Connor.
.

Blog Archive