Showing posts with label eavesdrop. Show all posts
Showing posts with label eavesdrop. Show all posts

Friday, September 6, 2013

New NSA Revelations: Internet Privacy Encryption Virtually 'Defeated'

Thursday, September 5, 2013 by Common Dreams
NSA builds 'industry relationships' to control encryption technologies, deteriorate privacy safeguards
- Jacob Chamberlain, staff writer

Internet privacy safeguards known as encryption technologies promised by email, online banking, and other such online databases have been virtually 'defeated' by the U.S. National Security Agency, according to new documents obtained by the Guardian, New York Times, and ProPublica.

According to the Guardian—which has reported extensively on the NSA's dragnet surveillance practices revealed by NSA whistleblower Edward Snowden—the NSA and its British counterparts the GCHQ have used "covert measures" to control and manipulate international encryption standards to tprivacyhe benefit of the NSA, largely through building "industry relationships" with many technology companies and internet service providers.

As joint reporting by ProPublica and the New York Times explains, according to the documents and interviews with industry officials, the NSA has deployed "custom-built, superfast computers to break codes" and began collaborating with "technology companies in the United States and abroad" to build 'backdoor' entry points into their products and introduce weaknesses into their encryption standards.

The records do not identify which specific companies have been working with the NSA to this extent. However, one document does reveal that a GCHQ team has been working to develop ways into encrypted traffic on the "big four" service providers, named as Hotmail, Google, Yahoo and Facebook.

"By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet."

Through these relationships the NSA has become nearly immune to most encryption technologies, and has thus mastered the use of "supercomputers" to break encryption with "brute force," leaving a dying number of encryption technologies immune to NSA surveillance.

As one of the NSA documents obtained by the news agencies states, the NSA "actively engages US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs," and in turn inserts "vulnerabilities into commercial encryption systems."

"US and British intelligence agencies have successfully cracked much of the online encryption relied upon by hundreds of millions of people to protect the privacy of their personal data, online transactions and emails," the Guardian reports.

"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies," a 2010 GCHQ document states. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable."

"Cryptography forms the basis for trust online," said Bruce Schneier, an encryption specialist and fellow at Harvard's Berkman Center for Internet and Society. "By deliberately undermining online security in a short-sighted effort to eavesdrop, the NSA is undermining the very fabric of the internet."

The NSA's encryption busting program called "Sigint [signals intelligence] enabling" received $254.9 million in 2013 alone (compared to $20 million allotted to the previously exposed PRISM program).

“The encryption technologies that the NSA has exploited to enable its secret dragnet surveillance are the same technologies that protect our most sensitive information, including medical records, financial transactions, and commercial secrets,” stated Christopher Soghoian, principal technologist of the ACLU’s Speech, Privacy and Technology Project.

Soghoian continues:
Even as the NSA demands more powers to invade our privacy in the name of cybersecurity, it is making the internet less secure and exposing us to criminal hacking, foreign espionage, and unlawful surveillance. The NSA’s efforts to secretly defeat encryption are recklessly shortsighted and will further erode not only the United States’ reputation as a global champion of civil liberties and privacy but the economic competitiveness of its largest companies.

Tuesday, September 28, 2010

White House Wants to Wiretap Internet Communications

The Obama administration is drawing up legislation to make it easier for US intelligence services to eavesdrop on the Internet, including email exchanges and social networks.
By AFP
Posted on September 27, 2010

The Obama administration is drawing up legislation to make it easier for US intelligence services to eavesdrop on the Internet, including email exchanges and social networks, The New York Times said Monday.

The White House intends to submit a bill before Congress next year that would require all online services that enable communications to be technically capable of complying with a wiretap order, including being able to intercept and unscramble encrypted messages, the Times reported.

The services would include encrypted email transmitters like BlackBerry, social networking websites like Facebook and peer-to-peer messaging software like Skype.

Federal law enforcement and national security officials are seeking the new regulations, arguing that extremists and criminals are increasingly communicating online rather than using phones.

"We're talking about lawfully authorized intercepts," said Federal Bureau of Investigation (FBI) general counsel Valerie Caproni.

"We're not talking expanding authority. We're talking about preserving our ability to execute our existing authority in order to protect the public safety and national security."

Officials from the White House, Justice Department, National Security Agency, FBI and other agencies have been meeting in recent months to craft the proposals, the Times said.

But, citing officials familiar with the discussions, it said the participants had not yet agreed on important elements, such as how to define which entities are considered communications service providers.

President Barack Obama's administration is seeking a broad mandate that would also apply to companies whose servers are operated abroad, such as Research in Motion, the Canadian maker of BlackBerry smartphones.

As an example, officials told the Times that investigators discovered that Faisal Shahzad, the suspect from the failed Times Square bombing in May, had been using a communication service without prebuilt interception capacity.

That meant that there would have been a delay before he could have been wiretapped, had he aroused suspicion beforehand, the officials said.