Showing posts with label cyberspace. Show all posts
Showing posts with label cyberspace. Show all posts

10/28/2015

US Senate Passes Controversial Security 'Spy' Bill CISA



Πηγή: telesutv
28 Oct 2015


Civil liberties groups have long been trying to convince congress to sack the bill, calling it an invasion of privacy.

The United States Senate passed Tuesday a controversial bill that freedom of speech advocates say grants governments new means to monitor its citizens, under the guise of security protection.

Under the new Cybersecurity Information Sharing Act, companies will be allowed and encouraged to share customer data with the Department of Homeland Security that it deems could be a cybersecurity threat.

The DHS could then pass on the data to other agencies, like the FBI and National Security Agency, which would theoretically use it to defend the corporation and the customer under threat of cyber attacks.

Privacy advocates and civil liberties groups have long been urging Congress to sack the bill, or at least include certain reforms, calling it an invasion of privacy that allows companies to share users' information with government without a warrant.

The bill also strikes down other already existing privacy laws, under the guise of added security.

The DHS itself had even spoken against the bill, saying it could derail “important privacy protections,” while tech companies argued that it should be rewritten.

“The incentive and the framework it creates is for companies to quickly and massively collect user information and ship it to the government,” Mark Jaycox, a legislative analyst for the civil liberties group the Electronic Frontier Foundation told Wired. “As soon as you do, you obtain broad immunity, even if you’ve violated privacy law.”

Exiled privacy activist Edward Snowden has echoed these sentiments and urged Congress to stop CISA.

“CISA gives companies legal immunity for violating privacy laws if they also give your data to the government,” tweeted Snowden earlier this week, following with a wave of further criticism of the bill.


Supporters of the bill argue that CISA will protect user data from getting into the wrong hands. The bill was introduced by Democrat Senator Dianne Feinstein in June 2014 after several high profile cyber attacks targeted U.S. corporations, including Anthem, Sony, and the Office of Personnel Management.

The advocacy of civil liberties groups slowed down the bill's passing as the Senate debated privacy protection reforms.

However, in the end all privacy reforms were struck down and CISA was passed by a 74 to 21 vote.

The legislation will now go to a conference committee between the Senate and the House of Representatives, which already passed its own version of CISA. If that is approved, the bill would head to President Barack Obama.




Civil liberties groups have long been trying to convince congress to sack the bill, calling it an invasion of privacy.
The United States Senate passed Tuesday a controversial bill that freedom of speech advocates say grants governments new means to monitor its citizens, under the guise of security protection.

Under the new Cybersecurity Information Sharing Act, companies will be allowed and encouraged to share customer data with the Department of Homeland Security that it deems could be a cybersecurity threat.

The DHS could then pass on the data to other agencies, like the FBI and National Security Agency, which would theoretically use it to defend the corporation and the customer under threat of cyber attacks.

Privacy advocates and civil liberties groups have long been urging Congress to sack the bill, or at least include certain reforms, calling it an invasion of privacy that allows companies to share users' information with government without a warrant.

The bill also strikes down other already existing privacy laws, under the guise of added security.

The DHS itself had even spoken against the bill, saying it could derail “important privacy protections,” while tech companies argued that it should be rewritten.

“The incentive and the framework it creates is for companies to quickly and massively collect user information and ship it to the government,” Mark Jaycox, a legislative analyst for the civil liberties group the Electronic Frontier Foundation told Wired. “As soon as you do, you obtain broad immunity, even if you’ve violated privacy law.”

Exiled privacy activist Edward Snowden has echoed these sentiments and urged Congress to stop CISA.

“CISA gives companies legal immunity for violating privacy laws if they also give your data to the government,” tweeted Snowden earlier this week, following with a wave of further criticism of the bill.

This content was originally published by teleSUR at the following address: 
 "http://www.telesurtv.net/english/news/US-Senate-Passes-Controversial-Security-Spy-Bill-CISA-20151028-0005.html?". If you intend to use it, please cite the source and provide a link to the original article. www.teleSURtv.net/english
Civil liberties groups have long been trying to convince congress to sack the bill, calling it an invasion of privacy.
The United States Senate passed Tuesday a controversial bill that freedom of speech advocates say grants governments new means to monitor its citizens, under the guise of security protection.

