Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Boston PD used facial recognition surveillance during 2013 music festival

- 0 comments

During the 2013 Boston Calling music festivals, the Boston police department used a facial recognition surveillance system to keep an eye on those who attended. Thousands of faces were captured, according to Dig Boston, via ten cameras that could perform so-called "intelligent video analysis" in real time.

The story is an interesting one, something that revolves around Dig Boston's reporters "searching the deep web" and spotting unsecured documents related to the Boston Calling surveillance programs. IBM is said to have worked with law enforcement in providing a facial recognition system that would tag "every person" that attended.

IBM is said to have licensed an Intelligent Operations Center, and at the heart of it all was a system being tested via Boston Calling surveillance that analyzed, in real time, things like faces and bodies, skin color, clothing, traffic patterns, and more. In addition, information nabbed from social networks was integrated in real time and factored into the overall equation.

There is a division between what the Boston PD says about the discovery and what the alleged documents reveal. According to Dig Boston, the docs have photos of police officers watching the IBM system while the music festival took place, but a statement from the department said, "BPD was not part of this initiative. We do not and have not used or possess this type of technology."

Boston Mayor's press secretary had different things to say, however, confirming that surveillance was used during the two music festivals, summing it up by saying that ultimately the city didn't go with the software, because it had "not seen a clear use case for this software that held practical value for the City's public safety needs."



Source : slashgear.com
[Continue reading...]

Wickr founder details FBI request for backdoor

- 0 comments


In December, it was reported that security firm RSA -- according to documents leaked by Edward Snowden -- was paid millions by the NSA to put a back door into its encryption products. A couple days later, the company denied having a secret contract with the government agency, and said that it never knowingly put a back door in its offerings. That didn't stop some companies from gravitating away from RSA, however, and one such company was Wickr. The company's founder, Nico Sell, announced this change at an RSA Security Conference, during which she made it clear her company would not have a back door and that users' security was important. Immediately after, an FBI agent approached her with a request -- to add a backdoor on behalf of the agency.

Wickr is a self-destructing message service akin to Snapchat, and it's company tagline is "Leave No Trace". The company touts the use of military-grade encryption for all video, picture, audio, and text messages, with secure file-shredding features for users and the ability to control who, where, and for how long one's own messages are available. Security, obviously, is the company's biggest point of focus.

According to Sell, immediately after exiting the stage at the conference where she detailed the service's security elements, an FBI agent casually approached her with a request that her company introduce a backdoor into the service that would give the FBI access to users' messages. The approach was said to be casual, something Sell states is apparently how such approaches are commonly done. "Always casual, testing, because most people would say yes."

Reportedly, Sell's response was an ear-full for the agent on the Constitution, a bit about George Washington, and followed up with a request for details on his part. Said Sell, "I asked if he had official paperwork for me, if this was an official request, who his boss was. He backed down very quickly." Sell has suggested the NSA revert to a surveillance model that involved the targeting of individuals rather than the mass surveillance of communications. "I'm not against helping law enforcement, but the most important thing to me is protecting my friends and family the best way I know how. There are plenty of ways to track people without trampling human rights."




SOURCE: PC Magazine
[Continue reading...]

NSA project working towards encryption-breaking quantum computer, reveals Snowden doc

- 0 comments


According to documents leaked by Edward Snowden, the NSA dreams of a quantum computer that can break nearly every type of encryption -- one it is working towards (in part, at least) via a program called Penetrating Hard Targets, a $79.7 million project. The NSA isn't the only entity working on making a quantum computer reality, and such technologies would have widespread benefits beyond the cryptographically-oriented industry and various spy games.

Whether the NSA has advanced beyond similar efforts underway at the civilian level is unknown, but the Washington Post is reporting such efforts on the government's part are no farther ahead in terms of progress. A large amount of the work is reportedly taking place via classified contracts with a College Park laboratory, but not much is known beyond that.

If such a technology is developed, all forms of public key encryption could be broken. The documents seem to state the NSA is performing a lot of its research in Faraday cages, something said to be necessary to keep the "delicate" experiments up and running. No immediate breakthroughs seem likely, however, and MIT associate professor Scott Aaronson took that a step further, saying: "It seems improbable that the NSA could be that far ahead of the open world without anybody knowing it."

