Quotulatiousness

November 18, 2013

Lifelogging in 30-second intervals

Filed under: Media, Technology — Tags: , , , — Nicholas @ 15:38

Jerry Brito is a sousveillance fan and he thinks you should be too:

The Narrative Clip is a digital camera about the size of a postage stamp that clips to one’s breast pocket or shirt collar and takes a photo every thirty seconds of whatever one’s seeing. The photos are uploaded to the cloud and can be accessed on demand with a smartphone app, making it easy to look up any moment in one’s life. When the project to mass-produce these cameras first hit Kickstarter, I knew I had to have one, and with any luck mine will be arriving in a couple of weeks.

The prospect of having a complete photographic record of my life is compelling for many reasons. I have a terrible memory, especially for faces, so it will be interesting to see if this device can help. There are also moments in life that would be great to relive, but that one can’t – or one doesn’t know one should – be photographing. Narrative’s Instagram feed has some good examples of these. But most importantly, I want to help hasten our inevitable sousveillance future.

[…]

Being monitored in everyday life has become inescapable. So, as David Brin points out in The Transparent Society, the question is not whether there should be pervasive monitoring, but who will have access to the data. Will it only be the powerful, who will use the information to control? Or will the rest of us also be able to watch back?

Ideally, perhaps, we would all be left alone to live private lives under no one’s gaze. Short of halting all technological progress, however, that ship has sailed. Mass surveillance is the inevitable result of smaller cameras and microphones, faster processors, and incredibly cheap storage. So if I can’t change that reality, I want to be able to watch back as well.

November 14, 2013

How the internet was “weaponized”

Filed under: Government, Technology, USA — Tags: , , , , , — Nicholas @ 07:45

In Wired, Nicholas Weaver looks back on the way the internet was converted from a passive network infrastructure to a spy agency wonderland:

According to revelations about the QUANTUM program, the NSA can “shoot” (their words) an exploit at any target it desires as his or her traffic passes across the backbone. It appears that the NSA and GCHQ were the first to turn the internet backbone into a weapon; absent Snowdens of their own, other countries may do the same and then say, “It wasn’t us. And even if it was, you started it.”

If the NSA can hack Petrobras, the Russians can justify attacking Exxon/Mobil. If GCHQ can hack Belgicom to enable covert wiretaps, France can do the same to AT&T. If the Canadians target the Brazilian Ministry of Mines and Energy, the Chinese can target the U.S. Department of the Interior. We now live in a world where, if we are lucky, our attackers may be every country our traffic passes through except our own.

Which means the rest of us — and especially any company or individual whose operations are economically or politically significant — are now targets. All cleartext traffic is not just information being sent from sender to receiver, but is a possible attack vector.

[…]

The only self defense from all of the above is universal encryption. Universal encryption is difficult and expensive, but unfortunately necessary.

Encryption doesn’t just keep our traffic safe from eavesdroppers, it protects us from attack. DNSSEC validation protects DNS from tampering, while SSL armors both email and web traffic.

There are many engineering and logistic difficulties involved in encrypting all traffic on the internet, but its one we must overcome if we are to defend ourselves from the entities that have weaponized the backbone.

November 5, 2013

Camelot? Not so much…

Filed under: Government, History, USA — Tags: , , , , , — Nicholas @ 16:38

Gene Healy thinks that after fifty years, it’s time we stopped pretending that John F. Kennedy was a great president:

In a December 1963 interview, the president’s widow gave a name to the Kennedy mystique, telling journalist Theodore White of Jack’s fondness for the lyric from the Lerner and Loewe musical about King Arthur: “Once there was a spot, for one brief shining moment, that was known as Camelot.”

Much more than a “moment,” Camelot has proven an enduring myth.

JFK places near the top 10 in most presidential ranking surveys of historians, and in a 2011 Gallup poll, Americans ranked him ahead of George Washington in a list of “America’s greatest presidents.”

Kennedy’s murder was a national tragedy, to be sure, but an honest assessment of his record shows that our lawless and reckless 35th president was anything but a national treasure.

[…]

Indeed, JFK rarely let legal specifics deter his exercise of presidential power. At his behest in 1961, the Internal Revenue Service set up a “strike force,” the Ideological Organizations Project, targeting groups opposing the administration.

In 1962, outraged that American steel manufacturers had raised prices, he ordered wiretaps, IRS audits and dawn FBI raids on steel executives’ homes.

