
latimes.com
Just as U.S. companies are coming to grips with the threats to their computer networks emanating from cyber spies based in China, a noted expert is highlighting what he says is an even more pernicious vulnerability in smartphones.

wiredThe document, marked “Law Enforcement Use Only” and dated August 2010, illustrates there are some significant differences in how long carriers retain your data.
Verizon, for example, keeps a list of everyone you’ve exchanged text messages with for the past year, according to the document. But T-Mobile stores the same data up to five years. It’s 18 months for Sprint, and seven years for AT&T.
That makes Verizon appear to have the most privacy-friendly policy. Except that Verizon is alone in retaining the actual contents of text messages. It allegedly stores the messages for five days, while T-Mobile, AT&T, and Sprint don’t store them at all.

reuters.com(Reuters) - Troy Lange knows that just mentioning cellphones is enough to give security officers heartburn at the National Security Agency.
Lange, as the NSA's mobility mission manager, is developing a smartphone that he wants to bring inside the super-secret U.S. spy agency to access classified information and apps while on the move. He wants it to work as easily as any of the smartphones those that are so ubiquitous in the outside world.
That is no small vision for an agency where entire buildings are designated as Sensitive Compartmented Information Facilities, known as SCIFs in spy speak, with many restrictions to ensure the handling and discussion of secret information stays secure.
Visitors to the Fort Meade, Maryland, NSA complex are not allowed to bring outside cellphones into the building.
Lange argues that using smartphones inside areas that deal with secret material will increase efficiency.
"I want to get this into everybody's hands" -- every employee in the Defense Department, intelligence community and across government, he said, while acknowledging that kind of talk makes "the security people's heads pop off."
More...
hothardware.comLooks like HTC has quietly slipped its users a spying app that tracks an alarming amount of user behavior and sends that data off to itself and perhaps others via a mysterious service in the cloud. The snooping app came nestled with the 2.3.4 Android update pushed out to some of its smartphones such as the Sensation 4G and EVO 4G.
TrevE and Team Synergy of the InfectedROM site (and XDA fame), discovered the app. HTC includes an application called Carrier IQ and Carrier IQ recently added a user-behavior logging feature called IQ Insight Experience Manager.
According to the Carrier IQ website: "IQ Insight Experience Manager uses data directly from the mobile phone itself to give a precise view of how users interact with both their phones and the services delivered through them, even if the phone is not communicating with the network. ... Identify exactly how your customers interact with services and which ones they use. See which content they consume, even offline."
But wait there's more. Turns out that after HTC collects these stats, CIQ isn't the only app with access to them.
wbur.orgLast Friday, the U.S. First Circuit Court of Appeals issued a ruling that affirmed, stronger than ever, the rights of individuals to openly record the actions of police officers.
In 2007, a young lawyer named Simon Glik was walking through Boston Common when he saw three police officers arresting a teenager. Glik thought the officers were getting a little rough, so he flipped open his cellphone camera and started shooting video.
The officers arrested Glik for, in their minds, violating the state’s wire-tapping law, even though the whole incident happened out in public and Glik didn’t try to conceal the fact that he was recording.
The ACLU took up Glik’s cause and the courts threw out the charges against him. Since then, the Boston Police Department has been instructing personnel that the state’s wiretapping law does not apply to people making unconcealed audio or video recordings in public. But Glik and the ACLU have pressed on, suing the BPD and the individual officers for violating his First Amendment rights.
The officers moved to have the suit dismissed, saying they were just enforcing an interpretation of the law that was handed down to them by their superiors. But on Friday, the federal court disagreed.
More...
tyrepress.com
security.cbronline.comGoing rate of one million stolen email addresses is $25, says cyber security company
Google's operating system (OS) for mobile phones, Android, has become a favourite target for cyber criminals with the amount of malware targeted at Android devices jumping 76% since last quarter, to become the most attacked mobile OS.
According to computer security company McAfee's latest 'Threats Report: Second Quarter 2011', this year has also resulted in the busiest ever first half-year in malware history.
In the second quarter (2Q) of 2011, Android OS-based malware surpassed Symbian OS for the most popular target for mobile malware developers.
