Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Saturday, October 5, 2013

The NSA, FBI, and Internet Security

Over the past few months we've learned a lot about how the US government looks at its own citizens. We've learned this through the actions of Edward Snowden. He's done us a great service by forcing a conversation that the NSA and FBI didn't want us to have. The NSA lied to the Senate recently by claiming that it never tracked US citizens through Cell Phones. We would never have known about these activities if it wasn't for Snowden.

Snowden was using email to send information back and forth between himself and Glenn Greenwald. Since email is in one of those fuzzy gray areas of the law around data retention and government access to it this has caused a bit of a problem. It make things more difficult Snowden used an encrypted email service called Lavabit. It's encryption was at such a level that when the FBI requested data from it, they were confounded and essentially attempted to blackmail (legally of course) the owner into handing over the encryption key. This would have effectively rendered the service these people were paying for worthless. They were paying to have their email traffic be secured from both public and private entities.

As we hear and more about how the US government has been behaving towards internet security, the more we're learning that the NSA and other US agencies are doing their best to thwart it. They have worked with the NIST and weakened the encryption key they developed. The problem with these backdoors is that if it's there for the "good guys" (whoever that might be) it's also there for the "bad guys" (whoever that might be). This isn't just general encryption keys, it's things that we use every day without using it. Whenever we are using any website that includes "https" we are using a basic encryption protocol called SSL. Think about when you're banking, you see the https. Google now allows you to use this when you send information to and from them. This encryption has also been broken by the NSA. This is our personal stuff and if it's broken by the NSA it can be broken by other people. Now does this mean we're likely to have a rash of new fraud cases or theft cases? No, as it's been compromised for some time. However, people do know about it now and this of course is a greater cause for concern.

What can we do about this? Well, first, look into more secure encryption methods. I wouldn't be surprised if Google and applications like HTTPS everywhere will change their algorithm in result. Second, contact your representative and your senator. I'm lucky my senator in Oregon is very vocal (Ron Wyden) not everyone is so please help inform your leaders. Third, buy from companies that you know haven't given up data to the NSA, don't use Facebook and the like and basically try to follow the great writing that Sean did several months ago over on KBMOD. He nailed it then and it's even more pressing than before to keep up with security.

Friday, June 14, 2013

Why now in Syria?

Today Obama announced that we're going to begin military aid to the Syria rebel group Supreme Military Council. Supposedly, this is because the Syrian regime has used chemical weapons on rebels and civilians. Despite the fact that we've repeatedly condemned Russia for seeking to aid the Syrian regime, we're going to do the opposite and arm the opposition which has a massive group of hardline extremists that will likely turn against the US as soon as they are in the position to do so. Furthermore, there are rumors, according to the UN, that the Syrian rebellion has also used chemical weapons. This combined with the fact that 93,000 civilians have been compared to the 150 killed with the chemical weapons usage makes me think that this is a shaky argument at best. I certainly hope we don't find ourselves arming a group that also used chemical weapons.

Before this announcement and continuing after, John McCain has and is calling for a "No Fly Zone" in Syria, while the Obama administration has declined to implement one because of Syria's air capabilities. However, it's been effectively confirmed that Israel has in the past bombed Syria. A no fly zone would preclude Israel from bombing Syria in anyway shape or form. In fact, when Russia wanted to enact a no Israeli fly zone, through providing anti aircraft weapons (only capable of hitting planes), the US condemned this as aiding the Syrian regime. It's also likely that those same systems would have been able to hit the majority of US planes as well as the Israeli Air Force, so we were as much protesting anything that would have prevented our Air Force from dominating the sky above Syria.

Based on the interviews I've heard, I don't think the end result in Syria is going to be a beneficial one for the US unless something magical happens. Where we arm the right people and they are the only ones we help and they automagically kick the Syrian Regime out of the country. It's not going to happen. Even after Assad is overthrown (if he is) it's likely that Syria will continue to be consumed by a civil war, which will likely be even more of a religious civil war than it is now. Now it's as much ethic based as not.

On Reddit, there's a meme that's arguing that the reason we entered Syria now is an attempt to distract the US media from the NSA and Prism debacles. This could be on the right trail. The news is dominated by the fact that we're supplying aid to the rebels, what the implications of these actions will be and what won't be. I think getting involved in another conflict in any manner isn't good for the US, especially if the side we backs fails, which it is still likely to do so. We've lost any moral authority we had with Russia in an argument regarding supplying weapons to either side.