In 2011, Pulitzer Prize-winning national security journalist Thomas E. Ricks opined that JFK “probably was the worst American president of the [20th] century.”

In foreign policy, Ricks said, “he spent his 35 months in the White House stumbling from crisis to fiasco.”

True enough, after being buffaloed into the disastrous Bay of Pigs operation by the CIA, Kennedy helped bring the world to the brink of thermonuclear war in the Cuban Missile Crisis — not because Soviet missiles in Cuba altered the strategic balance of power (they did not), but because, as former Defense Secretary Robert McNamara later admitted, the missiles were “politically unacceptable” for the president.

Moreover, Kennedy’s aura of vitality and “vigah” depended on deliberate lies about his medical fitness for office: “I never had Addison’s disease … my health is excellent,” JFK told a reporter in 1961.

As Kennedy biographer Richard Reeves notes, JFK, who “received the last rites of the Catholic Church at least four times as an adult,” was “something of a medical marvel, kept alive by complicated daily combinations of pills and injections,” including a psychiatrically dangerous cocktail of painkillers and amphetamines regularly administered by celebrity physician Max “Dr. Feelgood” Jacobson.

Update, 6 November: Nick Gillespie assigns the blame (for the still-going hagiography) on the boomers in a piece titled “JFK Still Dead, Baby Boomers Still Self-Absorbed”

Indeed, by the early 1970s, what American over or under 30 didn’t agree with the sentiments expressed in a 1971 New York Times Magazine story on youth politics co-authored by Louis Rossetto, the future cofounder of Wired magazine? “John F. Kennedy, one of the leading reactionaries of the sixties, is remembered for his famous line, ‘Ask not what your country can do for you; ask what you can do for your country,’” seethed Rossetto and Stan Lehr. “Today, more and more young people are instead following the advice of [author] David Friedman: ‘Ask not what government can do for you… ask rather what government is doing to you.’”

But boomers were so much older then, they’re younger than that now, right? Despite the raft of revelations not just about governmental abuses of power generally but those involving JFK specifically, boomers just can’t quit him (or their airbrushed image of him) as their own mortality comes into focus. Here’s Vanity Fair’s James Wolcott, known for an “artful nastiness that’s long disappeared from his peers’ arsenal,” still going weak in the knees for Jack:

    I remember the light at the end of the school hallway reflecting off the floor as word went round and the weight in the air the days after. For kids my age, it was like losing a father, a father who had all of our motley fates in his hands…

As Splice Today’s Russ Smith — himself a boomer old enough to remember where he was when Kennedy was shot — notes, this is pure overstatement: “It wasn’t ‘like losing a father,’ and to suggest so is an affront to all the children who actually did lose their own father at a tender age.” Smith, who as the founder of the Baltimore and Washington City Papers and The New York Press knows a thing or two about reader appetites, is “betting that most of these books bomb, mostly because for most Americans those tumultuous days in 1963 are ancient history. Kennedy’s assassination might as well have occurred in the 19th century. Save for ascending and budding historians, where’s the audience for yet another encore of Camelot?”

November 4, 2013

Living in a Surveillance State: Mikko Hypponen at TEDxBrussels

Filed under: Liberty, Technology, USA — Tags: , , , , — Nicholas @ 00:01

November 2, 2013

FATCA may have significant (negative) influence on Canadian law

Filed under: Business, Cancon, Law, USA — Tags: , , , , — Nicholas @ 11:00

In Maclean’s, Erica Alini tries to explain just what the US Foreign Account Tax Compliance Act (FATCA) is, and why Canadians should be very concerned about it:

To say that FATCA is controversial is an understatement. The law is so complex and onerous to implement that some foreign banks have reportedly kicked out their U.S. clients in order to avoid dealing with it. Americans living abroad are queuing to give up their U.S. passports over it. The other problem with FATCA is that it asks foreign banks to do things that are often illegal in their home countries, such as passing on certain private information.

It has caused a stir in Canada as well, but the press here generally portrays it as something that affects only dual citizens and green-card holders. Given the number of Americans who live in Canada, that would be enough to make it a big issue (and a big headache for Ottawa). But the truth is FATCA has the potential to touch a much larger number of unsuspecting Canadians.