The report also said that while Symbian OS and Java ME remain the most targeted to date, the rapid rise in Android malware indicates that the platform could become an increasing target for cybercriminals - affecting everything from calendar apps, to SMS messages to a fake Angry Birds updates.
McAfee Labs senior vice-president Vincent Weafer said, "This year we've seen record-breaking numbers of malware, especially on mobile devices, where the uptick is in direct correlation to popularity."
Weafer also said that cyber criminals are building sophisticated malware which are difficult to detect.

Rupert Murdoch, James Murdoch and their former editor Andy Coulson all face embarrassing new allegations of dishonesty and cover-up after the publication of an explosive letter written by the News of the World's disgraced royal correspondent, Clive Goodman.
In the letter, which was written four years ago but published only on Tuesday, Goodman claims that phone hacking was "widely discussed" at editorial meetings at the paper until Coulson himself banned further references to it; that Coulson offered to let him keep his job if he agreed not to implicate the paper in hacking when he came to court; and that his own hacking was carried out with "the full knowledge and support" of other senior journalists, whom he named.
The claims are acutely troubling for the prime minister, David Cameron, who hired Coulson as his media adviser on the basis that he knew nothing about phone hacking. And they confront Rupert and James Murdoch with the humiliating prospect of being recalled to parliament to justify the evidence which they gave last month on the aftermath of Goodman's allegations. In a separate letter, one of the Murdochs' own law firms claim that parts of that evidence were variously "hard to credit", "self-serving" and "inaccurate and misleading".
More...
(AP)WASHINGTON (AP) — Like its predecessor, the Obama administration says it cannot count how many people in the U.S. have had their telephone calls and emails monitored by government agents in national security investigations under federal surveillance law.
The national intelligence office said in a letter this week to two Senate Democrats that it was "not reasonably possible to identify the number."
The senators, Ron Wyden of Oregon and Mark Udall of Colorado, worry that the government may be monitoring communications of law-abiding citizens with inadequate justification.
"We're not asking these questions to embarrass the administration or make the intelligence community's job more difficult," Wyden said in a statement Thursday. "Congress needs to know if the laws it writes are being interpreted and implemented as intended before it is asked to extend them, and failing to assure the public that government agencies aren't violating the rights of law-abiding Americans erodes public confidence and makes it harder for intelligence agencies to do their jobs."
More...
krebsonsecurity.com
forbes.comHow do one ex-Air Force official and one former airplane hobby shop owner, both of whom happen to have decades of experience as network security contractors for the military, spend their weekends? Building a flying, unmanned, automated password-cracking, Wi-Fi-sniffing, cell-phone eavesdropping spy drone, of course.
At the Black Hat and Defcon security conferences in Las Vegas next week, Mike Tassey and Richard Perkins plan to show the crowd of hackers a year’s worth of progress on their Wireless Aerial Surveillace Platform, or WASP, the second year Tassey and Perkins have displayed the 14-pound, six-foot long, six-foot wingspan unmanned aerial vehicle. The WASP, built from a retired Army target drone converted from a gasoline engine to electric batteries, is equipped with an HD camera, a cigarette-pack sized on-board Linux computer packed with network-hacking tools including the BackTrack testing toolset and a custom-built 340 million word dictionary for brute-force guessing of passwords, and eleven antennae.
More...
iol.co.zaWhat makes it easy is the fact that few cellphone users bother to set the special PIN codes to allow them to use securely the special feature of accessing their messages from another phone. This means their cellphones remain on the service provider’s default settings – well known to all in the business.
And the user is left vulnerable to hackers such as Glenn Mulcaire, the private investigator at the centre of the UK’s News of the World phone hacking scandal.
But even in cases where the four-digit message default setting has been changed, private investigators say it is relatively easy to access – as long as you have a connection placed inside the particular service provider, or the gift of the “blag” – see sidebar.
Acting on behalf of the tabloid newspaper, Mulcaire – in search of a scoop for his employers – is alleged to have invaded the privacy of not only politicians and celebrities, but also, post-mortem, murdered teenager Milly Dowler and UK soldiers who lost their lives in Afghanistan and other theatres of war.
More...
mashable.comShe’s the highest official of News Corp. to be arrested so far. According to The Washington Post, she was arrested for “conspiring to intercept communications and on corruption allegations.”
