Contact Form

Name

Email *

Message *

Showing posts with label Electronic Frontier Foundation. Show all posts
Showing posts with label Electronic Frontier Foundation. Show all posts

Tuesday, August 5, 2014

NSA Spying Brings Together Eclectic Group.

Documentary By Acclaimed Filmmaker Explains How Unlikely Alliances Formed To Battle NSA

August 5, 2014 by  
 19 5
 
 0 61

On June 27, The Electronic Frontier Foundation, Greenpeace and the Tenth Amendment Center joined forces to fly a 135-foot-long airship bearing a downturned arrow and the words “Illegal Spying Below” over the National Security Agency’s $1.2-billion data center in Bluffdale, Utah.
The action was an attempt to draw attention to government spying andStandAgainstSpying.org, a group trying to stop it. According to organizers, the airship protest was a success.
“More than 30 articles were written about the airship, and those articles were collectively shared more than 51,000 times over social media within 72 hours,” EFF reported.
Documentarian Brian Knappenberger (The Internet’s Own Boy), explained that the large data center jutting out of the small Utah community made it a perfect target for the protest.
“While it is only one of several data centers, for many people the Bluffdale facility has become a symbol out-of-control, unconstitutional, dragnet surveillance, as well as a threat to the environment,” he said. “I thought it was important to document this audacious attempt to raise awareness of this secretive facility and pressure Congress to rein in the NSA.”
The effort, according to organizers, should serve to illustrate how Americans, no matter their political differences, should join forces to protect their privacy.
“This video shows how a common threat to the freedom of association drew our three organizations together, despite very different missions,” EFF Activism Director Rainey Reitman said. “Now it’s time for Congress to build a diverse coalition to pass meaningful reform. We launched an airship, they need to land a bill on the president’s desk.”

Monday, July 14, 2014

NSA Spying Includes Pictures Of Ordinary People Doing Very Ordinary Things. Do You Still Think It Is Harmless?

NSA Spying: Now It’s Personal

July 14, 2014 by  
 9 8
 
 1 44

This article first appeared July 11 on the website of the Electronic Frontier Foundation.
By Eva Galperin and Nadia Kayyali
Imagine that you watched a police officer in your neighborhood stop ten completely ordinary people every day just to take a look inside their vehicle or backpack. Now imagine that nine of those people are never even accused of a crime. They just happened to be in the wrong place at the wrong time. Even the most law-abiding person would eventually protest this treatment. In fact—they have.
Now replace police officers with the NSA. The scenario above is what the NSA is doing with our communications, under cover of its twisted interpretation of Section 702 of the FISA Amendments Act. The Washington Post has revealed that “Nine of 10 account holders found in a large cache of intercepted conversations, which former NSA contractor Edward Snowden provided in full to The Post, were not the intended surveillance targets.” Additionally, “[n]early half of the surveillance files, a strikingly high proportion, contained names, e-mail addresses or other details that the NSA marked as belonging to U.S. citizens or residents.”
The thousands of pages of documents that provide that basis for the article are not raw content. Rather, as Barton Gellman, one of the authors of the article states in a follow uppublished several days later states: “Everything in the sample we analyzed had been evaluated by NSA analysts in Hawaii, pulled from the agency’s central repositories and minimized by hand after automated efforts to screen out U.S. identities.”
What that means is that if you’re on the Internet, you’re in the NSA’s neighborhood—whether you are in the U.S. or not. And like those who protest unjust policies like stop and frisk in their cities, you should be protesting this treatment.
This revelation is significant because it proves the point privacy and civil liberties advocates have been making for years: NSA surveillance is not narrowly targeted. EFF’s legal fight against the NSA’s warrantless mass surveillance program has been ongoing since 2006, butThe Washington Post’s statistics about 160,000 intercepts they have analyzed from the Snowden files indicate that even what the NSA calls “targeted” surveillance is far from narrow in scope.  In fact, it is so bloated that we should all be questioning its necessity and efficacy at this point. Taken hand in hand with The Intercept’s article outlining the targeting of five civil rights and political leaders from the Muslim-American community, our outrage should be palpable.
What’s more, the report comes on the heels of a debate specifically about Section 702 that has been brewing in Congress for months, as civil liberties champions like Senator Ron Wyden and Representative Zoe Lofgren question and work to address how the NSA uses this authority. This revelation should make it clear to the Senate when it considers the USA FREEDOM Act: Section 702 needs to be reformed. Cosmetic changes to NSA spying, or even substantive changes to Section 215 bulk telephone records collection, are insufficient. Unbridled, unconstitutional collection of the contents of communications needs to end.
The Washington Post article is based on a comprehensive review of thousands of pages of documents. In fact, as the article points out: “No government oversight body, including the Justice Department, the Foreign Intelligence Surveillance Court, intelligence committees in Congress or the president’s Privacy and Civil Liberties Oversight Board, has delved into a comparably large sample of what the NSA actually collects.” What’s more, these are documents that government officials have repeatedly insisted Edward Snowden would never have been able to access.
Regardless of the government’s denials, Snowden did have these documents, and now we know at least some of what they contained. So does Congress. So there’s no excuse anymore for the type of maneuvering that led to the gutting of USA FREEDOM in the House.  More importantly, there’s no excuse for the Senate to ignore Section 702 when it considers USA FREEDOM.
Real NSA reform from Congress will, among other things, shut the backdoor that allows the NSA to access American’s communications. It will also end collection of communications “about” a target.
Of course, none of this solves the problem of how NSA surveillance affects non-U.S. persons. One of the shocking things about The Washington Post’s article is its description of the communications intercepted:
Scores of pictures show infants and toddlers in bathtubs, on swings, sprawled on their backs and kissed by their mothers. In some photos, men show off their physiques. In others, women model lingerie, leaning suggestively into a webcam or striking risque poses in shorts and bikini tops.
We are no longer talking about statistics. We are talking about real people going about their daily lives. It is not surprising to learn that in the course of its investigations, the NSA gathers up a considerable number of communications that prove to be insignificant, irrelevant, or (as is the case with communications between US persons) outside the scope of their work. What is shocking is that the NSA keeps this enormous trove of personal data about people it should not be watching in the first place. It appears that the unspoken coda to General Alexander’s “collect it all” motto is “and never throw it away.”
The bottom line is this: The Internet is a global neighborhood. We shouldn’t feel unsafe there. But the NSA doesn’t seem to care.
The good news is, we can do something. Take action now. Go tohttps://www.standagainstspying.org and see how your elected representative stacks up when it comes to reforming the NSA, tweet at them, and send a letter to President Obama urging him to use his executive authority to reform the NSA now. You can also take action by contacting lawmakers here. If you are overseas, you can sign the letter to President Obama. You can also endorse the Necessary and Proportionate principles. Take back the Internet.