Under the new Cybersecurity Information Sharing Act, companies will be allowed and encouraged to share customer data with the Department of Homeland Security that it deems could be a cybersecurity threat.

The DHS could then pass on the data to other agencies, like the FBI and National Security Agency, which would theoretically use it to defend the corporation and the customer under threat of cyber attacks.

Privacy advocates and civil liberties groups have long been urging Congress to sack the bill, or at least include certain reforms, calling it an invasion of privacy that allows companies to share users' information with government without a warrant.

The bill also strikes down other already existing privacy laws, under the guise of added security.

The DHS itself had even spoken against the bill, saying it could derail “important privacy protections,” while tech companies argued that it should be rewritten.

“The incentive and the framework it creates is for companies to quickly and massively collect user information and ship it to the government,” Mark Jaycox, a legislative analyst for the civil liberties group the Electronic Frontier Foundation told Wired. “As soon as you do, you obtain broad immunity, even if you’ve violated privacy law.”

Exiled privacy activist Edward Snowden has echoed these sentiments and urged Congress to stop CISA.

“CISA gives companies legal immunity for violating privacy laws if they also give your data to the government,” tweeted Snowden earlier this week, following with a wave of further criticism of the bill.

This content was originally published by teleSUR at the following address: 
 "http://www.telesurtv.net/english/news/US-Senate-Passes-Controversial-Security-Spy-Bill-CISA-20151028-0005.html?". If you intend to use it, please cite the source and provide a link to the original article. www.teleSURtv.net/english
Civil liberties groups have long been trying to convince congress to sack the bill, calling it an invasion of privacy.
The United States Senate passed Tuesday a controversial bill that freedom of speech advocates say grants governments new means to monitor its citizens, under the guise of security protection.

Under the new Cybersecurity Information Sharing Act, companies will be allowed and encouraged to share customer data with the Department of Homeland Security that it deems could be a cybersecurity threat.

The DHS could then pass on the data to other agencies, like the FBI and National Security Agency, which would theoretically use it to defend the corporation and the customer under threat of cyber attacks.

Privacy advocates and civil liberties groups have long been urging Congress to sack the bill, or at least include certain reforms, calling it an invasion of privacy that allows companies to share users' information with government without a warrant.

The bill also strikes down other already existing privacy laws, under the guise of added security.

The DHS itself had even spoken against the bill, saying it could derail “important privacy protections,” while tech companies argued that it should be rewritten.

“The incentive and the framework it creates is for companies to quickly and massively collect user information and ship it to the government,” Mark Jaycox, a legislative analyst for the civil liberties group the Electronic Frontier Foundation told Wired. “As soon as you do, you obtain broad immunity, even if you’ve violated privacy law.”

Exiled privacy activist Edward Snowden has echoed these sentiments and urged Congress to stop CISA.

“CISA gives companies legal immunity for violating privacy laws if they also give your data to the government,” tweeted Snowden earlier this week, following with a wave of further criticism of the bill.

This content was originally published by teleSUR at the following address: 
 "http://www.telesurtv.net/english/news/US-Senate-Passes-Controversial-Security-Spy-Bill-CISA-20151028-0005.html?". If you intend to use it, please cite the source and provide a link to the original article. www.teleSURtv.net/english

9/18/2011

Top Spy Website Hacked



Πηγή: The Daily Beast
By Eli Lake
Sep. 17 2011


INSA, the leading trade association for intelligence contractors, just had its website hacked. What’s worse, such cyberpiracy is not that uncommon, Eli Lake explains.


On Wednesday, 48 hours after releasing a policy paper on cybersecurity, the top trade association for intelligence contractors got a first-hand lesson on the subject: they discovered that their website was hacked.

