Contact Form

Name

Email *

Message *

Showing posts with label EFF. Show all posts
Showing posts with label EFF. Show all posts

Friday, July 4, 2014

Want To Know Where You Have Been, Check Your Phone. Problem: Everyone Else Can Also!

EFF: Is Your Android Device Telling the World Where You’ve Been?

July 4, 2014 by  
 14 3
 
 2 80
EFF: Is Your Android Device Telling the World Where You’ve Been?
THINKSTOCK

This post, written by technology projects director Peter Eckersley and staff technologist Jeremy Gillula, was originally published on the EFF website.
Do you own an Android device? Is it less than three years old? If so, then when your phone’s screen is off and it’s not connected to a Wi-Fi network, there’s a high risk that it is broadcasting your location history to anyone within Wi-Fi range who wants to listen.
This location history comes in the form of the names of wireless networks your phone has previously connected to. These frequently identify places you’ve been, including homes (“Tom’s Wi-Fi”), workplaces (“Company XYZ office net”), churches and political offices (“County Party HQ”), small businesses (“Toulouse Lautrec’s house of ill-repute”), and travel destinations (“Tehran Airport wifi”). This data is arguably more dangerous than that leaked in previous location data scandals because it clearly denotes in human language places that you’ve spent enough time to use the Wi-Fi. Normally, eavesdroppers would need to spend some effort extracting this sort of information from the latititude/longitude history typically discussed in location privacy analysis. But even when networks seem less identifiable, there are ways to look them up.
The Electronic Frontier Foundation briefly mentioned this problem during our recent post about Apple deciding to randomize MAC addresses in iOS 8. As EFF pointed out there, Wi-Fi devices that are not actively connected to a network can send out messages that contain the names of networks they’ve joined in the past in an effort to speed up the connection process. But after writing that post, EFF became curious just how many phones actually exhibited that behavior, and if so, how much information they leaked. To our dismay, we discovered thatmany of the modern Android phones EFF tested leaked the names of the networks stored in their settings (up to a limit of 15). And when EFF looked at these network lists, we realized that they were, in fact, dangerously precise location histories.
Aside from Android, some other platforms also suffer from this problem and will need to be fixed, although for various reasons, Android devices appear to pose the greatest privacy risk at the moment.
In Android EFF traced this behavior to a feature introduced in Honeycomb (Android 3.1) called Preferred Network Offload (PNO). PNO is supposed to allow phones and tablets to establish and maintain Wi-Fi connections even when they’re in low-power mode (i.e. when the screen is turned off). The goal is to extend battery life and reduce mobile data usage, since Wi-Fi uses less power than cellular data. But for some reason, even though none of the Android phones EFF tested broadcast the names of networks they knew about when their screens were on, many of the phones running Honeycomb or later (and even one running Gingerbread) broadcast the names of networks they knew about when their screens were turned off.

Response From Google

When EFF brought this issue to Google’s attention, it responded:
We take the security of our users’ location data very seriously and we’re always happy to be made aware of potential issues ahead of time. Since changes to this behavior would potentially affect user connectivity to hidden access points, we are still investigating what changes are appropriate for a future release.
Additionally, yesterday a Google employee submitted a patch to wpa_supplicant that fixes this issue. While we are glad this problem is being addressed so quickly, it will still be some time before that fix gets integrated into the downstream Android code. And even then, Android fragmentation and the broken update process for non-Google Android devices could delay or even prevent many users from receiving the fix. (We hope Google can make progress on this problem, too.)

Protective Steps You Can Take Today

With that said, a workaround is available (for most devices) for users who want to protect their privacy right now: Go into your phone’s “Advanced Wi-Fi” settings and set the “Keep Wi-Fi on during sleep” option to “Never.” Unfortunately, this will cause a moderate increase in data usage and power consumption — something users shouldn’t have to do in order to keep their phone from telling everyone everywhere they’ve been.
Unfortunately, on at least one device we tested — a Motorola Droid 4 running Android 4.1.2 — even this wasn’t sufficient. On the Droid 4, and perhaps on other phones, the only practical way to prevent the phone from leaking location is to manually forget the networks you don’t want broadcast, or disable Wi-Fi entirely whenever you aren’t actively connecting to a known Wi-Fi network. You can also find apps that will do this automatically for you.
Location history is extremely sensitive information. We urge Google to ship their fix as soon as possible, and other Android distributors to offer prompt updates containing it.