Tuesday, July 8, 2014

When Meetings Are Held In Secret, Can Any Good Come Out Of Them?

International Treaty Negotiations Go Further Underground with Unprecedented Secrecy Around Meetings in Canada

July 8, 2014 by  
 34 25
 
 1 93

This post, written by EFF Global Policy Analyst Maria Sutton, was originally published on the foundation’s website July 8.
EFF is in Ottawa this week for the Trans-Pacific Partnership (TPP) negotiations, to influence the course of discussions over regressive digital policy provisions in this trade agreement that could lead to an increasingly restrictive Internet. But this round is different from the others—the secrecy around the talks is wholly unprecedented. The Canadian trade ministry, who is hosting this round of talks, has likely heightened the confidentiality due to the mass public opposition that is growing against this undemocratic, corporate-driven trade deal.
The trade offices from the 12 countries negotiating this deal no longer pre-announce details about the time and location of these negotiations. They don’t bother releasing official statements about the negotiations because they no longer call these “negotiation rounds” but “officials’ meetings.” But the seeming informality of these talks is misleading—negotiators are going to these so-called meetings to secretly pull together a deal. As far as we know, they’re still discussing whether they could expand the international norm of copyright terms to make it even longer. They are negotiating provisions that could lead to users getting censored and filtered over copyright, with no judicial oversight or consideration for fair use. And trade delegates are deliberating how much of a crime they should make it if users break the DRM on their devices and content, even if users don’t know it’s illegal and the content they’re unlocking isn’t even restricted by copyright in the first place.
So for this negotiation, we had to rely on rumors and press reports to know when and where it was even happening. At first, there were confirmed reports that the next TPP meeting would take place at a certain luxury hotel in downtown Vancouver. So civil society began to mobilize, planning events in the area to engage users and members of the public about the dangers of TPP. Then seemingly out of the blue, the entire negotiating round was moved across the country to Ottawa. There’s no way to confirm whether this was a deliberate misdirection, but either way it felt very fishy.
Already given this level of secrecy, it goes without saying that there will be no room for members of civil society or the public to engage directly with TPP negotiators. Towards the beginning of TPP talks, we were given 15 minutes to present to stakeholders, in addition to a stakeholder event that allowed us to hang around a big room to meet and pass information to negotiators who walked by. Then it was cut down to ten minutes (after we made some noise that it was going to be cut down to a mere eight minutes). In the following rounds, the stakeholder event was completely removed from the schedules of the official rounds. These didn’t provide sufficient time to convey to negotiators about the major threats we saw in this agreement, so those events already seemed to be a superficial nod to public participation. But now, they don’t even pretend to give us their ear.
Of course, corporate lobbyists continue to have easy access to the text. Advisors to major content industries can comment and read the text of the agreement on their private computers. But those of us who represent the public interest are left to chase down negotiators down the halls of hotels to let our concerns be heard and known to them.
As we watch TPP crawl its way towards getting finalized, signed, and eventually taint our laws with its one-sided corporate agenda, we need to continue to remember this fact: laws made in secret, with no public oversight or input, are illegitimate. That is not how law is made in democracies. If we’re to defend the fundamental democratic rule that law is based on transparent, popular consensus, we need to fight back against an agreement that engages in such a secretive, corporate-captured process.
Additional Resources:

Friday, July 4, 2014

Want To Know Where You Have Been, Check Your Phone. Problem: Everyone Else Can Also!

