Wednesday, June 6, 2012

Obama Surveillance:Thousands of secret court orders allow government to spy on Americans



Published on 5 Jun 2012 by

The Electronic Communications Privacy Act of 1986 has created a culture of complete secrecy. According to a recent study, it was revealed that a federal docket which handles thousands of secret cases has allowed mass electronic surveillance. The online activity, cell phone records and information stored on a person's computer is all fair game and now privacy groups are pushing for this law to be updated. Kade Crockford, privacy rights coordinator for ACLU, joins us with more.

Like us and/or follow us:
http://twitter.com/RT_America
http://www.facebook.com/RTAmerica

Monday, June 4, 2012

" Flame " Malware was Signed By Rogue Microsoft Certificate.

Microsoft released an emergency Windows update on Sunday after revealing that one of its trusted digital signatures was being abused to certify the validity of the Flame malware that has infected computers in Iran and other Middle Eastern Countries.

The compromise exploited weaknesses in Terminal Server, a service many enterprises use to provide remote access to end-user computers. By targeting an undisclosed encryption algorithm Microsoft used to issue licenses for the service, attackers were able to create rogue intermediate certificate authorities that contained the imprimatur of Microsoft's own root authority certificate—an extremely sensitive cryptographic seal. Rogue intermediate certificate authorities that contained the stamp were then able to trick administrators and end users into trusting various Flame components by falsely certifying they were produced by Microsoft.

"We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft," Microsoft Security Response Center Senior Director Mike Reavey wrote in a blog post published Sunday night. "We identified that an older cryptography algorithm could be exploited and then be used to sign code as if it originated from Microsoft. Specifically, our Terminal Server Licensing Service, which allowed customers to authorize Remote Desktop services in their enterprise, used that older algorithm and provided certificates with the ability to sign code, thus permitting code to be signed as if it came from Microsoft."

The exploit, which abused a series of intermediate authorities that were ultimately signed by Microsoft's root authority, is the latest coup for Flame, a highly sophisticated piece of espionage malware that came to light last Monday. Flame's 20-megabyte size, it's extensive menu of sophisticated spying capabilities, and its focus on computers in Iran have led researchers from Kaspersky Lab, Symantec, and other security firms to conclude it was sponsored by a wealthy nation-state. Microsoft's disclosure follows Friday's revelation that the George W. Bush and Obama administrations developed and deployed Stuxnet, the highly advanced software used to set back the Iranian nuclear program by sabotaging uranium centrifuges at Iran's Natanz refining facility.

The emergency update released by Microsoft blacklists three intermediate certificate authorities tied to Microsoft's root authority. All versions of Windows that have not applied the new patch can be tricked by the Flame attackers into displaying cryptographically generated assurances that the malicious wares were produced by Microsoft.

Microsoft engineers have also stopped issuing certificates that can be used for code signing with the Terminal Services activation and licensing process. The ability of the licensing mechanism to sign untrusted code that linked Microsoft's root authority is a mistake of breathtaking proportions. None of Microsoft's Sunday night blog posts explained why such design was ever allowed to be put in place. A description of the Terminal Services License Server Activation refers to a "limited-use digital certificate that validates server ownership and identity." Based on Microsoft's description of the attack, it would appear the capabilities of these certificates weren't as limited as company engineers had intended.

"This is a pretty big goof," Marsh Ray, a software developer two-factor authentication company PhoneFactor, told Ars. "I don't think anyone realized that this enabled the sub CA that was present on the licensing server to have the full authority of the trusted root CA itself."
Microsoft's mention of an older cryptography algorithm that could be exploited and used to sign code as if it originated from Microsoft evoked memories of an attack from 2008 to mint a rogue certificate authority that could be trusted by all major browsers. The attack in part relied on weaknesses in the MD5 cryptographic hash function that made it susceptible to "collisions," in which two or more different plaintext messages generated the same cryptographic hash. By unleashing 200 PlayStation 3 game consoles to essentially find a collision, the attackers could become a certificate authority that could spawn SSL (secure sockets layer) credentials trusted by major browsers and operating systems.

Based on the language in Microsoft's blog posts, it's impossible to rule out the possibility that at least one of the certificates revoked in the update was also created using MD5 weaknesses. Indeed, two of the underlying credentials used MD5, while the third used the more advanced SHA-1 algorithm. In a Frequently Asked Questions section of Microsoft Security Advisory (2718704), Microsoft's security team also said: "During our investigation, a third Certificate Authority has been found to have issued certificates with weak ciphers." The advisory didn't elaborate.

