Select Menu

Slider

Windows

Apple | Mac

Linux

Mobile

Hardware

Tutorial

Android

Privacy
Today, the much-anticipated findings of President Obama’s National Security Agency task force have hit the wire [PDF]. The non-binding 200 page report of 40-plus recommendations calls for the end of many of the most controversial programs.
Here are the big takeaways:
1. The government would no longer hold on to phone records in bulk. Instead, phone companies might warehouse the data for individual requests from the government. The recommendations say that the government should only access such data with a specific purpose, so it’s unknown how the NSA would continue to mine networks for patterns — or if it would be allowed to at all.
Here’s the important quote, “We recommend that legislation should be enacted that terminates the storage of bulk telephony meta-data by the government.”
2. Stop undermining global security standards. The NSA likes to maintain undiscovered hacking tools (“zero-day exploits“) and force loopholes in Internet security standards. The work it’s doing to crack basic encryption falls along those lines as well. It helps them monitor more traffic, but makes the web overall a less safe place.
3. No tech company “backdoors”. Google and other major tech companies have vigorously denied that they create special backdoor access for NSA spying, but the report recommends they cease this supposedly non-existent practice anyway. It is unclear whether such backdoors were currently being built out or already in existence.
4. Organizational changes: The director of the NSA should be confirmed by the Senate and open to civilians, there should be a new privacy board to review strategies, and the secret court should have a special public advocate. This differs from previous leaks to the Wall Street Journal, which implied that the panel recommend a civilian director.
5. More transparency: The government should disclose the number of users who the NSA has requested to examine.
The panel follows a torrent of new developments, any of which may significantly alter the way U.S. intelligence agencies gather private data en masse
Source : TechCrunch
- -
NSA
As a key part of a campaign to embed encryption software that it could crack into widely used computer products, the U.S. National Security Agency arranged a secret $10 million contract with RSA, one of the most influential firms in the computer security industry, Reuters has learned.
Documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products, the New York Times reported in September. Reuters later reported that RSA became the most important distributor of that formula by rolling it into a software tool called Bsafe that is used to enhance security in personal computers and many other products.

Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract. Although that sum might seem paltry, it represented more than a third of the revenue that the relevant division at RSA had taken in during the entire previous year, securities filings show.

The earlier disclosures of RSA's entanglement with the NSA already had shocked some in the close-knit world of computer security experts. The company had a long history of championing privacy and security, and it played a leading role in blocking a 1990s effort by the NSA to require a special chip to enable spying on a wide range of computer and communications products.

RSA, now a subsidiary of computer storage giant EMC Corp, urged customers to stop using the NSA formula after the Snowden disclosures revealed its weakness.

RSA and EMC declined to answer questions for this story, but RSA said in a statement: "RSA always acts in the best interest of its customers and under no circumstances does RSA design or enable any back doors in our products. Decisions about the features and functionality of RSA products are our own."

The NSA declined to comment.

The RSA deal shows one way the NSA carried out what Snowden's documents describe as a key strategy for enhancing surveillance the systematic erosion of security tools. NSA documents released in recent months called for using "commercial relationships" to advance that goal, but did not name any security companies as collaborators.
Via : NDTV Gadgets
- -
Pawel Kopczynski / Reuters
The latest documents from the National Security Agency leaked by Edward Snowden show that government spies are capable of listening in on mobile phone calls that use a common form of encryption, according to a Washington Post report. But if you're vulnerable, blame your carrier — this code has been cracked for years.
The Post on Friday published confidential government documents provided by Snowden that show that the NSA can "process" cellular phone calls on GSM networks, even if they are encrypted. GSM, which stands for Global System for Mobile communications, is the world's most widely used cellphone technology — though several large networks, notably Verizon and Sprint, rely on an older network technology called CDMA.
The report may sound scary, but there's a bit of explanation required that puts this in perspective.
First, it's only calls and not data that can be eavesdropped on, in this way at least. Second, it's only calls that have been encrypted according to a common standard called A5/1 — which was developed in 1987. The vulnerability comes into play on 2G networks, which modern cellphones may resort to it when 3G or 4G networks are not available or too congested. 
It's not uncommon for old cryptography methods to be in use for decades, or become relevant after years of disuse. But A5/1 has remained in use despite several serious vulnerabilities being demonstrated by cryptographers. The methods are too technical to get into here, but a modern PC would have little trouble performing the attacks; a number of papers on the subject are stored atCryptome.
Why are carriers and phone manufacturers around the world using such an out-of-date cypher? It's not clear, but some carriers are already making the change to the newer A5/3 method of encryption.
One other thing to consider is that these conversations, however strong their encryption, are automatically decoded upon reaching the carrier's internal network. So even if the NSA can't listen in between a target and the tower, they could bring a judge-signed order to the carrier and not have to decrypt anything at all.
Lastly, the NSA has repeatedly stated that it only snoops on conversations involving foreign citizens, as it has no legal basis by which to conduct such surveillance on Americans. But if they can crack A5/1, others can as well — for everyone from hackers to foreign intelligence services, the cat's been out of the bag for a long time.
Source : NBC News
- - -
NSA spying
If true, NSA spying could "seriously undermine confidence in the security and privacy of online communications," Microsoft's general counsel, Brad Smith, said in a blog post. "In light of these allegations, we've decided to take immediate and coordinated action."
Smith pledged to "pursue a comprehensive engineering effort to strengthen the encryption of customer data across our networks and services." That includes major communications, productivity, and developer services such as Outlook.com, Office 365, SkyDrive, and Windows Azure.
Content moving between customers and Microsoft's servers will be encrypted by default, as will communications moving between Redmond's data centers, using "best-in-class industry cryptography to protect these channels, including Perfect Forward Secrecy and 2048-bit key lengths," Smith said. "All of this will be in place by the end of 2014, and much of it is effective immediately."
Smith said Office 365 and Outlook.com customer content is already encrypted when traveling between customers and Microsoft, while most Office 365 workloads as well as Windows Azure storage are now encrypted in transit between data centers.
In addition to encryption, Microsoft also said it will "take new steps to reinforce legal protections for our customers' data," - like informing them when the feds request data. "Where a gag order attempts to prohibit us from doing this, we will challenge it in court," Smith said.
The company will also open a "network of transparency centers" in Europe, the Americas and Asia that will build on "our long-standing program that provides government customers with an appropriate ability to review our source code, reassure themselves of its integrity, and confirm there are no back doors."
"Ultimately, we're sensitive to the balances that must be struck when it comes to technology, security and the law, ... but we also want to live in a country that is protected by the Constitution," Smith concluded. "We believe these new steps strike the right balance, advancing for all of us both the security we need and the privacy we deserve."
Reports that Microsoft would step up encryption emerged last month. That came after The Washington Post, citing documents provided by Edward Snowden, reported on MUSCULAR, an NSA program that operates in conjunction with the U.K. version of the NSA, the Government Communications Headquarters (GCHQ). Together, they "are copying entire data flows across fiber-optic cables that carry information between the data centers of the Silicon Valley giants" like Yahoo and Google, the paper said.
Source : PCMag
- - - -