EFF: Is Your Android Device Telling the World Where You’ve Been?

July 4, 2014 by  
 14 3
 
 2 80
EFF: Is Your Android Device Telling the World Where You’ve Been?
THINKSTOCK

This post, written by technology projects director Peter Eckersley and staff technologist Jeremy Gillula, was originally published on the EFF website.
Do you own an Android device? Is it less than three years old? If so, then when your phone’s screen is off and it’s not connected to a Wi-Fi network, there’s a high risk that it is broadcasting your location history to anyone within Wi-Fi range who wants to listen.
This location history comes in the form of the names of wireless networks your phone has previously connected to. These frequently identify places you’ve been, including homes (“Tom’s Wi-Fi”), workplaces (“Company XYZ office net”), churches and political offices (“County Party HQ”), small businesses (“Toulouse Lautrec’s house of ill-repute”), and travel destinations (“Tehran Airport wifi”). This data is arguably more dangerous than that leaked in previous location data scandals because it clearly denotes in human language places that you’ve spent enough time to use the Wi-Fi. Normally, eavesdroppers would need to spend some effort extracting this sort of information from the latititude/longitude history typically discussed in location privacy analysis. But even when networks seem less identifiable, there are ways to look them up.
The Electronic Frontier Foundation briefly mentioned this problem during our recent post about Apple deciding to randomize MAC addresses in iOS 8. As EFF pointed out there, Wi-Fi devices that are not actively connected to a network can send out messages that contain the names of networks they’ve joined in the past in an effort to speed up the connection process. But after writing that post, EFF became curious just how many phones actually exhibited that behavior, and if so, how much information they leaked. To our dismay, we discovered thatmany of the modern Android phones EFF tested leaked the names of the networks stored in their settings (up to a limit of 15). And when EFF looked at these network lists, we realized that they were, in fact, dangerously precise location histories.
Aside from Android, some other platforms also suffer from this problem and will need to be fixed, although for various reasons, Android devices appear to pose the greatest privacy risk at the moment.
In Android EFF traced this behavior to a feature introduced in Honeycomb (Android 3.1) called Preferred Network Offload (PNO). PNO is supposed to allow phones and tablets to establish and maintain Wi-Fi connections even when they’re in low-power mode (i.e. when the screen is turned off). The goal is to extend battery life and reduce mobile data usage, since Wi-Fi uses less power than cellular data. But for some reason, even though none of the Android phones EFF tested broadcast the names of networks they knew about when their screens were on, many of the phones running Honeycomb or later (and even one running Gingerbread) broadcast the names of networks they knew about when their screens were turned off.

Response From Google

When EFF brought this issue to Google’s attention, it responded:
We take the security of our users’ location data very seriously and we’re always happy to be made aware of potential issues ahead of time. Since changes to this behavior would potentially affect user connectivity to hidden access points, we are still investigating what changes are appropriate for a future release.
Additionally, yesterday a Google employee submitted a patch to wpa_supplicant that fixes this issue. While we are glad this problem is being addressed so quickly, it will still be some time before that fix gets integrated into the downstream Android code. And even then, Android fragmentation and the broken update process for non-Google Android devices could delay or even prevent many users from receiving the fix. (We hope Google can make progress on this problem, too.)

Protective Steps You Can Take Today

With that said, a workaround is available (for most devices) for users who want to protect their privacy right now: Go into your phone’s “Advanced Wi-Fi” settings and set the “Keep Wi-Fi on during sleep” option to “Never.” Unfortunately, this will cause a moderate increase in data usage and power consumption — something users shouldn’t have to do in order to keep their phone from telling everyone everywhere they’ve been.
Unfortunately, on at least one device we tested — a Motorola Droid 4 running Android 4.1.2 — even this wasn’t sufficient. On the Droid 4, and perhaps on other phones, the only practical way to prevent the phone from leaking location is to manually forget the networks you don’t want broadcast, or disable Wi-Fi entirely whenever you aren’t actively connecting to a known Wi-Fi network. You can also find apps that will do this automatically for you.
Location history is extremely sensitive information. We urge Google to ship their fix as soon as possible, and other Android distributors to offer prompt updates containing it.