It's also unclear if those with control of one of the rogue Microsoft certificates could sign Windows software updates. Such a feat would allow attackers with control over a victim network to hijack Microsoft's update mechanism by using the credentials to pass off their malicious wares as official patches. Microsoft representatives didn't respond to an e-mail seeking comment on that possibility. This article will be updated if an answer arrives later.
Two of the rogue certificates were chained to a Microsoft Enforced Licensing Intermediate PCA. A third was chained to a Microsoft Enforced Licensing Registration Authority CA, and ultimately to the company's root authority. In addition to potential exploits from the actors behind Flame, unrelated attackers could also use the certificates to apply Microsoft's signature to malicious pieces of software.

A third Microsoft advisory pointed out that Flame so far has been found only on the machines of highly targeted victims, so the "vast majority of customers are not at risk."
"That said, our investigation has discovered some techniques used by this malware that could also be leveraged by less sophisticated attackers to launch more widespread attacks," Jonathan Ness, of Microsoft's Security Response Center, continued. "Therefore, to help protect both targeted customers and those that may be at risk in the future, we are sharing our discoveries and taking steps to mitigate the risk to customers."



http://arstechnica.com/security/2012/06/flame-malware-was-signed-by-rogue-microsoft-certificate/

Stuxnet Flame And War By Other Means.

I was one of the first to report about the source of the Stuxnet computer virus in The American Conservative magazine back in December 2010.  It was created in an Israeli laboratory at its Dimona nuclear facility. The New York Times picked up the story over a year later.  We have now learned, from a deliberate leak, that the US National Security Agency and Department of Energy helped the Israelis to develop the virus and that an infected component was placed in the Iranian computer network with the assistance of the CIA (apparently using an agent affiliated with the Mujaheddin e Khalq supplied by the Israelis).

The timing of the leak of the story by the White House is, of course, interesting.  It clearly is intended to burnish President Obama’s national security credentials, demonstrating that the White House is wisely covertly waging war against Iran to avoid a shooting war.  At least that is the spin. But Obama is nevertheless waging war, which the Iranians have already noted, and which will make any agreement on their nuclear program impossible.  So rather than mitigating what Washington and Tel Aviv are describing as the serious problem posed by possible Iranian ambitions, it has only made the issue insoluble without an actual armed conflict.  So much for war by proxy.

But the more disturbing aspect of the story is the apparent enthusiasm by the White House to engage in de facto warfare as long as there are no boots on the ground and Americans being killed.  The decision to go after Iran by computer virus was apparently made by President Bush but became effective shortly after Obama took office. 

Cyberwarfare, which is now a reality rather than just a Pentagon money pit, is in a league with drones.  They both make it possible to attack another country without the type of disagreeable consequences that normally, in the past, eventually brought about an end to the fighting.  Perpetual warfare by other means is now an aspect of governance for the United States.  And both Stuxnet and drones are a contagion. 

The virus is not containable and has already been cloned by hackers while drone technology is becoming cheaper and will no doubt be the no-war no-peace option for many countries with unstable borders.  Both the virus and the drone technology will, and have already, spilled over into the United States.  Drones have increased the government’s ability to surveil the public everywhere all the time and we have just learned of yet a new official lab created virus called Flame, which has also migrated to personal and business computers.

http://www.theamericanconservative.com/stuxnet-flame-and-war-by-other-means/

Sunday, June 3, 2012

Flame Attack : Details Emerging Slowly.



More details about the Flame malware are emerging as security analysts study the infection.


The latest numbers from Kaspersky Lab researcher suggest around 1,000 Windows PCs have been infected, the vast majority of which are in the Middle East. The security company reported 189 infections in Iran, 98 in Israel/Palestine and 32 in Sudan identified so far. Infections have been discovered in a wide range of sectors, including academia, private companies, and government.


Researchers have confirmed that Flame, Flamer and Skywiper are all the same thing, after some initial confusion as it was given three different names by different research groups.

The malware is best described as a cyber-espionage toolkit, and is written partly in the Lua scripting language with compiled C++ code linked in, with five different encryption methods and a SQLite database to store structured information. The malware is controlled by a network of command and control servers, and data was regularly sent from compromised PCs to C&C servers through a covert SSL channel.


While many initial reports hyped up the complexity of the malware, closer analysis of Flame suggests that the tools it uses are not that complex, but rather the ways the whole package works together is the most sophisticated aspect of its design.


Justin Doo, security practice director for MENA region, Symantec, told ITP.net the day after the malware emerged that Flame gives who ever is controlling the malware a range of different tools.


"It is particularly sophisticated in terms of the capabilities it has. Depending on who is controlling the malware depends on its behaviour. In one instance it may record voice, through the microphone, and in another instance it may be a Trojan so it looks like an application but it is doing something completely different," he said.