[…]

In general, what you get for signing an agreement to enforce FATCA is a pledge that the U.S. will do its best to share some of its information on your country’s potential tax cheats. You read that right: Not a duty to reciprocate your efforts, but a lame “we’ll try hard” promise. That’s because the U.S. government does not, at the moment, have permission to force U.S. banks to share information with foreign governments. Only Congress can change that.

That sounds bad enough, but it gets worse for Canada. We are the exception — the only country with which the U.S. has an automatic information-sharing agreement. Now, the trouble with FATCA is that it demands some new information: Not about the Canadian assets and incomes of people who live in the U.S. but about the assets and incomes of people who live in Canada but might have some ties to the U.S. While Canadian taxation, thankfully, is based on residency — you owe the CRA if you’ve been living in Canada — the U.S. has started demanding that its citizens file taxes regardless of where they live.

One of the unforeseen effects of this legislation is that it’s been making it much harder for US citizens to do business in other countries or to work in other countries for extended periods of time. If foreign banks refuse to allow US citizens to open accounts, you’re imposing significant costs and extra inconvenience on people who are in no way attempting to hide assets or income from the IRS. As with so many government initiatives, it probably won’t inconvenience actual criminals all that much, but will primarily impact ordinary — innocent — US citizens.

October 29, 2013

What happens when you challenge hackers to investigate you?

Filed under: Law, Technology — Tags: , , , , — Nicholas @ 09:13

Adam Penenberg had himself investigated in the late 1990s and wrote that up for Forbes. This time around, he asked Nick Percoco to do the same thing, and was quite weirded out by the experience:

It’s my first class of the semester at New York University. I’m discussing the evils of plagiarism and falsifying sources with 11 graduate journalism students when, without warning, my computer freezes. I fruitlessly tap on the keyboard as my laptop takes on a life of its own and reboots. Seconds later the screen flashes a message. To receive the four-digit code I need to unlock it I’ll have to dial a number with a 312 area code. Then my iPhone, set on vibrate and sitting idly on the table, beeps madly.

I’m being hacked — and only have myself to blame.

Two months earlier I challenged Nicholas Percoco, senior vice president of SpiderLabs, the advanced research and ethical hacking team at Trustwave, to perform a personal “pen-test,” industry-speak for “penetration test.” The idea grew out of a cover story I wrote for Forbes some 14 years earlier, when I retained a private detective to investigate me, starting with just my byline. In a week he pulled up an astonishing amount of information, everything from my social security number and mother’s maiden name to long distance phone records, including who I called and for how long, my rent, bank accounts, stock holdings, and utility bills.

[…]

A decade and a half later, and given the recent Edward Snowden-fueled brouhaha over the National Security Agency’s snooping on Americans, I wondered how much had changed. Today, about 250 million Americans are on the Internet, and spend an average of 23 hours a week online and texting, with 27 percent of that engaged in social media. Like most people, I’m on the Internet, in some fashion, most of my waking hours, if not through a computer then via a tablet or smart phone.

With so much of my life reduced to microscopic bits and bytes bouncing around in a netherworld of digital data, how much could Nick Percoco and a determined team of hackers find out about me? Worse, how much damage could they potentially cause?

What I learned is that virtually all of us are vulnerable to electronic eavesdropping and are easy hack targets. Most of us have adopted the credo “security by obscurity,” but all it takes is a person or persons with enough patience and know-how to pierce anyone’s privacy — and, if they choose, to wreak havoc on your finances and destroy your reputation.

H/T to Terry Teachout for the link.

October 28, 2013

Reason.tv – What We Saw At The Anti-NSA “Stop Watching Us” Rally

Filed under: Government, Liberty, USA — Tags: , , , , , — Nicholas @ 09:59

On October 26, 2013, protesters from across the political spectrum gathered in Washington, D.C. to take part in the Stop Watching Us rally, a demonstration against the National Security Agency’s domestic and international surveillance programs.

Reason TV spoke with protesters — including 2012 Libertarian Party presidential candidate Gary Johnson and former Congressman Dennis Kucinich — to discuss the rally, why people should worry about the erosion of privacy, and President Barack Obama’s role in the growth of the surveillance state.

Correction: Laura Murphy, Director of the ACLU Washington Legislative Office, was incorrectly identified as Susan N. Herman, ACLU President.

Produced by Joshua Swain, interviews by Todd Krainin.

