Tampilkan postingan dengan label electronic eavesdropping. Tampilkan semua postingan
Tampilkan postingan dengan label electronic eavesdropping. Tampilkan semua postingan
Sabtu, 18 Februari 2012
COMSEC AUDIO JAMMER APP for iPHONE
itunes.apple.com
COMSEC AUDIO JAMMER
Keep your private conversations private!
The COMSEC AUDIO JAMMER protects your sensitive room conversations by generating a random masking sound, which desensitizes any near-by microphone. Effective against any microphone based eavesdropping device including tape recorders, RF transmitters, hard-wired microphones (including contact type) and shotgun microphones. It also protects against microwave or laser reflection pickups (when used correctly).
COMSEC AUDIO JAMMER uses specially designed audio speech patterns to mask your conversations from hidden microphones & eavesdroppers.
The speech patterns are randomly designed and generated to mask normal conversations from eavesdroppers.
More...get the app here.
Kamis, 16 Februari 2012
Securing Corporate Data in a Law Office's Computer Network
Note: An excellent article, and a serious subject... When is the last time your law firm had a Cyber TSCM sweep? Ever? Contact me, I can help. ~JDL
law.com
The dramatic rise in electronic economic espionage against U.S. corporations came into full view with a report on the trend issued by the U.S. government last November. That same month, the Federal Bureau of Investigation held a meeting in New York City with some of the weaker links in the online spy game: law firms.
It’s an issue that should be getting the attention of in-house counsel, especially as they share sensitive--and potentially valuable--data with outside counsel.
Rich with client information, law firms are often much less equipped to fend off cyberattacks than the corporations they represent. Ergo “a hacker can hit a law firm and it’s a much, much easier quarry,” Mary Galligan, head of the cyber division in the FBI’s New York City office told Bloomberg. Likewise, in a series of blog posts on this issue currently running in Forbes, cybersecurity expert Alan Paller says: “The important files relating to clients’ international activities are usually much easier to find in the law firms’ files than in the corporate files.”
Digital risk consultancy Stroz Friedberg has advised both law firms and corporate clients on this growing problem. Firms need to take a risk-oriented approach to protecting client information, says company co-president Eric Friedberg, a former federal prosecutor and an expert in cybercrime response. At the same time, he says, there are important questions in-house counsel can ask about how their files will be protected (seeCounsel’s Dozen list below).
“Attackers go where the money is,” says Friedberg. These days, law firms should assume that hackers will infiltrate their network, and they should identify which digital assets are most at risk and put the most security around those areas, he says.
More...
law.com
The dramatic rise in electronic economic espionage against U.S. corporations came into full view with a report on the trend issued by the U.S. government last November. That same month, the Federal Bureau of Investigation held a meeting in New York City with some of the weaker links in the online spy game: law firms.
It’s an issue that should be getting the attention of in-house counsel, especially as they share sensitive--and potentially valuable--data with outside counsel.
Rich with client information, law firms are often much less equipped to fend off cyberattacks than the corporations they represent. Ergo “a hacker can hit a law firm and it’s a much, much easier quarry,” Mary Galligan, head of the cyber division in the FBI’s New York City office told Bloomberg. Likewise, in a series of blog posts on this issue currently running in Forbes, cybersecurity expert Alan Paller says: “The important files relating to clients’ international activities are usually much easier to find in the law firms’ files than in the corporate files.”
Digital risk consultancy Stroz Friedberg has advised both law firms and corporate clients on this growing problem. Firms need to take a risk-oriented approach to protecting client information, says company co-president Eric Friedberg, a former federal prosecutor and an expert in cybercrime response. At the same time, he says, there are important questions in-house counsel can ask about how their files will be protected (seeCounsel’s Dozen list below).
“Attackers go where the money is,” says Friedberg. These days, law firms should assume that hackers will infiltrate their network, and they should identify which digital assets are most at risk and put the most security around those areas, he says.
More...
Chinese Telecoms May Be Spying on Large Numbers of Foreign Customers
theatlantic.com
A U.S. Congressional probe is investigating whether China's state-linked firms, which built much of the communications infrastructure in several Asian countries, is using its access for snooping.
Two Chinese telecommunications giants are under scrutiny by a US congressional committee. The outcome of the probe could have revealing implications for Central Asian states, which have used these companies to modernize their telecom sectors.
