Contact Form

Name

Email *

Message *

Showing posts with label chilling effect of nsa spying. Show all posts
Showing posts with label chilling effect of nsa spying. Show all posts

Wednesday, February 26, 2014

Ways To Stop NSA Spying

EFF Tech Experts: Tech Companies Must Defend Against Surveillance

February 26, 2014 by  
 3 4
 
 0 16

This open letter to tech companies was originally published by the Electronic Frontier Foundation. It includes 10 principles to protect users from National Security Agency sabotage.
In the past nine months, our trust in technology companies has been badly shaken. Today, in collaboration with prominent security researchers and technologists, EFF presents an open letter to technology companies, urging them to protect users from NSA backdoors and earn back the trust that has been lost.
From the Snowden revelations emerge stories of collusion between government spy agencies and the companies whose services are integral to our everyday lives. There have been disturbing allegations published by Reuters indicating that RSA, an influential information security firm, accepted a $10 million contract from NSA that included, among other items, an agreement to use what we now know to be an intentionally compromised random number generator as the default for its BSAFE cryptographic library.
A future where we cannot trust the very technologies meant to secure our communications is fundamentally unsustainable. It’s time for technology companies to start helping users regain trust, with transparency and active opposition to illegal surveillance. Implementing the requisite changes in technical infrastructure and business practices may have short-term costs; however, the long-term cost of keeping users in perpetual fear of NSA sabotage is far greater.
How to Protect Your Users from NSA Backdoors: An Open Letter to Technology Companies
As security researchers, technologists, and digital rights advocates, we are deeply concerned about collaboration between government agencies and technology companies in undermining users’ security. Among other examples, we are alarmed by recent allegations that RSA, Inc. accepted $10 million from NSA to keep a compromised algorithm in the default setting of a security product long after its faults were revealed. We believe that covert collusion with spy agencies poses a grave threat to users and must be mitigated with commitment to the following best practices to protect users from illegal surveillance:
  1. Provide public access to source code whenever possible, and adopt a reproducible build process so that others can verify the integrity of pre-compiled binaries. Both open and closed source software should be distributed with verifiable signatures from a trusted party and a path for users to verify that their copy of the software is functionally identical to every other copy (a property known as “binary transparency”).
  2. Explain choices of cryptographic algorithms and parameters. Make best efforts to fix or discontinue the use of cryptographic libraries, algorithms, or primitives with known vulnerabilities and disclose to customers immediately when a vulnerability is discovered.
  3. Hold an open and productive dialogue with the security and privacy communities. This includes facilitating review and responding to productive criticism from researchers.
  4. Provide a clear and secure pathway for security researchers to report vulnerabilities. Fix security bugs promptly.
  5. Publish government request reports regularly (often these are called “Transparency Reports”). Include the most granular reporting allowed by law.
  6. Invest in secure UX engineering to make it as easy as possible for users to use the system securely and as hard as possible for users to use the system unsafely.
  7. Publicly oppose mass surveillance and all efforts to mandate the insertion of backdoors or intentional weaknesses into security tools.
  8. Fight in court any attempt by the government or any third party to compromise users’ security.
  9. Adopt a principle of discarding user data after it is no longer necessary for the operation of the business.
  10. Always protect data-in-transit with strong encryption in order to prevent dragnet surveillance. Follow best practices for setting up SSL/TLS on servers whenever applicable.
Sincerely,
The Electronic Frontier Foundation in collaboration with*:
  • Roger Dingledine, Project Leader, Tor Project
  • Brendan Eich, CTO, Mozilla Corporation
  • Matthew Green, Assistant Research Professor, Department of Computer Science, Johns Hopkins University
  • Nadia Heninger, Assistant Professor, Department of Computer and Information Science, University of Pennsylvania
  • Tanja Lange, Professor, Department of Mathematics and Computer Science, Technische Universiteit Eindhoven
  • Nick Mathewson, Chief Architect, Tor Project
  • Eleanor Saitta, OpenITP / IMMI
  • Bruce Schneier, Security Technologist
  • Christopher Soghoian, Principal Technologist, Speech, Privacy and Technology Project, American Civil Liberties Union
  • Ashkan Soltani, Independent Researcher and Consultant
  • Brian Warner, Tahoe-LAFS Project
  • Zooko Wilcox-O’Hearn, Founder and CEO, LeastAuthority.com
*Affiliations listed for identification purposes only.