October 4, 2013

John Lanchester on the Guardian‘s GCHQ files

Filed under: Britain, Government, Liberty, Media — Tags: , , , , , — Nicholas @ 07:44

Novelist John Lanchester was invited to look at the trove of files the Guardian received from Edward Snowden:

In August, the editor of the Guardian rang me up and asked if I would spend a week in New York, reading the GCHQ files whose UK copy the Guardian was forced to destroy. His suggestion was that it might be worthwhile to look at the material not from a perspective of making news but from that of a novelist with an interest in the way we live now.

I took Alan Rusbridger up on his invitation, after an initial reluctance that was based on two main reasons. The first of them was that I don’t share the instinctive sense felt by many on the left that it is always wrong for states to have secrets. I’d put it more strongly than that: democratic states need spies.

And all’s well in the world and we’re worried over nothing?

My week spent reading things that were never meant to be read by outsiders was, from this point of view, largely reassuring. Most of what GCHQ does is exactly the kind of thing we all want it to do. It takes an interest in places such as the Horn of Africa, Iran, and North Korea; it takes an interest in energy security, nuclear proliferation, and in state-sponsored computer hacking.

There doesn’t seem to be much in the documents about serious crime, for which GCHQ has a surveillance mandate, but it seems that much of this activity is covered by warrants that belong to other branches of the security apparatus. Most of this surveillance is individually targeted: it concerns specific individuals and specific acts (or intentions to act), and as such, it is not the threat.

Few people are saying we don’t need intelligence-gathering organizations like GCHQ, but we do have a right to be concerned about what they are doing when they’re not watching actual, known threats. They have capabilities that we generally thought were just from the pages of James Bond novels or Tom Clancy thrillers … and they use them all the time, not just for keeping tabs on the “bad guys”.

In the case of modern signals intelligence, this is no longer true. Life has changed. It has changed because of the centrality of computers and digital activity to every aspect of modern living. Digital life is central to work: many of us, perhaps most of us, spend most of our working day using a computer. Digital life is central to our leisure: a huge portion of our discretionary activity has a digital component, even things which look like they are irreducibly un-digital, from cycling to cooking.

[…]

As for our relationships and family lives, that has, especially for younger people, become a digital-first activity. Take away Facebook and Twitter, instant messaging and Skype and YouTube, and then — it’s hard to imagine, but try — take away the mobile phone, and see the yawning gap where all human interaction used to take place. About the only time we don’t use computers is when we’re asleep — that’s unless we have a gadget that tracks our sleep, or monitors our house temperature, or our burglar alarm, or whatever.

This is the central point about what our spies and security services can now do. They can, for the first time, monitor everything about us, and they can do so with a few clicks of a mouse and — to placate the lawyers — a drop-down menu of justifications.

Looking at the GCHQ papers, it is clear that there is an ambition to get access to everything digital. That’s what engineers do: they seek new capabilities. When it applies to the people who wish us harm, that’s fair enough. Take a hypothetical, but maybe not unthinkable, ability to eavesdrop on any room via an electrical socket. From the GCHQ engineers’ point of view, they would do that if they could. And there are a few people out there on whom it would be useful to be able to eavesdrop via an electrical socket. But the price of doing so would be a society that really did have total surveillance. Would it be worth it? Is the risk worth the intrusion?

That example might sound far-fetched, but trust me, it isn’t quite as far fetched as all that, and the basic intention on the part of the GCHQ engineers — to get everything — is there.

October 1, 2013

PRSM – the not-at-all-a-joke NSA sharing network

Filed under: Government, Technology, USA — Tags: , , , , — Nicholas @ 12:59

Techdirt‘s Mike Masnick on the no-we’re-actually-serious “joke” PRSM network:

Soon after the very earliest reporting on Ed Snowden’s leaked documents about PRISM, the folks from Datacoup put together the very amusing GETPRSM website, which looks very much like the announcement of a new social network, but (the joke is) it’s really the NSA scooping up all our data and making the connections. It’s pretty funny. Except, of course, when you find out that it’s real. And, yes, that seems to be the latest revelation out of Ed Snowden’s leaks. The NY Times has an article by James Risen and Laura Poitras (what a combo reporting team there!) detailing how the NSA has basically built its own “shadow” social network in which it tries to create a “social graph” of pretty much everyone that everyone knows, foreign or American, and it all happens (of course) without a warrant. And, note, this is relatively new:

    The agency was authorized to conduct “large-scale graph analysis on very large sets of communications metadata without having to check foreignness” of every e-mail address, phone number or other identifier, the document said. Because of concerns about infringing on the privacy of American citizens, the computer analysis of such data had previously been permitted only for foreigners.