I do not think that this will pull people away from the NSA issue, we're going to keep seeing it. I'm going to keep writing about it - I just wanted to post something about the hypocrisy of the US entering the Syrian civil war. The big story for this week and next week is still the NSA and PRISM. We are going to continue seeing new developments in this area and we need to keep our eyes on it. If we don't keep pushing this, it will become 'ok' through passive consent. That's not acceptable.

Monday, June 10, 2013

NSA and Edward Snowden

Today saw the unveiling of the NSA leaker, Edward Snowden, a highschool dropout that worked his way through sheer capabilities as a programmer. To me this guy is pretty amazing. He cares about the people that he could have put in harms way, he made sure that he did not release any information that would put anyone in harms way, even though he had the capabilities. He learned from Bradley Manning and worked to ensure there would be no risks of physical injury. He felt that these actions violated the constitution and decided to expose these deeds to the public even though he knew his life was over. He believes he's likely to be targeted by the US government or an agent, such as a member of the Triad gang (he's in Hong Kong), to be executed.

Not only he is clearly concerned, but the media seems to think that this is also true. My roommate was watching ABC news with Diane Sawyer and during one segue she mentioned that he may have left because he feared for his life and was likely in danger. Think about it. It's publicly acknowledged by our press, that it's likely a whistleblower might be killed by the US government. This is a US citizen that has a family history of serving (father a member of the coast guard and mother a legal clerk) the US government. He is afraid for his life because he believes that the US government would murder him. If he dies and his body is found the blame will automatically fall upon the government. Edward will not be able to answer phone calls, call anyone, and is essentially on his own to make it to a country that has no extradition treaty with the US. This is a travesty - the fact that many people believe this man is going to die within the next few weeks - killed by his own government without his right to a trial.

Why does what he said matter? A lot of people are talking about it being only Metadata - here's an excellent article explaining what would have happened if the British had meta data during the revolutionary war. It would have ID'd Paul Revere as a likely revolutionary based on his association. Knowing nothing else about him other than a few clubs he and 254 other people in Boston were members of it was possible to deduce the entire social network and who was at the center of the networks.

As I mentioned in my last blog post this network analysis would have caused the changes in my Facebook network to raise some red flags. I suddenly move to Europe (I didn't list Eindhoven has my city of residence it would have been inferred from my friends), some of my first connects in Europe on Facebook were 2 Colombians, 2 Pakistanis, an Iranian, and a Turk. These changes represented a major shift in my circle of friends. I had few non-americans as friends and no Iranians or Pakistanis in my network. Using the full history of my data they wouldn't have found much except that I liked to drink and wrote drunk posts on Facebook while in college. However, it's likely I would have remained someone to keep an eye on, and since then I've written numerous posts about Anonymous, LulzSec and other controversial topics.

Anyway, it's important to keep this in mind when selecting the companies you decide to store your information with, even if it's "only" metadata. Where you go, who you talk to, and what you do online are all representations of you and a lot of information can be gleaned from that.

What can we do? Vote all the bums out of office next go around for one. Start companies that only hand over encrypted data that the end users are the only ones that can decrypt it. Educate your friends, family, co-workers, and anyone politically minded you know. We need to drive change otherwise this will continue and will only get worse. At what point do we need to start worrying that the NSA/US Government will start killing your friends because of who they talk to and what they believe?

Thursday, June 6, 2013

NSA, Phone Records, and access to data systems

NSA - Nothing to See Anywhere around here. The past two days have been bad for the Obama administration for both leaks and for privacy concerns. It was leaked yesterday to the Guardian's reporter Glenn Greenwald whom a lot of people in the US aren't fans of because he sticks to his morals regardless of which party is in power. This leak showed something that really shouldn't be that big of a surprise to anyone. In fact, Senators are all like, what's the big deal this has been going on since 2007. This was originally just AT&T that was wrapped up in this, but everyone suspected other telecoms were involved. After that had come to light congress retroactively gave immunity to the telecoms, despite an ongoing law suit from the EFF - which was dismissed, although EFF filed another shortly their after.

Today was another turn of events where operation PRISM was unmasked, by both the Guardian and Washington Post. This system has direct access to major technology companies servers including Google and Facebook, although both companies deny this. Superficially, PRISM is intended to filter through to a majority of foreign based data. In this case it's seriously the slimmest majority - only 51% - a majority though, although in the US Senate you'd never know.