US legislators have expressed concern that Huawei and ZTE act as front companies for the Chinese government, and represent a grave "cyber-security threat." The chairman of the House Permanent Select Committee on Intelligence, Michigan Republican Mike Rogers, asserted during a congressional hearing last October that China is engaged in the "brazen and wide-scale theft of intellectual property from foreign commercial competitors."
"Attributing this espionage isn't easy, but talk to any private sector cyber analyst, and they will tell you there is little doubt that this is a massive campaign being conducted by the Chinese government," he added.
More...
A U.S. Congressional probe is investigating whether China's state-linked firms, which built much of the communications infrastructure in several Asian countries, is using its access for snooping.
Two Chinese telecommunications giants are under scrutiny by a US congressional committee. The outcome of the probe could have revealing implications for Central Asian states, which have used these companies to modernize their telecom sectors.
US legislators have expressed concern that Huawei and ZTE act as front companies for the Chinese government, and represent a grave "cyber-security threat." The chairman of the House Permanent Select Committee on Intelligence, Michigan Republican Mike Rogers, asserted during a congressional hearing last October that China is engaged in the "brazen and wide-scale theft of intellectual property from foreign commercial competitors."
"Attributing this espionage isn't easy, but talk to any private sector cyber analyst, and they will tell you there is little doubt that this is a massive campaign being conducted by the Chinese government," he added.
More...
Rabu, 15 Februari 2012
Texas constable admits ordering bugging
chron.com
DALLAS (AP) — A small-town Texas constable told the FBI he secretly bugged other officials' offices after they were accused of illegally forcing motorists to forfeit their cash, according to a search warrant affidavit.
The affidavit, based on interviews conducted by FBI agents and Texas Rangers, quotes Shelby CountyConstable Fred Walker as saying he authorized the installation of hidden surveillance cameras and digital recorders even though he didn't have legal authority. It also includes a statement from a witness who claims Walker helped organize a scheme to sell drugs seized from suspects.
It's just another chapter in a longtime drama in Tenaha, a town of 1,160 near the Louisiana border, where seizures of cash from motorists stopped for traffic violations along U.S. Highway 59 — a well-known drug route that runs from the U.S.-Mexico border to Canada — have led to lawsuits and a federal criminal investigation.
Walker, 53, was Tenaha's city marshal at the time the alleged bugging occurred. He was elected constable in 2010.
In a brief phone interview, Walker said he knew nothing about the affidavit, filed in U.S. District Court in Lufkin on Feb. 6. When asked if he arranged to have offices bugged, he hung up.
Walker's attorney, Bassey Akpaffiong of Houston, said prosecutors have told him to expect an indictment. Akpaffiong said Walker was never involved in selling drugs and never told the FBI he authorized the installation of secret listening devices.
Malcolm Bales, U.S. attorney for the Eastern District of Texas, declined to comment.
Sabtu, 04 Februari 2012
Anons' FBI Phone Snooping Casts Long Shadow on Cybersecurity
technewsworld.com
Members of Anonymous managed to tap into an FBI conference call recently, after which they put a recording of the call on the open Web. The news has raised concern in many corners of the security industry. "The odds are that cybersecurity at the FBI and Scotland Yard is on par with, or superior to, security at most corporations," Abrams said.
Members of Anonymous managed to tap into an FBI conference call recently, after which they put a recording of the call on the open Web. The news has raised concern in many corners of the security industry. "The odds are that cybersecurity at the FBI and Scotland Yard is on par with, or superior to, security at most corporations," Abrams said.
The hacker community Anonymous on Friday landed another blow in its war with the United States Federal Bureau of Investigation (FBI).
It posted an internal memo from the law enforcement agency about an upcoming international call to discuss hackers. Anonymous also put up a recording of the call itself onYouTube.
The attacks are part of a concerted hacker effort against the FBI.
"The information was intended for law enforcement officers only and was illegally obtained," the FBI said in a statement sent to TechNewsWorld by spokesperson Jenny Shearer. "A criminal investigation is underway to identify and hold accountable those responsible."
The recorded call was a conversation between the FBI and Scotland Yard regarding tracking Anonymous members and other digital activists. It also involved other details about the efforts against such groups.