    The agency can augment the communications data with material from public, commercial and other sources, including bank codes, insurance information, Facebook profiles, passenger manifests, voter registration rolls and GPS location information, as well as property records and unspecified tax data, according to the documents. They do not indicate any restrictions on the use of such “enrichment” data, and several former senior Obama administration officials said the agency drew on it for both Americans and foreigners.

There were apparently two policy changes that allowed this to happen, and both occurred in the past three years. First, in November of 2010, the NSA was allowed to start looking at phone call and email logs of Americans to try to help figure out associations for “foreign intelligence purposes.” Note that phrase. We’ll come back to it. For years, the NSA had been barred from viewing any content on US persons, and the NSA, President Obama and others have continued to insist to this day that there are minimization procedures that prevent spying on Americans. Except, this latest revelation shows that, yet again, this isn’t actually true.

September 28, 2013

Google is “fighting stupid with stupid”

Filed under: Business, Law, Technology — Tags: , , , — Nicholas @ 11:54

In Maclean’s, Jesse Brown looks at the rather dangerous interpretation of how email works in a recent court decision:

Newsflash: Google scans your email! Whether you have a Gmail account or just send email to people who do, Gmail’s bots automatically read your messages, mostly for the purpose of creating targeted advertising. And if you were reading this in 2005, that might seem shocking.

Today, I think most Internet users understand how free webmail works and are okay with it. But a U.S. federal judge has ruled otherwise. Yesterday, U.S. District Judge Lucy H. Koh ruled that Google’s terms of service and privacy policies do not explicitly spell out that Google will “intercept” users’ email (here’s the ruling).

The word “intercept” is crucial here, because it may put Google in the crosshairs of State and Federal anti-wiretapping laws. After Judge Koh’s ruling, a class-action lawsuit against Google can proceed, whose plaintiffs seek remedies for themselves and for class groups including “all U.S. citizen non-Gmail users who have sent a message to a Gmail user and received a reply…”. Like they say in Vegas, go big or go home.

[…]

An algorithm that scans my messages for keywords like “vacation” in order to offer me cheap flights is not by any stretch of the imagination a wiretap.

But Google has taken a different tack in their defence. If, they’ve argued, what Gmail does qualifies as interception, than so does all email, since automated processing is needed just to send the stuff, whether or not advertising algorithms or anti-spam filters are in use. This logic can be extended, I suppose, to all data that passes through the Internet.

You might call it fighting stupid with stupid, but I think it’s a bold bluff: rule us illegal, Google warns the court, and be prepared to deem the Internet itself a wiretap violation.

September 21, 2013

Justin Amash on congressional classified briefings

Filed under: Bureaucracy, Government, USA — Tags: , , , , — Nicholas @ 10:01

In The Atlantic, Garance Franke-Ruta has transcribed some of Representative Justin Amash’s comments on the ins-and-outs of confidential briefings offered to congressmen:

Amash, who has previously butted heads with Intelligence Committee Chairman Mike Rogers and ranking member Dutch Ruppersberger over access to classified documents, recounted what happened during remarks before libertarian activists attending the Liberty Political Action Conference in Chantilly, Virginia, Thursday night. I quote his anecdote in full here, because it’s interesting to hear what it feels like to be one of the activist congressmen trying to rein in National Security Agency surveillance:

    What you hear from the intelligence committees, from the chairmen of the intelligence committees, is that members can come to classified briefings and they can ask whatever questions they want. But if you’ve actually been to one of these classified briefings — which none of you have, but I have — what you discover is that it’s just a game of 20 questions.

    You ask a question and if you don’t ask it exactly the right way you don’t get the right answer. So if you use the wrong pronoun, or if you talk about one agency but actually another agency is doing it, they won’t tell you. They’ll just tell you, no that’s not happening. They don’t correct you and say here’s what is happening.

    So you actually have to go from meeting to meeting, to hearing to hearing, asking asking questions — sometimes ridiculous questions — just to get an answer. So this idea that you can just ask, just come into a classified briefing and ask questions and get answers is ridiculous.

    If the government — in an extreme hypothetical, let’s say they had a base on the moon. If I don’t know that there’s a base on the moon, I’m not going to go into the briefing and say you have a moonbase. Right? [Audience laughs.] If they have a talking bear or something, I’m not going to say, ‘You guys, you didn’t engineer the talking bear.’