How are these things possible? Two major reasons, the Patriot Act and the "Secret" FISA Court. I use quotes around "Secret" because it's as "secret" as the drone program. However, we don't know what decisions are being made, we don't know what is being taken before the court, and we have no idea what sort of "do process" standards have been implemented in this court. If it's anything like the drone program it's likely just a few people sitting in a room talking about how bad terrorism is and data like the above to determine the guy needs to die. It's no way to run a democracy.

With the combination of the data in our phone records and our internet usage the NSA can create a massive time based network of connections between both Americans and Foreigners. Abrupt changes in the make up of a persons network with people from countries of interest likely flag them as a risk for interacting with Terrorist. Additionally, if a new pattern was detected the NSA would likely go back and look at historic data to try to understand why this new pattern arose and what they could do to predict future shifts in networks towards engaging with these groups of people. It would also lead the NSA to create models that could indicate how likely someone is to develop behavior patterns of terrorists after their network shifts from one sub group to different subgroups. Furthermore, it's likely that this information would be even more of interest if there's a full shift of members of that person's network towards more potential extremists.

We need to work to change this. The Senate knew about this and plans to hold closed door meetings to discuss it. These discussions should be public not behind closed doors. It's a disgrace.

Tuesday, April 24, 2012

Free-market, Small Government and Regulations

The free-market has been used to argue against regulations and for small government for years. However, I believe that the major supporters of using the free-market argument are disingenuous in their application of the argument. In addition, the free-market is a flawed theory which needs to be revisited by neoclassical scholars and adjusted.

The free-market theory comes from the idea that there is an invisible hand that guides the market towards equilibrium between supply and demand. This assumes that once the equilibrium is hit it will stay at that point until there is some shock to the system which would find a new equilibrium. Each time that there is a shock, the invisible hand would push the market into a new equilibrium. This idea came as a side comment in the Wealth of Nations. This idea has become enshrined in the minds of neoclassical economics in a manner that Newtonian Physics was presumed to be accurate. In both cases the theory is incorrect. Relativistic Physics has replaced Newtonian, but in Economics the free-market is still the prevailing mechanism for policy creation. There has been no evidence for an invisible hand at all. In fact Metcalf created the theory of a networked economy which argues that the value of a good becomes more valuable as more people use it. I've mentioned this in the past. Essentially, this will prevent any equilibrium from every being found as the price can increase and people will still adopt the networked item because it's becoming more valuable to the user. Or the price can remain constant even when it should drop for other factors such as a reduction in cost of production. A perfect example is the iPhone. According to research Apple has a whopping 72% margins on the iPhone, even if production was moved to the US Apple would still make 42% margin on the iPhone. There also is an over production of the iPhone and strong competition, which would indicate that the iPhone should drop prices as they are capable with that large of a margin. This market has a great deal of competition and has a large number of companies producing, which indicates that it Apple should be under pressure to drop prices. However this isn't happening because of the networked value of the iPhone. There are a huge number of apps for the phone, the apps are high quality and the product works well with other iPhones. The market has had no impact on the cost of the iPhone.

However, free-market champions would look at any effort to change the labor practices of Apple as wrong headed and regulation that isn't required. The Market isn't demanding any change to labor practices because the market can bear the current prices and the demand indicates that people don't care about labor practices. However, it's well known that there are no alternatives to Apple's iPhone that are produced in an ethical manner. So voting with your money wouldn't actually work here. The problem arises because there is something of a monopoly in the manufacturing of the smart phones in FoxConn. In this case there is a market failure. Which is something that neoclassical theorists argue cannot occur. The market cannot send a signal to firms because there is no mechanism in which the market could send a signal. This is can be understood if you view this industry as a networked economy. Where you see the ties between manufacturers and handset companies, which would show a massive connection to FoxConn.

Efforts to regulate the manufacturing of devices have been argued as the reason for moving the manufacturing to other countries. However, this is not the case in the case of Apple, as they would still have huge margins. It's because the company is attempting to maximize profits, not reduce costs to be profitable. The same arguments have been used to argue for smaller government. Saying that since there are no market failures the government should not intervene in the industry.

The unfortunate thing is that these arguments immediately disappear when it comes to protecting the profits of record industries. The same free-market advocates then move to argue that intellectual property must be protected. Essentially, creating protection for a specific product through IP causes a market failure and prevents the market from operating at its most efficient because there are not other competitors in the market. Creating IP requires a huge regulatory framework from the mechanisms of registering, logging complaints and prosecuting actors that infringe on the IP.