Senin, 30 Januari 2012
Bugging equipment found in Mexico lawmaker offices
philstar.com
MEXICO CITY (AP) — A search of several Mexican lawmakers' offices turned up recording equipment, leading legislators to believe they have been spied on for years, a congressman said Wednesday.
Congressman Armando Rios said security personnel found microphones and other devices that seemed to have been installed years ago.
"Some of the equipment has newer technology, but other devices are from a long time ago, which leads us to believe they were installed years ago," said Rios, a member of the leftist Democratic Revolution Party, or PRD
Rios said the offices of key committees and of several lawmakers from different political parties were bugged.
"What is at stake is the vulnerability of the legislature, of one of the powers of the union," Rios said.
Congress president Guadalupe Acosta, also of the PRD, on Tuesday filed a complaint with federal prosecutors, who opened an investigation.
Acosta wouldn't identify the lawmakers who were being spied on or who he thinks was behind the espionage. Rios blamed the government of President Felipe Calderon, who belongs to the conservative National Action Party, or PAN.
Interior Secretary Alejandro Poire denied Rios' accusations and said the government has done nothing illegal.
Mexico's main intelligence agency allegedly spied on the government's political opponents during the 71 years of rule by the Institutional Revolutionary Party, or PRI.
After PAN candidate Vicente Fox won the 2000 presidential election, he announced that the agency, the Center for National Security and Investigation, would no longer spy on political opponents. But in 2008, under Calderon, the agency hired a private company to monitor the activities of legislators.
Legislators complained they were being spied on but the government said it was simply collecting public information.
More...
MEXICO CITY (AP) — A search of several Mexican lawmakers' offices turned up recording equipment, leading legislators to believe they have been spied on for years, a congressman said Wednesday.
Congressman Armando Rios said security personnel found microphones and other devices that seemed to have been installed years ago.
"Some of the equipment has newer technology, but other devices are from a long time ago, which leads us to believe they were installed years ago," said Rios, a member of the leftist Democratic Revolution Party, or PRD
Rios said the offices of key committees and of several lawmakers from different political parties were bugged.
"What is at stake is the vulnerability of the legislature, of one of the powers of the union," Rios said.
Congress president Guadalupe Acosta, also of the PRD, on Tuesday filed a complaint with federal prosecutors, who opened an investigation.
Acosta wouldn't identify the lawmakers who were being spied on or who he thinks was behind the espionage. Rios blamed the government of President Felipe Calderon, who belongs to the conservative National Action Party, or PAN.
Interior Secretary Alejandro Poire denied Rios' accusations and said the government has done nothing illegal.
Mexico's main intelligence agency allegedly spied on the government's political opponents during the 71 years of rule by the Institutional Revolutionary Party, or PRI.
After PAN candidate Vicente Fox won the 2000 presidential election, he announced that the agency, the Center for National Security and Investigation, would no longer spy on political opponents. But in 2008, under Calderon, the agency hired a private company to monitor the activities of legislators.
Legislators complained they were being spied on but the government said it was simply collecting public information.
More...
Label:
bug,
bug sweep,
bugged,
bugging,
counter surveillance,
cyber tscm,
electronic eavesdropping,
spy,
spy watch,
spying,
tscm,
wiretapping
Minggu, 29 Januari 2012
DARPA-Funded Hacker's Tiny $50 Spy Computer Hides In Offices, Drops From Drones
forbes.com
Even more embarrassing than a student discovering your GPS tracking device on his car, as the FBI found out last year, is having to ask him to give the expensive piece of equipment back.
So security researcher Brendan O’Connor is trying a different approach to spy hardware: building a sensor-equipped surveillance-capable computer that’s so cheap it can be sacrificed after one use, with off-the-shelf parts that anyone can buy and assemble for less than fifty dollars.
At the Shmoocon security conference Friday in Washington D.C., O’Connor plans to present the F-BOMB, or Falling or Ballistically-launched Object that Makes Backdoors. Built from just the hardware in a commercially-available PogoPlug mini-computer, a few tiny antennae, eight gigabytes of flash memory and some 3D-printed plastic casing, the F-BOMB serves as 3.5 by 4 by 1 inch spy computer. And O’Connor has designed the cheap gadgets to dropped from a drone, plugged inconspicuously into a wall socket, thrown over a barrier, or otherwise put into irretrievable positions to quietly collect data and send it back to the owner over any available Wifi network. With PogoPlugs currently on sale at Amazon for $25, O’Connor built his prototypes with gear that added up to just $46 each.