Brooks had resigned her position on Friday as chief executive of News International, according to The Telegraph. She is alleged to have authorized electronic eavesdropping of the cellphones of hundreds of unknowing victims, tapping into the voicemail of a 13-year-old murder victim, and intercepting phone calls of numerous politicians and scores of celebrities.
More...
Note: This is the first installment in the Spy vs. Spy, "Technical Surveillance Threat Series". Stay tuned. JDL
Technical Surveillance Countermeasures, better known as "TSCM", is defined by "Wikipedia" as:
"A service provided by qualified personnel to detect the presence of technical surveillance devices ("bugs") and hazards and to identify technical security weaknesses that could aid in the conduct of a technical penetration of the surveyed facility".
In the civilian world, the above service is also sometimes referred to as a "Electronic Eavesdropping Detection" sweep or survey, or a "Bug Sweep".
Myself and my team have performed hundreds of TSCM Surveys for fortune 500 corporations, celebrities, executives, embassies, government offices, businesses, private individuals, law firms, etc., etc. There is always a common theme after an area has been cleared, "How can we protect ourselves from electronic surveillance threats after you leave?" The answer is usually complex, and almost always highly dependent upon our review (and recommendations) of our clients security posture and protocols in place at the time of the survey, and after we leave.
In this post, we will deal with one of those threats, "cellular devices", cell phones or "smart phones".
During our pre-survey Technical Threat Assessment, we usually find that "cellular devices" are allowed in almost all areas. There may be a cellular policy in place, but... during our verbal debrief after the area has been cleared, is usually when we find out what we have already discovered, that either there is no security protocol or policy in place regarding the allowance of cellular devices in board rooms and high level meetings, or there is a cellular policy in place, but it is not being enforced.
Almost all cellular phones have cameras, and many smart phones have audio recording features that allow conversations in person or over a smart phone to be easily recorded, stored, and even emailed. If you're like most of us, your cell phone is rarely more than 6 feet away from you. Many have "spy software" installed that allows for the smart phone microphone to be activated in secret without the phone ringing or lighting up. While it sits innocently near you, an eavesdropper can monitor every sound in the room.
So, does this potential eavesdropping threat sound like something that you want to allow in your next confidential boardroom meeting? Can your organization really afford to ignore this type of eavesdropping threat? Does your organization have a cellular policy in place? Is it enforced?
Here are a few personal cellular security tips:
Do not let your cell phone or smart phone out of your physical possession. Most cellular monitoring programs or "spyware" has to be installed through physical possession of the target phone. One of the best countermeasures is to keep tabs on yours.
Password protect your phone. I know it's a pain, but a password on your cell phone could save you or your organization a lot of misery.
Consider a review today of your organizations policy regarding cellular devices. Better safe, than sorry. No time? Contact ComSec, we can help. JDL
Stay tuned for the next installment in the Spy vs. Spy, Technical Surveillance Threat series.
ComSec, LLc provides professional Technical Surveillance & Eavesdropping Countermeasures services to Fortune 500 corporations to small businesses, non-profits, celebrities, executives and select individuals. Headquartered in Virginia Beach, VA | Northern VA-DC-MD. Serving the United States, and select International clients abroad.
cnn(CNN) -- Think about all the data -- photos, videos, text messages, calendar items, apps, call log, voice mail, and e-mail -- on your cell phone right now. If you're arrested, could the police search your cell phone? And would they need a warrant?
That depends on which state you're in.
In California, it is legal for police to search an arrestee's cell phone without a warrant -- ever since a January decision by the California Supreme Court.
California civil rights advocates are pushing back. The Electronic Frontier Foundation is supporting California Assembly Bill SB 914, which would require police in that state to get a warrant before searching an arrestee's cell phone.
EFF also recently filed an amicus brief in the Oregon case of James Tyler Nix, a criminal suspect who was arrested and placed in a holding cell.
According to EFF, "Forty minutes after the arrest, without a warrant, an investigator fished through the suspect's cell phone looking for evidence related to his alleged crime. Law enforcement officials claim they didn't need a warrant because the search was 'incident to arrest' -- an exception to the warrant requirement intended to allow officers to perform a search for weapons or to prevent evidence from being destroyed in exigent circumstances."
More...