Experts who spoke to the Washington Post expressed doubt that any such computer could be developed in the next five years, but that isn't stopping the NSA from trying. The security agency, according to the document, is concerned that quantum computing could have future implications on both the ability to spy on the communications of foreign entities, but also to protect its own communications from other agencies beyond the US.






SOURCE: Washington Post
[Continue reading...]

'Facebook' hit with lawsuit for reportedly breaching messages privacy

- 0 comments


In a complaint filed late last month, two Facebook users filed a lawsuit against the social network, claiming it scans the contents of private messages and performs activities branching off this that ultimately violate various California laws and the Electronics Communications Privacy Act. Facebook has denied the claims, saying they are "without merit."

According to the lawsuit, Facebook scans through the content contained within its users' private messages, the purpose of which is to use the culled data for advertisement purposes -- the information is reportedly shared with both marketers and advertisers. Specifically, it is said that messages created using a link to a third-party website causes Facebook to scan not only the message's content, but also follow the link and ultimately create a "profile" of the user's Internet activity.

The lawsuit's plaintiffs are hoping to gain a class-action lawsuit that encompasses all Facebook users that have been on either the receiving or the sending end of a private message on the social network within the last two years -- the stipulation being that they contained a Web link. Up to $10,000 in damages for each user is being sought, as well as requiring Facebook to halt the activity.

As mentioned, Facebook has called the allegations baseless, but further statement from the social network isn't available. If the class-action lawsuit goes through, this would be the latest in a long line of privacy concerns raised regarding Facebook. Back in August 2013, the company began laying out a variety of rule and policy changes that were taking place, among them being a particular emphasis on its Data Use Policy. The rewrite aimed to, among other things, "highlight how we use the information we receive to show you ads that we hope you find relevant and interesting."







SOURCE: Bloomberg
[Continue reading...]

Laptop searches by U.S. border agents ruled legal

- 0 comments


For most people, one's laptop is a like a trusted friend, packed full of data that one would not give out part and parcel to just anyone, particularly not strangers. Random laptop searches at United States borders have been taking place for years, and have been the subject of much outcry, particularly due to the complete lack of suspicion needed to perform the search. Civil rights attorneys filed a lawsuit against this activity, citing reasons of being unconstitutional, but a New York judge has dismissed their complaint, giving border agents the go-ahead.

Travelers, when entering the United States, are vulnerable to potential laptop searches by border agents. These searches aren't guaranteed to take place, but if you're one of the unfortunate travelers who gets tagged, you have no say in having your digital data picked through. There have been instances where laptops have been confiscated, such as the case regarding Pascal Abidor, a French-American citizen who, upon entering the U.S. border territory, had his laptop confiscated by the border personnel.

It is being argued that allowing border agents to search laptops -- which includes the machines of news photographers and those of similar professions -- will give access to both sensitive and confidential information. The judge had a different view of this however, saying that, in the case of Abidor, who was abroad researching Shiite history, he "cannot be so naive to expect that when he crosses into Syrian or Lebanese border that the contents of his computer will be immune from searches and seizure at the whim of those who work for Bashar al-Assad or Hassan Nasrallah."

Thus was part of U.S. District Judge Edward Korman's final decision, dismissing the lawsuit and ruling that reasonable suspicion is not needed to perform a laptop search. The plantiffs, it was ruled, did not show any injury resulting from the searches, and legal precedents were used to conclude that US border crossings allowed for government searches -- reasonable suspicion aside -- in the name of national security.

Said ACLU lawyer Catherine Crump: "Unfortunately, these searches are part of a broader pattern of aggressive government surveillance that collects information on too many innocent people, under lax standards, and without adequate oversight." The organization is debating about appealing the judge's decision, though whether it will is yet to be determined.





SOURCE: Associated Press
[Continue reading...]

NSA phone surveillance ruled legal by NY judge [UPDATE]

- 0 comments
In a ruling on federal phone-tracking this week a U.S. District Judge based in New York has ruled that the NSA’s actions thus far have been legal. Judge William Pauley sent a ruling on Friday, the 27th of December, saying the NSA program “represents the government’s counter-punch” in efforts to eliminate al-Qaida network efforts. This ruling dismisses a lawsuit brought on by the American Civil Liberties Union.
 