“If some target is surrounded by bad men with guns, you don’t want to have to retrieve this, but you also don’t want to have to pay four or five hundred dollars for every use,” says O’Connor. “The idea is that it’s as close to free as possible. So you can throw a bunch of these sensors at a target and get away with losing a couple nodes in the process.”
Sabtu, 21 Januari 2012
Alleged spy fed false info in sting to hurt credibility
vancouversun.com
Authorities fed an alleged Canadian naval spy fabricated information as part of a classic "sour milk" counter-intelligence ploy to taint the credibility of secrets the man is suspected of passing to Russia, Postmedia has learned.
"This was done by the book - sour the milk so that you con-fuse the other side," Michel Juneau-Katsuya, a former spy service counter-intelligence officer with sources close to the Halifax case, revealed in an interview Friday.
Once naval officials suspected there was a spy in their midst, deliberately flawed information was baited and designed to eventually be discovered by its foreign recipients, casting doubt on the usefulness of any other classified data related to the case.
Juneau-Katsuya said the deception is believed to have worked, and now "they don't know what is true and what is not [and] will have to be suspicious of pretty much everything [given to] them."
While military and RCMP investigators are still gathering details, Juneau-Katsuya said he believes Russia may have been after North Atlantic Treaty Organization [NATO] secrets.
"When you talk about Halifax, you talk about the Atlantic and the Arctic. And when you talk about the Atlantic and Arctic, you talk NATO. And when you talk NATO, you talk Russia," he said.
Jumat, 20 Januari 2012
10 Sites Skewered by Anonymous, Including FBI, DOJ, U.S. Copyright Office
techland.time.com
By the time East Coasters were finishing dinner last night, 10 websites had fallen to what hacktivist group Anonymous calls its “low orbit ion cannon,” or LOIC — a public domain software tool named after a weapon in a popular sci-fi real-time strategy game that’s designed to stress test whether a network can handle a distributed denial of service attack.
According to Anonymous, 10 well-known governmental and corporate sites with ties to the entertainment industry were assaulted and knocked offline in retaliation for the FBI shutting down Megaupload.com, one of the world’s largest file-sharing sites. The FBI had closed Megaupload.com earlier Thursday afternoon, accusing the company of more than $500 million in revenue losses stemming from copyright violations, and arresting four people in connection with the indictment.
Dubbing its DDoS spree “OpMegaupload,” Anonymous claims it took down usdoj.govand justice.gov (the U.S. Department of Justice), universalmusic.com (Universal Music Group),RIAA.org (the Recording Industry Association of America), MPAA.org (the Motion Picture Association of America), copyright.gov (the U.S. Copyright Office), hadopi.fr (France’s copyright-enforcement agency), wmg.com (Warner Music Group), bmi.com (Broadcast Music, Inc.) andfbi.gov (the Federal Bureau of Investigation). The DOJ’s website was first to fall, about an hour after the Justice Department announced its indictment of Megaupload.com.
Selasa, 17 Januari 2012
Facebook names $2m 'Koobface' hacking gang
telegraph.co.uk
Facebook has publicly identified a gang of five alleged cyber criminals it believes are behind Koobface, a piece of malicious software that has hijacked hundreds of thousands of Facebook users’ computers and made millions for its creators.
Facebook has publicly identified a gang of five alleged cyber criminals it believes are behind Koobface, a piece of malicious software that has hijacked hundreds of thousands of Facebook users’ computers and made millions for its creators.
After an investigation by Facebook and several independent security researchers, the gang behind Koobface have been named as a group of Russians operating relatively openly in central St Petersburg.
According to their own social networking profiles, the five men have enjoyed a luxurious lifestyle. On one group holiday, they visited Spain, Nice and Monte Carlo, before ending the trip at a casino in Germany, according to Sophos, a British security firm involved in the investigation.
The gang were “living the life of the rich and famous”, Sophos said.