Friday, April 25, 2014

Digital Freedom Growing On Colleges

EFF: Campus Activism Against NSA Spying is Growing Fast

April 25, 2014 by  
 10 4
 
 0 22

This piece, written by Electronic Frontier Foundation activist April Glaser, originally appeared on the foundation’s website on April 25.
The Electronic Frontier Foundation has been on the road, traveling to cities and towns across the country to bring our message of digital rights and reform to community and student groups.
And while we had the tremendous opportunity to talk about our work and our two lawsuits against the National Security Agency, the best part of the trip was learning about all of theinspiring and transformative activism happening everyday on the local level to combat government surveillance and defend our digital rights.
We met students and professors in Eugene, Ore., who held a campus-wide digital rights event at the University of Oregon. There, students had the opportunity to unpack their campus privacy policy, download and learn freedom-enhancing software, and explore their library’s open access initiative.
We traveled to Cambridge, Mass., where we met local activists and students ready to join the fight against draconian computer crime laws and raise awareness about the effects of mass surveillance on student innovation and academic freedom. In one particularly inspiring meeting with MIT’s Student Information Processing Board, we talked about how student innovators have long felt rudderless in the face of poorly written and outdated computer crime laws.
Most recently, a student was issued a subpoena for a project developed with fellow MIT classmates at a local hackathon. The students’ project, called TidBit, demonstrates how a client’s computer can mine for Bitcoin as an alternative to website advertising. The project was designed for a hackathon (where it won an award for innovation) and was never actually implemented, but instead explicitly marked as a proof of concept. Yet the State of New Jersey issued a subpoena trying to get info about the project and suggesting the TidBit developers had violated the law. EFF is helping the students fight back by moving to quash the subpoena. The TidBit case is the latest in a string of student confrontation with computer crime laws at MIT over the years.
We remember how Aaron Swartz was charged under the grossly unfair and outdated Computer Fraud and Abuse Act. And we remember when the Massachusetts Bay Transit Authority ordered that MIT students cancel their scheduled presentation at DEFCON about vulnerabilities that they found in Boston’s transit fare payment system, violating their 1st Amendment right to discuss their important research. The facts are clear: Student innovation is chilled by broken computer crime laws, and reform is sorely needed.
While we were in Cambridge, we participated in LibrePlanet, the annual Free Software Foundation conference. And after the conference local activists, technologists and free software enthusiasts joined us for a Free Software Foundation/EFF Speakeasy. We had the opportunity to talk about how the Free Software Foundation is one of the 22 plaintiffs in ourFirst Unitarian Church of Los Angeles  v. NSA case, as well as what technologists can do to combat mass surveillance.
EFF also stopped in New York City to meet with students from the New School and New York University to talk about what students can do on campus to oppose NSA surveillance. And we were delighted to co-host a Students’ Speakeasy, where we chatted about ways to get active on campus with the Student Net Alliance, a growing network of people involved in campus communities that support sound Internet law and policy. Whether it’s writing a letter about how mass surveillance chills academic freedom, learning, and the need to research and discuss controversial topics; holding regular campus cryptoparties; or petitioning for better open access policies on campus, there are plenty of things that students can do join the fight to protect our digital rights.
“The Internet was born on university campuses, and universities have always been at the center of critical fights to keep the Internet free and open,” said Alec Foster, founder of Student Net Alliance. “As students, we believe in advancing policy and technology that support the free and open flow of information, and ensure our private communications are equally protected online and offline.”
It’s been a busy month! Just last week we visited Iowa, where we collaborated with the student-run Iowa State University Digital Freedom Group to put together a giant event for the campus-wide First Amendment week. More than 250 people showed up to hear about EFF’s litigation against the NSA and learn about reforms in Congress that aim to rein the NSA back within the bounds of the Constitution.
When the ISU Digital Freedom Group was trying to form on campus last year, they met serious resistance from the school’s administration who wouldn’t give them the green lightbecause they did not want ISU students to advocate for or participate in the “secrecy network” Tor and would not permit the student group to use any “free software designed to enable online anonymity.”
But the students had not proposed that a Tor node be established on campus. Rather, they simply asked that they be able to provide a forum to “discuss, learn and practice techniques to anonymize and protect digital communication.” EFF wrote an open letter to university administrations across the country about the importance of student groups like the Digital Freedom Group that aim to discuss and learn about methods for secure and private use of the Internet.
After our tremendously successful event, the ISU Digital Student Group hosted their first cryptoparty, where campus based technologists taught about important Internet privacy tools like GPG email encryption, Tor, and Off-the-Record instant messaging. We all had a wonderful time in Ames and look forward to watching the group grow.
At EFF we are thrilled to meet more activists across the country working on the front lines to defend our digital rights. And this fight is now more important than ever. Snowden’s revelations have brought conversations about government surveillance and the right to privacy into the spotlight. Now is the time to organize for real reform. Join us.

Monday, December 9, 2013

The Latest Information On Whom Cares About Your Data And Who Is Protecting You.