    You’re not going to ask questions about things you don’t know about. The point of the Intelligence Committee is to provide oversight to Congress and every single member of Congress needs information. Each person in Congress represents about 700,000 people. It’s not acceptable to say, ‘Well, the Intelligence Committees get the information, we don’t need to share with the rest of Congress.’ The Intelligence Committee is not one of the branches of government, but that’s how it’s being treated over and over again.

September 18, 2013

The NSA scandal is not about mere privacy

Filed under: Government, Liberty, USA — Tags: , , , , — Nicholas @ 08:19

Last week, Yochai Benkler posted this in the Guardian:

The spate of new NSA disclosures substantially raises the stakes of this debate. We now know that the intelligence establishment systematically undermines oversight by lying to both Congress and the courts. We know that the NSA infiltrates internet standard-setting processes to security protocols that make surveillance harder. We know that the NSA uses persuasion, subterfuge, and legal coercion to distort software and hardware product design by commercial companies.

We have learned that in pursuit of its bureaucratic mission to obtain signals intelligence in a pervasively networked world, the NSA has mounted a systematic campaign against the foundations of American power: constitutional checks and balances, technological leadership, and market entrepreneurship. The NSA scandal is no longer about privacy, or a particular violation of constitutional or legislative obligations. The American body politic is suffering a severe case of auto-immune disease: our defense system is attacking other critical systems of our body.

First, the lying. The National Intelligence University, based in Washington, DC, offers a certificate program called the denial and deception advanced studies program. That’s not a farcical sci-fi dystopia; it’s a real program about countering denial and deception by other countries. The repeated misrepresentations suggest that the intelligence establishment has come to see its civilian bosses as adversaries to be managed through denial and deception.

[…]

Second, the subversion. Last week, we learned that the NSA’s strategy to enhance its surveillance capabilities was to weaken internet security in general. The NSA infiltrated the social-professional standard-setting organizations on which the whole internet relies, from National Institute of Standards and Technology to the Internet Engineering Task Force itself, the very institutional foundation of the internet, to weaken the security standards. Moreover, the NSA combined persuasion and legal coercion to compromise the commercial systems and standards that offer the most basic security systems on which the entire internet runs. The NSA undermined the security of the SSL standard critical to online banking and shopping, VPN products central to secure corporate, research, and healthcare provider networks, and basic email utilities.

Serious people with grave expressions will argue that if we do not ruthlessly expand our intelligence capabilities, we will suffer terrorism and defeat. Whatever minor tweaks may be necessary, the argument goes, the core of the operation is absolutely necessary and people will die if we falter. But the question remains: how much of what we have is really necessary and effective, and how much is bureaucratic bloat resulting in the all-too-familiar dynamics of organizational self-aggrandizement and expansionism?

The “serious people” are appealing to our faith that national security is critical, in order to demand that we accept the particular organization of the Intelligence Church. Demand for blind faith adherence is unacceptable.

September 15, 2013

Bruce Schneier on what you can do to stay out of the NSA’s view

Filed under: Liberty, Technology — Tags: , , , , , — Nicholas @ 10:44

Other than going completely off the grid, you don’t have the ability to stay completely hidden, but there are some things you can do to decrease your visibility to the NSA:

With all this in mind, I have five pieces of advice:

  1. Hide in the network. Implement hidden services. Use Tor to anonymize yourself. Yes, the NSA targets Tor users, but it’s work for them. The less obvious you are, the safer you are.
  2. Encrypt your communications. Use TLS. Use IPsec. Again, while it’s true that the NSA targets encrypted connections — and it may have explicit exploits against these protocols — you’re much better protected than if you communicate in the clear.
  3. Assume that while your computer can be compromised, it would take work and risk on the part of the NSA — so it probably isn’t. If you have something really important, use an air gap. Since I started working with the Snowden documents, I bought a new computer that has never been connected to the Internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my Internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it’s pretty good.
  4. Be suspicious of commercial encryption software, especially from large vendors. My guess is that most encryption products from large US companies have NSA-friendly back doors, and many foreign ones probably do as well. It’s prudent to assume that foreign products also have foreign-installed backdoors. Closed-source software is easier for the NSA to backdoor than open-source software. Systems relying on master secrets are vulnerable to the NSA, through either legal or more clandestine means.
  5. Try to use public-domain encryption that has to be compatible with other implementations. For example, it’s harder for the NSA to backdoor TLS than BitLocker, because any vendor’s TLS has to be compatible with every other vendor’s TLS, while BitLocker only has to be compatible with itself, giving the NSA a lot more freedom to make changes. And because BitLocker is proprietary, it’s far less likely those changes will be discovered. Prefer symmetric cryptography over public-key cryptography. Prefer conventional discrete-log-based systems over elliptic-curve systems; the latter have constants that the NSA influences when they can.