Facebook said it has known the identities of the gang for some time, but has decided to name them publicly after being frustrated by the lack of law enforcement action against them. The Telegraph has chosen not to name them for legal reasons.
“We’ve had a picture of one of the guys in a scuba mask on our wall since 2008,” said Ryan McGeehan, manager of investigations at Facebook.
Kamis, 12 Januari 2012
Cyber-Crimes Pose 'Existential' Threat, FBI Warns
huffingtonpost.com
Despite the increased frequency and severity of online crime and espionage in 2011, many American corporations and consumers are still not taking the threat seriously, the FBI's top cyber official said Thursday.
The risk posed by criminal hackers is "existential, meaning it could eliminate whole companies," said Shawn Henry, the FBI's executive assistant director. If hackers were able to tamper with critical infrastructure such as the power grid, "it could actually cause death," Henry said in remarks at the International Conference on Cyber Security in New York.
To highlight the growing threat, Henry cited several recent FBI investigations, such as one involving a smaller company that went out of business after hackers stole $5 million from accounts, another concerning a larger firm that "virtually overnight" lost a decade of research and development worth $1 billion, and still another regarding hackers who encrypted millions of records of a health services company and demanded money for the password.
"We've seen the number and sophistication of the attacks by these cyber actors increase dramatically," Henry said.
"Hundreds of millions of dollars have been stolen, primarily through the financial services sector, just in the last couple years," he said. An organized crime ring in Eastern Europe, for example, earned about $750,000 per week from cyber theft, he added.
More...
Note: Does your company have a Cyber TSCM / Cyber Counterespionage plan in place? Contact me, I can help. ~JDL
Despite the increased frequency and severity of online crime and espionage in 2011, many American corporations and consumers are still not taking the threat seriously, the FBI's top cyber official said Thursday.
The risk posed by criminal hackers is "existential, meaning it could eliminate whole companies," said Shawn Henry, the FBI's executive assistant director. If hackers were able to tamper with critical infrastructure such as the power grid, "it could actually cause death," Henry said in remarks at the International Conference on Cyber Security in New York.
To highlight the growing threat, Henry cited several recent FBI investigations, such as one involving a smaller company that went out of business after hackers stole $5 million from accounts, another concerning a larger firm that "virtually overnight" lost a decade of research and development worth $1 billion, and still another regarding hackers who encrypted millions of records of a health services company and demanded money for the password.
"We've seen the number and sophistication of the attacks by these cyber actors increase dramatically," Henry said.
"Hundreds of millions of dollars have been stolen, primarily through the financial services sector, just in the last couple years," he said. An organized crime ring in Eastern Europe, for example, earned about $750,000 per week from cyber theft, he added.
More...
Note: Does your company have a Cyber TSCM / Cyber Counterespionage plan in place? Contact me, I can help. ~JDL
Selasa, 10 Januari 2012
Cyber Attacks May Be Revealed to Investors as SEC Rules Push Disclosures
Note: This was bound to happen as more and more companies become victims of Cyber Espionage. Has your company become a victim of Cyber Espionage? And, more importantly, does your company have a Cyber TSCM / Cyber Counterespionage strategy in place to mitigate this risk?
Contact me, I can help. ~JDL
bloomberg.com
Contact me, I can help. ~JDL
bloomberg.com
China-based hackers rifled the computers of DuPont Co. (DD) at least twice in 2009 and 2010, hunting the technological secrets that made the company one of the world’s most successful chemical makers.
It’s not something investors would have learned from DuPont’sregulatory filings, or from those of other companies victimized by hackers. The 10-K’s DuPont submitted to the U.S. Securities and Exchange Commission over the period don’t identify hacking as even a significant risk, much less reveal what two U.S. intelligence officials later said was a successful case of industrial espionage.
Over the next three months, as publicly traded companies file 10-K’s, investors may see new admissions of corporate networks being hacked after the SEC said companies can’t continue to hold back the details of those incidents.
As cyberspies from China, Russia and other countries ransack the computer networks of one major U.S. and European firm after the next, the SEC in October offered its new interpretation of disclosure requirements as applied to cybercrime. The amount of information that’s forthcoming will depend on whether company lawyers determine the incidents had, or will have, a material effect on the enterprise.