Cryptome, a site affiliated with the hacker collective Anonymous, published the membership emails and phone numbers and in some cases home addresses for the members of the Intelligence and National Security Alliance (INSA). By clicking on a link titled, “INSA Nest of Official and Corporate Spies,” anyone can find contact information for senior officials at the NSA, FBI, and CIA, as well as top national security contracting firms like Booz Allen Hamilton.

"When this happens to an organization which is an association made up of your brightest and most competent intelligence and national security professionals and no one is surprised, it tells you we have a cybercrime epidemic," INSA President Ellen McCarthy told The Daily Beast Friday. "It’s not just a few isolated incidents, it’s happening all the time."

INSA boasts members from the top of both the contracting world and the U.S. intelligence community. President Obama’s top adviser on counterterrorism,John Brennan, is a former chairman of INSA’s board of directors, as is Mike McConnell, a former director of national intelligence.

The irony in this case is that the files were published a day after INSA released a paper urging government contractors and the intelligence community to establish common protocols to ward off cyberintruders. The second sentence of the paper notes, “Cyberspace is a haven for a broad range of disruptive operations, including reconnaissance, theft, sabotage, and espionage.”

INSA is only the latest example of how the intelligence community and its affiliated contractors have been hacked by increasingly brazen hackers. On July 11, Anonymous published some 90,000 emails and login credentials for U.S. military officers after breaking into the servers of Booz Allen Hamilton. The group published the data on a website called Pirate Bay and announced on Twitter that July 11 was “Military Meltdown Monday.” The month before, another group of hackers called “LulzSec” (who claim to have since disbanded) published internal files from the FBI and claimed to briefly disable the CIA’s public website.

To get a sense of how bad the problem is, earlier this year, the company that provides the secure login protection or digital keys, RSA, suffered a breach that effectively gave the hacker a skeleton key for thousands of corporate networks all over the world.

“The people who are supposed to be most sophisticated about network security are constantly getting owned,” said Noah Shachtman, a cybersecurity expert at the Brookings Institution and the editor of Wired’s Danger Room blog. “It used to be that if you wanted to steal secrets from the U.S. government, you would have to go to the Pentagon or Langley, Va. But now, because so much of what our military and intelligence agencies do is actually in private contractor hands, one of the easiest ways to get sensitive information is to break into these corporate and association networks.”

McCarthy said the hackers got the master member list the group uses mainly as an invite list for their events. She said more sensitive information like the credit card numbers of its members were on websites on remote locations.

"The people who are supposed to be most sophisticated about network security are constantly getting owned," said Noah Shachtman, a cybersecurity expert.

INSA announced the breach in part, McCarthy said, because the trade organization has encouraged other businesses to be up front with the public after suffering hacks to their servers. She also said she was most upset that some of the home addresses of the group’s membership were shared.

Shachtman said that the emails could also be valuable to hackers. “INSA is just another Washington trade association, one of a thousand. But the personal information on the membership list could be extraordinarily useful for hackers who want to get access to more sensitive networks,” he said. “With the personal emails of these government and industry officials, a hacker could use this information to deliver very personalized and very convincing scams on some of the intelligence world’s leading lights.”


8/16/2011

Wiretapped Democracy




During the recent turmoil of the Arab Spring West countries heavily criticized the authoritarian regimes of the African continent for the repression of human rights underlying their support to the freedom of assembly and expression, which apply also on the Internet. Meanwhile in USA prepared a bill titled "Protecting Cyberspace as a National Asset Act of 2010" with witch Internet becomes a National Asset, a government agency management is created while  the US President is granted with powers to seize control of and even shut down the Internet with devastating results on the rest of the world. On top of this the UK Prime Minister Cameron coping with the recent London riots suggested that maybe the rioters should be banned from using social media. But how looks in fact the situation on freedom and privacy in the so called developed countries? Lets have a look.