EFF’s Updated List Of Who Protects Your Online Information

December 9, 2013 by  
 9 2
 
 0 57

This article, compiled by senior staff attorney Kurt Opsahl, staff attorney Nate Cardozo and activist Parker Higgins, was originally published by the Electronic Frontier Foundation on Dec. 5.
The Electronic Frontier Foundation has asked the companies in its Who Has Your Back Program what they are doing to bolster encryption in light of the National Security Agency’s unlawful surveillance of your communications. EFF is pleased to see that four companies — Dropbox, Google, SpiderOak and Sonic.net — are implementing five out of five of EFF’s best practices for encryption. In addition, EFF appreciates that Yahoo! just announced several measures it plans to take to increase encryption, including the very critical encryption of data center links, and that Twitter has confirmed that it has encryption of data center links in progress. See the infographic.
By adopting these practices, described below, these service providers have taken a critical step toward protecting their users from warrantless seizure of their information off of fiber-optic cables. By enabling encryption across their networks, service providers can make backdoor surveillance more challenging, requiring the government to go to courts and use legal process. While Lavabit’s travails have shown how difficult that can be for service providers, at least there was the opportunity to fight back in court.
While not every company in EFF’s survey has implemented every recommendation, each step taken helps; and EFF appreciates those who have worked to strengthen their security. EFF hopes that every online service provider adopts these best practices and continues to work to protect their networks and their users.

Crypto Survey Results

UPDATE, Nov. 20: Facebook and Tumblr have provided further information to supplement the Encrypt the Web Report. EFF is pleased to report that Tumblr is planning to upgrade its Web connections to HTTPS this year and implement HSTS by 2014, and Facebook is working on encrypting data center links and implementing STARTTLS.
UPDATE, Nov. 22: Google has provided further information to supplement the report on its use of HSTS. See the updated chart below and the notes for more information.
UPDATE, Dec. 5: Microsoft has provided further information, announcing a plan to expand encryption across all its services, including encrypting links between data center and implementing forward secrecy by the end of 2014.

crypto-survey-graphic-20131205

Why Crypto Is So Important

The NSA’s MUSCULAR program, which tapped into the fiber-optic lines connecting the data centers of Internet giants like Google and Yahoo, exposed the tremendous vulnerabilities companies can face when up against as powerful an agency as the NSA. Bypassing the companies’ legal departments, the program grabbed extralegal access to your communications, without even the courtesy of an order from the secret rubber-stamp Foreign Intelligence Surveillance Court. The program is not right, and it’s not just.
With that in mind, EFF has asked service providers to implement strong encryption. EFF would like to see encryption on every step of the way for a communication on its way to, or within, a service provider’s systems.
For starters, EFF has asked companies to encrypt their websites with Hypertext Transfer Protocol Secure (HTTPS) by default. This means that when a user connects to a website, it will automatically use a channel that encrypts the communications from the user’s computer to the website.
EFF has also asked them to flag all authentication cookies as secure. This means cookie communications are limited to encrypted transmission, which directs Web browsers to use these cookies only through an encrypted connection. That stops network operators from stealing (or even logging) users’ identities by sniffing authentication cookies going over insecure connections.
To ensure that the communication remains secure, EFF has asked companies to enable HTTP Strict Transport Security (HSTS). HSTS essentially insists on using secure communications, preventing certain attacks where a network pretends that the site has asked to communicate insecurely.
All of these technologies are now industry-standard best practices. While they encrypt the communications from the end user to the server and back, the MUSCULAR revelations have shown this is not enough. Accordingly, EFF has asked service providers to encrypt communications between company cloud servers and data centers. Anytime a user’s data transits a network, it should be strongly encrypted, in case an attacker has access to the physical data links or has compromised the network equipment.
In addition, we have asked for email service providers to implement STARTTLS for email transfer. STARTTLS is an opportunistic encryption system, which encrypts communications between email servers that use the Simple Mail Transfer Protocol (SMTP) standard. When a user emails someone on a different provider (say, a Hotmail user writing to a Gmail user), the mail message will have to be delivered over the Internet. If both email servers understand STARTTLS, then the communications will be encrypted in transit. If only Gmail does but Hotmail does not (the current situation), they will be in the clear and exposed to eavesdropping, so it’s critical to get as many email service providers as possible to implement the system.
Finally, EFF has asked companies to use forward secrecy for their encryption keys. Forward secrecy, sometimes called “perfect forward secrecy,” is designed to protect previously encrypted communications, even if one of the service providers’ keys is later compromised. Without forward secrecy, an attacker who learns a service provider’s secret key can use it to go back and read previously incomprehensible encrypted communications — perhaps ones that were recorded months or years in the past.
  • 1. The HSTS domains are wallet.google.com; checkout.google.com; chrome.google.com; docs.google.com; sites.google.com; spreadsheets.google.com; appengine.google.com; encrypted.google.com; accounts.google.com; profiles.google.com; mail.google.com; talkgadget.google.com; talk.google.com; hostedtalkgadget.google.com; plus.google.com; plus.sandbox.google.com; script.google.com; history.google.com; security.google.com; goto.google.com; market.android.com; ssl.google-analytics.com; drive.google.com; googleplex.com; groups.google.com; apis.google.com; chromiumcodereview.appspot.com; chrome-devtools-frontend.appspot.com; codereview.appspot.com; codereview.chromium.org; code.google.com; dl.google.com; translate.googleapis.com; oraprodsso.corp.google.com; oraprodmv.corp.google.com; gmail.com; googlemail.com; www.gmail.com; www.googlemail.com; google-analytics.com; and googlegroups.com.