Daniel Turner, a spokesman for Wilmington, Delaware-based DuPont, said, regarding the previously-reported hack, “We let our disclosures speak for themselves.”
Senin, 09 Januari 2012
Symantec Confirms Anonymous Took Product Source Code
crn.com
Symantec (NSDQ:SYMC) confirmed Friday that an India-based chapter of hacker collective Anonymous had accessed the network of an unidentified third party and had taken source code from two of its corporate security products.
The vendor said code samples provided Thursday to an online community of security professionals called Infosec Island were from two products: Symantec Endpoint Protection 11 and Symantec AntiVirus 10.2. The vendor supports the latter, but no longer sells it, while the former is currently on version 12.1. The code was four or five years old, according to Symantec.
"It would be very difficult to do anything with (the code), because it is so old," Symantec spokesman Cris Paden said.
Malware designed to take advantage of the code would only work on the older products. Therefore, hackers would have to find a company that had not updated its security software in years, an unlikely scenario. "They would have been annihilated a long time ago from cyber threats," Paden said.
Symantec claimed the theft did not indicate that source code in its current products could be taken. The software today is architected differently, so the techniques used to take code from the older products won't work, Paden said. "It's not possible that they would be able to access current-day code."
Kamis, 05 Januari 2012
Brute force tools crack Wi-Fi security in hours, millions of wireless routers vulnerable
computerworld.com
If you set WPA/WPA2 security protocol on your home or small business wireless router, and you think your Wi-Fi is secure, there two recently released brute force tools that attackers may use to bypass your encryption and burst your security bubble. The irony is that the vulnerability which can be exploited was intended to be a security strength, a usability issue to help the technically clueless setup encryption on their wireless networks. Wi-Fi Protected Setup (WPS) is enabled by default on most major brands of wireless routers including Belkin, Buffalo, D-Link, Cisco's Linksys and Netgear, leaving millions of wireless routers around the world vulnerable to brute force attacks which can crack the Wi-Fi router's security in two to ten hours.
Most wireless routers come with a WPS personal identification number (PIN) printed on the device. When a user is setting up a wireless home network via a network setup wizard, enabling encryption is often as easy as pushing a button on the router and then entering the eight digit PIN which came with it. When an attacker is attempting to brute force the PIN and an incorrect value was entered, a message is sent that basically tells an attacker if the first half of the PIN was right or not. Additionally, according to Stefan Viehbock, the security researcher who reported the flaw, "The 8th digit of the PIN is always the checksum of digit one to digit seven," meaning it only takes an attacker about 11,000 brute force guesses to own the password. Unfortunately most wireless routers don't have a lockout policy after several failed password attempts.
Rabu, 04 Januari 2012
How to Know If Someone Bugged Your Room
theatlanticwire.com
For tips on sweeping a room for surreptitious surveillance devices, look no further than the Federal Bureau of Investigation. That's where members of the federal government have been going for years to find out who's wiretapped their telephone or implanted a microphone in their corner office. And now we know a lot more about the bureau's routine wiretap inspections thanks to GovernmentAttic.org, a website that publishes documents from Freedom of Information Act requests. The site has published a 66MB cache of correspondence from 1952 to 1995 detailing various issues of telephone security often involving paranoid government officials from senators to post master generals to secretaries of the Department of Agriculture to President Richard Nixon who think someone is surreptitiously listening to their conversations.
For tips on sweeping a room for surreptitious surveillance devices, look no further than the Federal Bureau of Investigation. That's where members of the federal government have been going for years to find out who's wiretapped their telephone or implanted a microphone in their corner office. And now we know a lot more about the bureau's routine wiretap inspections thanks to GovernmentAttic.org, a website that publishes documents from Freedom of Information Act requests. The site has published a 66MB cache of correspondence from 1952 to 1995 detailing various issues of telephone security often involving paranoid government officials from senators to post master generals to secretaries of the Department of Agriculture to President Richard Nixon who think someone is surreptitiously listening to their conversations.
It's going to take an army of readers to rummage through the entire cache of FBI documents but from what we've read so far, much of the correspondence involves government officials requesting wiretap inspections from the FBI, typically because they fear sensitive information has leaked from their office, and, upon inspection, the FBI finds nothing. Interestingly, they do often provide an informative report on how they went about sweeping the room.