Strange deaths

It seems that the economic crises in Europe is not the only reason for people to commit suicide. People that involve into wiretapping cases have a similar trend. Adamo Bove - head of security at Telecom Italia, the country's largest telecommunications firm - back in 2006 who at the direction of Milan prosecutors, he'd used mobile phone records to trace how a "Special Removal Unit" composed of CIA and SISMI (the Italian CIA) agents abducted Abu Omar, an Egyptian cleric, and flew him to Cairo where he was tortured and the year before of his counterpart Costas Tsalikidis, a software engineer for Vodaphone in Greece that had just discovered a highly sophisticated bug embedded in the company's mobile network, both found dead allegedly committing suicide. The bug was used to transmit the eavesdropping on the prime minister's (backing the Plan Pythia I) and other top officials' cell phone calls, including civil rights activists, the head of Greece's "Stop the War" coalition, journalists and Arab businessmen based in Athens, all in real time via four antennae located near the U.S. embassy in Athens, according to an 11-month Greek government investigation.

One similar case comes from the Wall Street. Mr. Karpel a trader that had agreed in 2008 to cooperate with federal authorities, and for about a year he taped conversations with fellow traders. Two days after federal prosecutors played for a jury a secretly recorded telephone conversation in a Manhattan courtroom, Karpel, one of those traders, hanged himself in his Fifth Avenue office although was never charged with any wrongdoing.
Recently, Mr. Sean Hoare so allegedly did commit suicide, being the first named journalist to allege Andy Coulson was aware of phone hacking by his staff concerning the News International phone hacking scandal. Well, before someone complains that these specific cases are rather outsiders as not connected to the public privacy - which is not correct - some recent facts point to the opposite direction.

Surveillance and Interceptions for everyone

For three years in thirty countries, Google's Street View cars collected data, including the content of personal emails, from wireless routers located in private homes and businesses. Several countries, including the U.K., Germany, Spain, and Canada, have conducted similar investigations and determined that Google violated their privacy laws.
While on July the Facebook's executive Randi Zuckerberg declared that "anonymity on the Internet has to go away" echoing the voice of a former Google CEO Eric Schmidt, who previously called for "true transparency and no anonymity" on the Web, the death certificate of the whistleblowers is signed as they lose one of their most essential tools. Anonymity's real value is rooted in helping the powerless to challenge the powerful as the case of WikiLeaks exemplifies. In Congress last month, when a House committee moved forward a proposal forcing Internet service providers to keep logs of all online activity by their users. Clearly, if it ultimately becomes law, this legislation would undermine not just anonymity in public spaces, but privacy in general. Should it succeed, we may achieve transparency, but at far too high a cost.

Talking about privacy and Internet security here is a fictional scene "directed" by an expert of the field:

"An American executive is in France for a series of trade negotiations. After a day of meetings, she logs in to her corporate webmail account using her company - provided laptop and the hotel wireless network. Relying on the training she received from her company's IT department, she makes certain to look for the SSL encryption lock icon in her web browser, and only after determining that the connection is secure does she enter her login credentials and then begin to upload materials to be shared with her colleagues. However, unknown to the executive, the French government has engaged in a sophisticated man-in-the-middle attack, and is able to covertly intercept the executive's SSL encrypted connections. Agents from the state security apparatus leak details of her communications to the French company with whom she is negotiating, who use the information to gain an upper hand in the negotiations. While this scenario is fictitious, the vulnerability is not".

Beyond these in US there is an elation of Industrial Espionage and Electronic Surveillance as the State Department estimates that there are over 700,000 eavesdropping devices sold each year reporting that over 6,500 incidents of industrial espionage occur in the United States each year with an average economic impact of $1.25 million.

The present step against privacy in the web has the name of mandatory Internet surveillance - or mandatory data retention - a bill that will force ISPs to surrender personal details about customers to law enforcement without a warrant. This bill is at the center of controversy already in Canada backed by the conservatives as the government has been trying to modernize its surveillance and wiretapping laws for years now, to take into account the growth of cellphone and Internet communications. These requirements compel ISPs and telcos to create large databases of information about who communicates with whom via Internet or phone, the duration of the exchange, and the users’ location. These regime require that your IP address be collected and retained for every step you make online. Privacy risks increase as these databases become vulnerable to theft and accidental disclosure. Meanwhile, service providers have to dealt with the expense of storing and maintaining these large databases.