At this time the ACLU has not sent out comment on the matter, but we’ll expect that they’ll have something to say imminently. The ACLU brought case to a New York court earlier this year after NSA documents were leaked by Edward Snowden. The ACLU suggested that the programs outlined in these documents far exceeded the congressional authority of the Patriot Act, authorized after September 11th, 2001 and reauthorized in the years 2005 and 2010.

Judge Pauley’s ruling this week suggests that the government’s efforts have “adapted to confront a new enemy: a terror network capable of orchestrating attacks across the world.” According to SFGate, Judge Pauley suggested that the data-collection programs outlined by Snowden’s documents were part of this new adaptation.

At this time it would appear that Judge Pauley’s dismissal of the lawsuit brought on by the ACLU will require the group to seek higher court if they wish to continue. Have a peek at the timeline below to gain greater insight into the ever-expanding world of the NSA’s programs as revealed over the preceding set of months in 2013.

UPDATE: You can now read the full ruling in PDF form courtesy of the ACLU.




[Continue reading...]

Samsung KNOX flaw leaves Galaxy S 4 compromised say researchers

- 0 comments
Samsung's KNOX security system on the Galaxy S 4 has a significant security hole that could allow data believed secure to be intercepted, including messages, browser use, and files transferred, researchers claim, though the South Korean company denies the seriousness of the supposed flaw. KNOX, which Samsung launched at Mobile World Congress earlier this year, is the company's attempt to take on BlackBerry in the enterprise, creating secure partitions on the phone for business and personal use. However, researchers at the Ben-Gurion University of the Negev claim to have discovered a flaw in KNOX that allows data to be easily intercepted, despite supposedly being protected by the system.

According to the university, the issue was inadvertently spotted by Ph.D. student Mordechai Guri while doing other testing on the Galaxy S 4. He found that by loading a special, compromised app on the non-secure, "personal" part of the Android smartphone, all of the data transferred by the handset - including what was used by the "secure" part - could be monitored.

Alternatively, the app - which could be disguised as a game or other simple application - could even surreptitiously inject its own code into the secure data transfer, the researchers say.

According to Guri, the fault has been replicated on several Galaxy S 4 handsets purchased through retail stores. KNOX can be downloaded to the phone, having been released earlier this year; the system is preloaded on the Galaxy Note 3. Although it carries no cost for users to download, corporations must pay a licensing fee for the various server-side components to the system.

Meanwhile, Samsung maintains that its preliminary inquiries suggest the issue is not as serious as the university researchers claim. Although conceding that a loophole exists, in a comment to the WSJ, a Samsung spokesperson argued that the original testing looked to have been done on a device not equipped with the typical security measures.

A typical enterprise user would have other software on the Galaxy S 4 which the lab team did not load, Samsung claimed, and with that in place "the core Knox architecture cannot be compromised or infiltrated by such malware" the spokesperson concluded.

Around 500 Galaxy S 4 handsets have been bought by the Defense Information Systems Agency and are undergoing testing, in collaboration with the NSA, to ascertain their potential safety for use on Pentagon systems. However, a US Department of Defense spokesperson said in response to the reported flaw, none of the handsets had been deployed, and the phone was still not approved for Pentagon use.

Samsung has already patched some holes in the KNOX system, releasing security updates as it identifies issues. The company is continuing to look into the claims made by the Israeli university.




VIA : Android Community
[Continue reading...]

Hackers break into Washington Post servers for third time in three years

- 0 comments
The Washington Post's servers were penetrated by hackers who accessed employees' user names and password data in a breach that marked the third intrusion in as many years, the paper reported.

Security personnel still don't know the full extent of the loss, an article published Wednesday said. The intrusion was discovered by outside security consultant Mandiant, which reported it to Washington Post officials Wednesday. Compromised data includes employees' user names and passwords that were "stored in encrypted form," which typically means as a cryptographic hash. Post officials, working under the assumption that a fair percentage of hashed passwords can be cracked, planned to direct all employees to change their passwords.

There's no evidence yet that subscriber information such as credit card data or home addresses was accessed. There was also no immediate sign that hackers had accessed the paper's publishing system, employee e-mail databases, or sensitive personal information belonging to workers. Wednesday's article cited a Washington Post official as saying investigators believe the intrusion lasted at most a few days.