As you can imagine, the descriptions of wiretap sweeps get much more technical from the '50s to the '70s to the '90s. In the old days, a wiretap inspection was simpler. Take this sweep of the office of Postmaster General Arthur Summerfield in 1953.
Note: A "Do it yourself" sweep, is kind of like "do it yourself" plumbing...you get what you pay for...
Don't let those "leaks" continue...contact me, I can help. ~JDL
Label:
bug,
bug sweep,
bugged,
bugging,
bugs,
cyber tscm,
eavesdropping detection,
electronic eavesdropping,
fbi,
spy watch,
spying,
tscm,
wiretapping
Jumat, 30 Desember 2011
Wiretap suits OKd against U.S., not telecoms
sfgate.com
The nation's telecommunications companies can't be sued for cooperating with the Bush administration's secret surveillance program, but their customers can sue the government for allegedly intercepting their phone calls and e-mails without a warrant, a federal appeals court ruled Thursday.
In a pair of decisions, the Ninth U.S. Circuit Court of Appeals in San Francisco upheld a 2008 law immunizing AT&T and other companies for their roles in wiretapping calls to alleged foreign terrorists, but revived a suit that accused the government of illegally intercepting millions of messages from U.S. residents.
That lawsuit was partly based on testimony in 2003 by former AT&T technician Mark Klein about equipment in the company's office on Folsom Street in San Francisco that allowed Internet traffic to be routed to the government.
"We look forward to proving the program is an unconstitutional and illegal violation of the rights of millions of ordinary Americans," said Cindy Cohn, the foundation's legal director.
Justice Department spokesman Dean Boyd declined comment.
More...
The nation's telecommunications companies can't be sued for cooperating with the Bush administration's secret surveillance program, but their customers can sue the government for allegedly intercepting their phone calls and e-mails without a warrant, a federal appeals court ruled Thursday.
In a pair of decisions, the Ninth U.S. Circuit Court of Appeals in San Francisco upheld a 2008 law immunizing AT&T and other companies for their roles in wiretapping calls to alleged foreign terrorists, but revived a suit that accused the government of illegally intercepting millions of messages from U.S. residents.
That lawsuit was partly based on testimony in 2003 by former AT&T technician Mark Klein about equipment in the company's office on Folsom Street in San Francisco that allowed Internet traffic to be routed to the government.
'Dragnet' surveillance
The Electronic Frontier Foundation, a privacy-rights organization representing AT&T customers, claimed the company had similar installations in other cities and used them for "dragnet" surveillance of everyday e-mails and phone calls, which the National Security Agency purportedly screened electronically for connections to terrorism."We look forward to proving the program is an unconstitutional and illegal violation of the rights of millions of ordinary Americans," said Cindy Cohn, the foundation's legal director.
Justice Department spokesman Dean Boyd declined comment.
More...
Label:
bug sweep,
bugged,
bugging,
electronic eavesdropping,
electronic surveillance,
nsa,
secret,
spy watch,
spying,
tscm,
wiretap,
wiretapping
Senin, 26 Desember 2011
U.S. Headed For Cyberwar Showdown With China In 2012
forbes
The new year is likely to bring a distinct shift in U.S. national security priorities, as the Obama Administration and Congress sharpen their response to China’s continuous assault on U.S. information networks. Although intelligence-community analysts believe the most sophisticated intrusions are being executed by a relatively small number of agents linked to the general staff of China’s Peoples Liberation Army, the damage they are inflicting on U.S. security and economic competitiveness is judged to be extensive.
The new year is likely to bring a distinct shift in U.S. national security priorities, as the Obama Administration and Congress sharpen their response to China’s continuous assault on U.S. information networks. Although intelligence-community analysts believe the most sophisticated intrusions are being executed by a relatively small number of agents linked to the general staff of China’s Peoples Liberation Army, the damage they are inflicting on U.S. security and economic competitiveness is judged to be extensive.
Thus far, China’s cyber campaign consists mainly of espionage aimed at stealing military secrets and intellectual property. However, Gen. Keith Alexander, head of the Pentagon’s joint Cyber Command established to counter such campaigns, said in November that, “We see a disturbing track from exploitation to disruption to destruction.” Alexander wasn’t talking just about the Chinese, but there’s little doubt among intelligence analysts that Beijing is the biggest and most persistent perpetrator of cyber crimes.