Mandatory Data Retention

The EU Data Retention Directive, adopted by the European Union in 2006 (for the background facts click here), is the most prominent example of a mandatory data retention framework (for a detailed analysis click here). The highly controversial Directive compels all ISPs and telecommunications service providers operating in Europe to retain a subscriber's incoming and outgoing phone numbers, IP addresses, location data, and other key telecom and Internet traffic data for a period of 6 months to 2 years, for all European citizens, including those not suspected or convicted of any crime. The Directive has been opposed by lawmakers in the European Parliament who argue that it fosters a surveillance society and undermines fundamental rights. The European Data Protection Supervisor named the Directive as "the most privacy invasive instrument ever adopted by the EU in terms of scale and the number of people it affects."

Despite that the the Bundestag's legal experts of the Working Group on Data Retention on April published an opinion stating that "it is impossible to rephrase the Directive in such a way that it would ensure compliance with the Charter of Fundamental Rights", a number of countries have already transposed the Directive into national legislation including Austria, Bulgaria, Denmark, Estonia, France, Italy, Latvia, Liechtenstein(see page 127), Malta (see also), the Netherlands, Poland, Portugal,Slovakia, Slovenia, Spain, Norway, and the United Kingdom along with some non European Union countries such as Serbia and Iceland.
Other countries fight against it like Cyprus, Czech Republic, Germany, Greece (I sense that the pending change of Constitution will bear surprises), and Romania.

The Dutch Senate on April approved a long-anticipated shortening of mandatory retention periods for internet data to six months, it published its correspondence with the Dutch Minister of Security and Justice on the Data Retention Directive evaluation by the European Commission. The Senate criticized the report for "too easily sidestepping" several Constitutional Court cases across the European Union, in which implementation laws were ruled unconstitutional or the principle of blanket data retention itself was deemed in breach of the ECHR.

It is worth noting that on May the European Commission rushed into an agreement with US concerning the exchange of PNR (Passenger Name Record) data on individuals and circulated the final agreement prior to formally submitting to the Council of the European Union and the European Parliament for their agreement. The European Commission's Legal Service coming later advised that the PNR is "not compatible with fundamental rights".

In USA according to the newly released 2010 Wiretap Report, federal and state courts approved that wiretaps reached a new all - time high. increased by a 34%. It must be noted that in the data are not included interceptions regulated by the Foreign Intelligence Surveillance Act (FISA) or interceptions approved by the President outside the exclusive authority of the federal wiretap law and the FISA).

As the Electronic Frontier Foundation reports, on July the House passed a bill that contains a mandatory data retention provision that would require your Internet service providers to retain 12 months' worth of personal information - while the National Sheriffs Association strongly supported the bill asking for a 18 months period - that could be used to identify what web sites you visit and what content you post online. The bill was re-written to also include the enforced retention of customers’ names, addresses, phone numbers, credit card numbers and bank account numbers. This came as a result of the calls of the DOJ back in January when Jason Weinstein, deputy assistant attorney general at the Justice Department, said that data retention was crucial to fighting Internet crimes, especially online child pornography. In response to questions, he added  that up to two years of data retention "would be a useful starting point," which echoes what FBI director Robert Mueller told Congress in 2008.

The internet and telecom providers can handle the additional open-ended costs of mandatory data retention, since those costs will be transferred to the consumers. It will be the same as a new hidden tax. Smaller businesses, and start-ups may not be able to bear the added costs, thus reducing innovation, and killing competition with the big internet companies. Many organizations are actively opposing the bill claiming that it will devastate human society and U.S. Society as whole. By the same time the chief lawyer of the National Security Agency testifying to a Senate hearing stated that he believes the agency has the authority to track Americans via cell phones.

With the fiscal deficit plague infecting the whole West it is very possible that social unrest is on the top list of future events. In this upcoming time of crises the West governments will be called to prove that they are not authoritarian powers, that they listen and serve the population's demands and finally that they are credible and accountable entities enhancing the democratic liberties at the expense of their own political careers. Don't hold your breath...