Flame is able to steal documents, take screenshots of users' desktops, spread via USB drives, disable security vendor products, turn on PC microphones, turn on Bluetooth and search for nearby Bluetooth devices and intercept network traffic. It has also been discovered that Flame can record Skype conversations.


The malware is also able to identify which anti-virus software, if any, is in use on its host machine, and modifies behaviour to avoid detection.

http://www.itp.net/589284-flame-attack-details-emerging-slowly

Tuesday, May 22, 2012

CISPA : Passes House In Last Minute Unexpected Vote.

The House of Representatives has approved Cyber Intelligence Sharing and Protection Act with a vote count of 248-168. The bill is now headed for the Senate. President Barack Obama will be able to sign or cancel it pending Senate approval.

Initially slated to vote on the bill Friday, the House of Representatives decided to pass Cyber Intelligence Sharing and Protection Act (CISPA) Thursday after approving a number of amendments.

 
Apart from cyber and national security purposes, the bill would now allow the government to use private information obtained through CISPA for the investigation and prosecution of “cybersecurity crime,” protection of individuals and the protection of children. The new clauses define “cybersecurity crime” as any crime involving network disruption or hacking.

“Basically this means CISPA can no longer be called a cyber security bill at all. The government would be able to search information it collects under CISPA for the purposes of investigating American citizens with complete immunity from all privacy protections as long as they can claim someone committed a 'cybersecurity crime.' Basically it says the Fourth Amendment does not apply online, at all,” Techdirt's Leigh Beadon said.
Declan McCullagh, correspondent from CNET News, says CISPA will cause more trouble than is immediately apparent.

“The most controversial section of CISPA is the language – that notwithstanding any other portion the of law, companies can share what they want as long as it’s for what they call a ‘cyber security purpose,'" he told RT.

The CISPA battleground in numbers


CISPA was introduced in the House last November.  Critics chided the bill, saying its broad wording could allow the government to spy on individual Internet users and block websites that publish vaguely defined ‘sensitive’ data.

 "[CISPA] doesn’t really have any protections against cyber threats, all it does is make people share their information. But that’s not going to solve the problem. What’s going to solve the problem is actual security measures, protecting the service in the first place, not spying on people after the fact," Internet activist Aaron Swartz told RT.

The White House issued a statement Wednesday saying President Barack Obama would be advised to veto the bill if he receives it. The Obama administration denounces the proposed law for potentially giving the government cyber-sleuthing powers that would allow both federal authorities and private businesses to sneak into inboxes and online activities in the name of combating Internet terrorism tactics.

We asked our Twitter followers what they think of CISPA's possible adoption into law – and they don't seem happy.


http://www.rt.com/news/house-cispa-vote-thursday-083/

Saturday, May 19, 2012

#Copyright Disclaimer Under Section 107 of the Copyright Act 1976.

A few pointers  for those who are unsure of the copyright act.

Copyright Disclaimer Under Section 107 of the Copyright Act 1976, allowance is made for fair use for purposes such as criticism, comment, news reporting, teaching, scholarship, and research. Fair use is a use permitted by copyright statute that might otherwise be infringing. Non-profit, educational or personal use tips the balance in favor of fair use.

Friday, May 18, 2012

#Twitter Backs Privacy Browser Project.

Micro-blogging service Twitter has declared its support for an initiative that lets people browse the web without being monitored.
The "Do Not Track" initiative stops firms tracking people as they visit several different websites.
The monitoring is done to help advertisers craft ads to a user's preferences and lifestyle.
Blocking the tracking depends on websites honouring requests from users to browse anonymously.
Do Not Track (DNT) has been brokered by the US Federal Trade Commission which wants people to be able to tell websites to stop gathering and sharing data when they visit.
Sites that decide to ignore users' requests to stop tracking them could be subject to FTC action.
A DNT option is available in the recent versions of the Firefox, Internet Explorer and Safari browsers. Turning on Do Not Track in Google's Chrome involves installing an add-on.

Browsers backing Do Not Track

  • Firefox 5+
  • IE 9+
  • Safari 5.1+
  • Chrome 17 (with add-on)
For DNT to work, websites have to agree to discard any data they would otherwise collect and share about what people do when they visit a site.
In a help document, Twitter said it would now respect the Do Not Track option in all the browsers that supported it.
However, it said that those that turn on DNT would notice a change in the information Twitter presented to them.
"We stop collecting the information that allows us to tailor Twitter based on your recent visits to websites that have integrated our buttons or widgets," it said in its help document.
A survey carried out by Mozilla, which makes the Firefox web browser, found that 8.6% of the users of its desktop browser and 19% of mobile browser users were opted in to Do Not Track.


http://www.bbc.com/news/technology-18114990