Thursday, November 21, 2013

It Is Time To Reform NSA Spying. Our Freedom Is Being Violated Every Day

Electronic Frontier Foundation: Same Mass Surveillance Story, Different Chapter

November 21, 2013 by  
 2 5
 
 0 41
Electronic Frontier Foundation: Same Mass Surveillance Story, Different Chapter
PHOTOS.COM
This post, written by EFF staff attorney Mark Rumold, originally appeared on the foundation’s website on Nov. 20.
Documents released Monday by the Director of National Intelligence tell a story we’ve heard before: The government, through one-sided argument in a secret court, obtained unConstitutional orders to collect vast amounts of information about millions of innocent Americans.
Before, it was Americans’ call records; the opinions released today describe the National Security Agency’s program collecting Americans’ Internet communications. And, just as we saw with the government’s bulk collection of calling records, what the Foreign Intelligence Surveillance Act court envisioned to be a closely controlled Internet metadata program quickly resulted in violations of its orders and restrictions, the search and collection of more information than the government was authorized to acquire, and repeated violations of the privacy of millions of Americans.
Here are some snippets, taken from the opinions and orders of the FISA court, describing the government’s repeated operation of the programs in violation of its orders:
Opinion of the FISC (pages 21-22)
Notwithstanding this and many similar prior representations, there in fact had been systemic overcollection since [redacted]. On [redacted] the government provided written notice of yet another form of substantial non-compliance discovered by NSA OGC. . . This overcollection, which had occurred continuously since the initial authorization . . . , included the acquisition of [redacted]. . . The government later advised that this continuous overcollection acquired many other types of data and that “[v]irtually every PR/TT record” generated by this program included some data that had not been authorized for collection.
The current application relies on this prior framework, but also seeks to expand authorization in ways that tests the limits of what the applicable FISA provisions will bear. It also raises issues that are closely related to serious compliance problems that have characterized the government’s implementation of prior FISC orders. It is therefore helpful at the outset to summarize both the underlying rationale of the prior authorizations and the government’s frequent failures to comply with their terms.
Order and Supplemental Order of the FISC (pages 6) (emphasis in original)
Given the apparent widespread disregard of [FISC imposed] restrictions, it seems clear that NSA’s Office of General Counsel has failed to satisfy its obligation to ensure that all analysts with access to information derived from the PT/TT metadata ‘recieve appropriate training and guidance regarding the querying standard set out in paragraph c. above, as well other procedures and restrictions regarding the retrieval, storage, and dissemination, of such information
The Court is also seriously concerned regarding NSA’s placement of unminimized metadata from both the above-captioned matters into databases accessible by outside agencies, which, as the government has acknowledged, violates not only the Court’s orders, but also NSA’s minimization and dissemination procedures set forth in USSID 18.
The Electronic Frontier Foundation just begun digesting the documents released Monday and will provide more analysis in the coming days. But EFF hopes these disclosures will provide more evidence, if any more was needed, of the need for serious and comprehensive FISA reform.

Tuesday, November 12, 2013

Unforseen Effects Of The NSA Spying Scandal. Writers Now Watch What They Do And Say.

NSA Spying Has Led Writers To Self-Censor

November 12, 2013 by 

A new survey conducted by a leading literary organization finds that the recent revelations of pervasive spying on American citizens have had a chilling effect on the intellectual freedom, creativity and social discourse of American writers.
The PEN American Center, a nonprofit literary group, partnered with the FDR Group to produce the report titled “Chilling Effects: NSA Surveillance Drives U.S. Writers to Self-Censor,” which notes that 85 percent of writers expressed worries about the government’s ongoing surveillance of American citizens. Seventy-three percent of respondents said that they “have never been as worried about privacy rights and freedom of the press as they are today.”
The report also notes:
–28% have curtailed or avoided social media activities, and another 12% have seriously considered doing so;
–24% have deliberately avoided certain topics in phone or email conversations, and another 9% have seriously considered it;
–16% have avoided writing or speaking about a particular topic, and another 11% have seriously considered it;
–16% have refrained from conducting Internet searches or visiting websites on topics that may be considered controversial or suspicious, and another 12% have seriously considered it;
–13% have taken extra steps to disguise or cover their digital footprints, and another 11% have seriously considered it;
–3% have declined opportunities to meet (in person, or electronically) people who might be deemed security threats by the government, and another 4% have seriously considered it.
Writer comments on the matter included statements like: “I assume everything I do electronically is subject to monitoring.”
And: “I feel that increased government surveillance has had a chilling effect on my research, most of which I do on the Internet. This includes research on issues such as the drug wars and mass incarceration, which people don’t think about as much as they think about foreign terrorism, but is just as pertinent.”
A similar chilling of creative expression and research by U.S. writers and journalists occurred after the passage of the  2012 National Defense Authorization Act, which included provisions allowing the Federal government to detain indefinitely any citizen suspected of aiding foreign terrorist organizations. The Act sparked a lawsuit by activists and reporters — including such notable names as Chris Hedges, Noam Chomsky, Naomi Wolf and Daniel Ellsberg — who claimed a section of the National Defense Authorization Act, signed by President Barack Obama in December, could give the Federal government legal powers to detain any dissident voices.