Thursday, June 12, 2014

Is FBI Director James Comey Incompetent Or Just Another Obama Stooge Liar? His Testimony Seems To Indicate Both!

FBI Director Doesn’t Think Agency Will Spy On Americans, Fails To Mention It Already Is

June 12, 2014 by 
 13 4

 0 38
FBI Director Doesn’t Think Agency Will Spy On Americans, Fails To Mention It Already Is
THINKSTOCK

FBI Director James Comey insisted during a House Judiciary Committee Hearing Wednesday that his agency doesn’t — and will not — use the government’s sophisticated facial recognition technology to keep tabs on innocent civilians. But there’s probably more to the story than he let on.
Earlier this year, a Freedom of Information Act request filed by the Electronic Frontier Foundation revealed that the FBI plans to database more than 52 million pictures in its Next Generation Identification facial recognition program by next year.
“One of our biggest concerns about NGI has been the fact that it will include non-criminal as well as criminal face images,” Jennifer Lynch, a senior staff attorney at the EFF said in April. “We now know that FBI projects that by 2015, the database will include 4.3 million images taken for non-criminal purposes.”
According to Lynch, the agency could include in its database photos of Americans who applied for jobs or had non-criminal interactions with government that have traditionally required fingerprinting and background checks.
“Currently, if you apply for any type of job that requires fingerprinting or a background check, your prints are sent to and stored by the FBI in its civil print database. However, the FBI has never before collected a photograph along with those prints,” Lynch continued. “This is changing with NGI. Now an employer could require you to provide a ‘mug shot’ photo along with your fingerprints. If that’s the case, then the FBI will store both your face print and your fingerprints along with your biographic data.”
During yesterday’s hearing, Comey told lawmakers that the EFF’s concerns were unfounded, saying that the database will only contain criminal mug shots.
Pressed by Representative Zoe Lofgren, a Democrat who represents a district squarely situated in California’s Silicon Valley, Comey added that some non-criminals might be included if they apply for certain jobs or licenses.
“I think there is some circumstances in which when states send us records, they’ll send us pictures of people who are getting special driving licenses to transport children or explosive materials or something — but as I understand it those are not part of the searchable Next Generation Identification database,” he said.
The FBI director said that he even asked for an explanation from his underlings following the release of the EFF report when Lofgren cited the numbers put out by the electronic privacy organization.
“I saw some of the same media,” he said, “and that’s what led me to ask my folks: So what’s the deal with this? And the explanation to me was the pilot is mug shots, because those are repeatable, we can count on the quality of them, and they’re tied to criminal conduct, clearly, and so there was not a plan and there is not at present where we are going to add other non-mug shot photos. But again, if I’ve got that wrong I’ll fix it with you.”
Comey also said that he wasn’t sure if the 52 million figure is accurate.
“It’s my understanding that the contractor who is building this Next Generation database, a company called MorphoTrust, also built the State Department facial recognition database, which contains 244 million faces,” Lofgren pressed further. “Will your Next Generation Identification system be capable of importing the State Department records or searching the State Department records?”
Comey said that he didn’t know — but the FBI director did insist that the agency would not be importing photos from areas such as State driver license databases.
The FBI director’s light-on-facts testimony comes just weeks after The New York Timespublished a piece detailing how the National Security Agency scoops up and stores as many as 55,000 images that sleuths in the agency consider “facial recognition quality” from the communications they intercept each day.

It is not clear how many people around the world, and how many Americans, might have been caught up in the effort. Neither federal privacy laws nor the nation’s surveillance laws provide specific protections for facial images. Given the N.S.A.’s foreign intelligence mission, much of the imagery would involve people overseas whose data was scooped up through cable taps, Internet hubs and satellite transmissions.

And despite halfhearted assurances from top officials that a similar strategy is being implemented in domestic intelligence and law enforcement, the legal gray area in how Federal privacy laws treat new technology like facial recognition is a big worry for privacy advocates. In addition, the FBI is not very far removed from the NSA’s activities thanks to the agency’s obscure Data Intercept Technology Unit.
When the media and members of Congress say the NSA spies on Americans, what they really mean is that the FBI helps the NSA do it, providing a technical and legal infrastructure that permits the NSA, which by law collects foreign intelligence, to operate on U.S. soil. It’s the FBI, a domestic U.S. law enforcement agency, that collects digital information from at least nine American technology companies as part of the NSA’s Prism system. It was the FBI that petitioned the Foreign Intelligence Surveillance Court to order Verizon Business Network Services, one of the United States’ biggest telecom carriers for corporations, to hand over the call records of millions of its customers to the NSA.

In essence, Comey’s agency — acting as a proxy for the NSA — is already doing much of what he claims he doesn’t think his agency plans to do.