The question is what to do about it. To date, U.S. cyber efforts have been focused mainly on defensive measures, seeking to repel network intruders in a fashion that Alexander likens to the famously failed Maginot Line. The National Security Agency and other U.S. security organizations are known to have developed their own network-attack capabilities, but former White House cyber-security advisor Richard Clarke has warned that it would be dangerous for the U.S. to step up its own campaign against Chinese networks while U.S. safeguards against retaliation are so weak.
2012 Will See Rise in Cyber-Espionage and Malware, Experts Say
pcworld.com
The security industry expects the number of cyber-espionage attacks to increase in 2012 and the malware used for this purpose to become increasingly sophisticated.
The security industry expects the number of cyber-espionage attacks to increase in 2012 and the malware used for this purpose to become increasingly sophisticated.
In the past two years there has been a surge in the number of malware-based attacks that resulted in sensitive data being stolen from government agencies, defense contractors, Fortune 500 companies, human rights organizations and other institutions. (See also "How to Remove Malware From Your Windows PC.")
"I absolutely expect this trend to continue through 2012 and beyond," said Rik Ferguson, director of security research and communication at security firm Trend Micro. "Espionage activities have, for hundreds of years, taken advantage of cutting-edge technologies to carry out covert operations; 2011 was not the beginning of Internet-facilitated espionage, nor will it be the end," he added.
Threats like Stuxnet, which is credited with setting back Iran's nuclear program by several years, or its successor, Duqu, have shocked the security industry with their level of sophistication. Experts believe that they are only the beginning and that more highly advanced malware will be launched in 2012.
Rabu, 16 November 2011
Attackers Get Sneakier With Encrypted Malware
pcworld.com
Malware just got sneaky! Well, sneakier, that is. Attackers in Brazil have found a way to sneak around antivirus programs by using cryptography.
Recently Dmitry Bestuzhev, Kaspersky Lab's Head of Global Research and Analysis Team for Latin America, was looking over some potentially malicious links from Brazil when he discovered some files with .jpeg filename extensions. At first glance, Bestuzhev thought that they were some form ofsteganography--the art and science of hiding messages. But upon further inspection, the reseacher discovered that they were actually more like .bmp (bitmap) files, than JPEGs.
The data contained within the files themselves was obviously encrypted and contained some kind of malware; Bestuzhev later discovered that the data was in the form of block ciphers--a cryptographic method that encrypts 128-bit blocks of plain text in to 128-bit blocks of cipher text. Since block ciphers can only be composed of 128-bit blocks, they must break up the message into several blocks and encrypt each one individually. A process called modes of operationallows a cryptographer to repeatedly use block ciphers to encrypt an entire program--or piece of malware, in this case.
Fox-IT and TNO to Work on System for Detecting Digital Espionage
digitaljournal.com
More...
Delft, The Netherlands (PRWEB) November 16, 2011
The threat of targeted cyber attacks, especially digital espionage is increasing rapidly. The current security measures against cybercrime focus primarily on the detection of massive and indiscriminate attacks. To protect businesses and governments against cyber espionage Fox-IT and TNO are developing the Cyber Attack Detector (CAD).
Analyzing a large number of digital espionage indicators will allow users to be instantly alerted when there are activities that indicate fraud or espionage. The Ministry of Economic Affairs, Agriculture and Innovation in The Netherlands has granted €800,000 via the “Innovation for Public Security” program for the development of this joint solution.
Digital espionage threat is increasing, protection lagging
The social and economic impact of cybercrime is increasing, as is the demand for an effective protection against cybercrime. The attack methods of the digital spy have become more sophisticated, with increasing reports of very specific and targeted attacks. Traditional protective equipment such as intrusion detection systems, firewalls, virus scanners, and log analyzers offer inadequate protection.
The social and economic impact of cybercrime is increasing, as is the demand for an effective protection against cybercrime. The attack methods of the digital spy have become more sophisticated, with increasing reports of very specific and targeted attacks. Traditional protective equipment such as intrusion detection systems, firewalls, virus scanners, and log analyzers offer inadequate protection.
More...
Langganan:
Postingan (Atom)


