Since I started working with Snowden’s documents, I have been using GPG, Silent Circle, Tails, OTR, TrueCrypt, BleachBit, and a few other things I’m not going to write about. There’s an undocumented encryption feature in my Password Safe program from the command line; I’ve been using that as well.

I understand that most of this is impossible for the typical Internet user. Even I don’t use all these tools for most everything I am working on. And I’m still primarily on Windows, unfortunately. Linux would be safer.

The NSA has turned the fabric of the Internet into a vast surveillance platform, but they are not magical. They’re limited by the same economic realities as the rest of us, and our best defense is to make surveillance of us as expensive as possible.

Trust the math. Encryption is your friend. Use it well, and do your best to ensure that nothing can compromise it. That’s how you can remain secure even in the face of the NSA.

Reining-in the NSA … while it’s still even theoretically possible

Filed under: Government, Liberty, Technology, USA — Tags: , , — Nicholas @ 10:25

In TechDirt, Glyn Moody on the fleeting opportunity to rein-in the NSA:

In the wake of the continuing leaks about the NSA’s activities, most commentators are understandably still trying to get to grips with the enormity of what has been happening. But John Naughton, professor of the public understanding of technology at the UK’s Open University, tackles a very different question on his blog: what is likely to happen in the future, if things carry on as they are?

Naughton notes that the NSA’s mission statement includes the following phrase: “to gain a decision advantage for the Nation and our allies under all circumstances.” “Under all circumstances” means that as the Internet grows — and as we know, it is currently growing rapidly — so the NSA will naturally ask for resources to allow it to do tomorrow what it is doing today: monitoring more or less everything that happens online. Naughton then asks where that might lead if the political climate in the US remains sufficiently favorable to the NSA that it does, indeed, get those resources:

    The obvious conclusion therefore, is that unless some constraints on its growth materialise, the NSA will continue to expand. It currently has 35,000 employees. How many will it have in ten years’ time? Who can say: 50,000, maybe? Maybe even more? So we’re confronted with the likelihood of the growth of a bureaucratic monster.

    How will such a body be subjected to democratic oversight and control? Let me rephrase that: can such a monster be subjected to democratic control?

September 7, 2013

Maybe the conspiracy theorists just aren’t paranoid enough

Filed under: Government, Media, Technology, USA — Tags: , , , , — Nicholas @ 09:49

Bruce Schneier on the destruction of public trust in government agencies:

I’ve recently seen two articles speculating on the NSA’s capability, and practice, of spying on members of Congress and other elected officials. The evidence is all circumstantial and smacks of conspiracy thinking — and I have no idea whether any of it is true or not — but it’s a good illustration of what happens when trust in a public institution fails.

The NSA has repeatedly lied about the extent of its spying program. James R. Clapper, the director of national intelligence, has lied about it to Congress. Top-secret documents provided by Edward Snowden, and reported on by the Guardian and other newspapers, repeatedly show that the NSA’s surveillance systems are monitoring the communications of American citizens. The DEA has used this information to apprehend drug smugglers, then lied about it in court. The IRS has used this information to find tax cheats, then lied about it. It’s even been used to arrest a copyright violator. It seems that every time there is an allegation against the NSA, no matter how outlandish, it turns out to be true.

Guardian reporter Glenn Greenwald has been playing this well, dribbling the information out one scandal at a time. It’s looking more and more as if the NSA doesn’t know what Snowden took. It’s hard for someone to lie convincingly if he doesn’t know what the opposition actually knows.

All of this denying and lying results in us not trusting anything the NSA says, anything the president says about the NSA, or anything companies say about their involvement with the NSA. We know secrecy corrupts, and we see that corruption. There’s simply no credibility, and — the real problem — no way for us to verify anything these people might say.

« Newer PostsOlder Posts »

Powered by WordPress