Large international news organizations have become a common hacking target in recent years. Early this year, the New York Times said China-based attackers persistently intruded on its internal servers for four months straight. In the process, they obtained password data for all of its reporters and other employees. The Wall Street Journal suffered its own intrusion around the same time. And in February, KrebsonSecurity reporter Brian Krebs uncovered an attack on Washington Post systems, also by suspected hackers from China. The NYT, Washington Post, Associated Press, and other news organizations have also been successfully targeted in other hacks, including a string of them by a group calling itself the Syrian Electronic Army.

The more recent attack on The Washington Post began with an intrusion into a server used by the paper's foreign staff and eventually spread to other company servers.



SOURCE: ArsTechnica
[Continue reading...]

Google, Microsoft, Apple & more demand government surveillance reform

- 0 comments
Google, Apple, Microsoft, Facebook, and other big names in tech have joined forces to protest government surveillance worldwide, calling for “Global Government Surveillance Reform” to better balance keeping citizens safe while also preserving their privacy. The group, which also includes AOL, LinkedIn, Twitter, and Yahoo, sets out five principles for transparency, oversight, accountability, and respect, penning a collective letter to President Obama and the US Congress in which they allege the balance of power has tipped too far away from the people and too much toward the stat


According to the eight firms, while they recognize that governments have a responsibility to protect citizens, they nonetheless believe that it’s time to rework the current laws which no longer address the digital age. Instead, they must be “rule-bound, narrowly tailored, transparent, and subject to oversight” in order to permit privacy and free expression.

The five guiding principles the companies set out echo and expand on those concepts. For instance, governments must be constrained in what user-information they collect, it’s argued, with “sensible limitations” on how much disclosure they can force out of service providers. Google and others have been vocal in recent demands for permission to reveal how many national security requests they receive each year.

Bulk data collection – potentially including the sort of huge location tracking the NSA is believed to be undertaking – is also name-checked, as is the need for a “clear legal framework” in which the right to protest disclosure is supported. Such laws should be set up in such a way that “the courts are accountable to an informed citizenry” it’s suggested.

Meanwhile, there’s also a request that governments be more open-minded about where data is stored – not requiring it to be within a country’s borders, for instance – and for countries to work together on better, more transparent sharing of information between each other.

Whether the pleading for reform will fall on deaf ears remains to be seen, but it’s clear that none of the key tech industry players is keen to go quietly along with increasing surveillance and government intrusion. Google has accelerated plans to encrypt all Drive data as a result, while Microsoft is similarly strengthening its security. The Obama government is yet to comment on the open letter.




SOURCE: slashgear
[Continue reading...]

Google Glass vulnerable to malicious wireless networks, says Symantec

- 0 comments
Earlier this week, an exploit surfaced by way of Lookout Mobile Security that would allow Google Glass to be controlled by a hacker using malicious QR codes. This was quickly – and quietly – patched, but another threat remains, one that extends beyond Glass and could facilitate data theft: a WiFi-based vulnerability that utilizes a man-in-the-middle attack to get the device to connect to a malicious wireless network.

This information comes from Symantec, who refers to a device called a Wi-Fi Pineapple, which functions by impersonating a wireless network that a device – such as Glass – has already connected to in the past. It does this by using the network’s SSID. So, for example, if Glass had previously connected to a network called My Awesome WiFI, the device could impersonate that SSID while instead broadcasting a malicious network.

This takes advantage of a feature that most devices have, whereby they remember a network they have previously connected to and stay on the outlook for it. The result of this is convenient – the device will automatically connect to a recognized network, removing the hassle. It is also where the vulnerability lies, and users should be aware of it, says Symantec.

Of course, this problem could affect any device that does this, but Glass is said to make avoiding this problem more difficult due to the way its interface works, sans any input devices like a keyboard. Glass will find a network it recognizes and connect to it, and the user may never notice anything off about it.

Although the problem is known, figuring out a solution that works to avoid this kind of potential attack is more complicated, with Symantec saying that things like utilizing MAC addresses are still vulnerable. For now, users are advised that the “practicable solution” is to act like any network can be malicious, and to either utilize encryption or a VPN.
[Continue reading...]
 
Copyright © . New IT News - Posts · Comments
Theme Template by SZ.D · Powered by SZ