This type of industrial policy is typically derided by the small government fans, as it is a type of regulation that selects a "winner" (IP owners) over "losers" (non IP owners). Which may be fine. However, whenever this selection pushes our government to select a winner (Music) over the fastest growing, possibly only growing, part of our economy (internet based companies) there is a serious risk to the future. As I've mentioned before these laws represent huge risks for innovation.

These laws are SOPA and PIPA, which I've discussed extensively. However, the next round of internet regulations come in the form of CISPA. This bill, which requires allows companies to share extensively with government agencies. This type of sharing of user data and information about the activities going on at the company would not go over very well from the the free-market advocates if this was a request for data about customer data for car dealerships or steel mills. Essentially, this is going to increase the cost of doing business in the US. This may prevent companies from working in the US and prevent innovation. If I was to create a company that dealt with social data I would not want to do so after the passing of this bill. It would be likely that I would be blackmailed into giving the government data about my users that I had no desire to give them.

The internet is the perfect example of a networked economy. Facebook's value comes from the fact that it has a huge user base. This is true for Google, Amazon and Instagram (List of companies that support CISPA). Without the users the services is literally worthless. With the users a company without any revenues can be worth $1 Billion (Instagram). The difference between this bill and other bills like SOPA and PIPA is that the agreement is bidirectional. The government will likely help Facebook and Google fight Chinese attacks and give information to each other about the activities of online hacktivist groups like Anonymous. It is likely that 4chan will end up giving over IP data and other information related to anonymous and Anonymous users.

This is regulation that the internet doesn't need and will stifle innovation. The government already has these powers, which maybe why the Obama administration is opposed to CISPA. It is also ironic that Obama plans on sanctioning countries that use Tech to abuse human rights specifically committing genocide. A whistle blower has recently announced that the NSA has intercepted 20 TRILLION emails and likely has copies of all of these stored somewhere. The passing of CISPA and any other law of similar persuasion  would likely protect companies like AT&T from future lawsuits for being complicit with these activities.

For devotes of the Free-Market these laws create market distortions and will cause serious harm to innovation on the internet. For people that understand networked economies, this will greatly undermine the value of these networks as users will likely change their behavior to mitigate the amount of information the Government can compile on them. CISPA and its sister laws SOPA and PIPA represent big government actions attempting to control and regulate industries that do not need to be regulated. In this case there is no market failure that needs to be addressed. Privacy is something that the users have been pushing for and Facebook and Google have steadily improved on those accounts. Surprisingly industry is doing a decent job at regulating itself. Finally, regulations being pushed by advocates of small government and free-market smack of hypocrisy and a lack of understanding. These laws require a deep understanding of the internet and how the market of the internet works. Without this understanding terrible laws will be passed that will damage our privacy and freedoms. For the issues that this law would protect from there are other methods that could be employed to gain the desired results without passing laws.

Contact your congressional members to fight against this bill.

Wednesday, February 22, 2012

Anonymous a "stateless" terror organization?

According to the Wall Street Journal the NSA is seriously considering labeling Anonymous a stateless organization. The Atlantic has some good discussion about this topic as well. I think this is something we should all be seriously concerned about. This has the serious problem of becoming something beyond scope like the War on Drugs or the War on Terror. These both allow the US to pursue military objectives in countries across the world for various different reasons. The War on Drugs mostly impacts the US, Mexico and large chunk of South America while the War on Terror allows the US to do the same in the US, nearly all of the Middle East and parts of Asia such as Pakistan and Afghanistan.

Now the US government is afraid that Anonymous was going to eventually target the US electric grid. This seems out of the scope of Anonymous for a few reasons, one they outline as that people's lives depend on the electric grid. Additionally, there's serious problems since Anonymous is much more dispersed than some of the other organizations that the US has focused on it will be difficult to determine something that was actually caused by Anonymous or something that some one claims was conducted by Anonymous.

It is likely that someone could claim to be a part of Anonymous and that they did an attack against something as serious as an electric grid but it will be difficult to prove that they did. Especially when there is a great deal of IP spoofing (this is a way of making a computer think your IP address (where you are on the physical internet connection this comes from your internet service provider) is a different IP address) going on and people will claim to be part of a group when they aren't.  I think that this will open a large can of worms.

Additionally, it brings up other concerns one that may impact me directly, will the NSA start looking at bloggers that are sympathetic to the ideas of Anonymous, using the web as a protest tool. If so then I've been overly sympathetic. That's not all though, during the SOPA/PIPA protests Anonymous sent out tweets with links that turned people into Low Orbit Ion Cannon (a software program) that commits Distributed Denial of Service attacks (brings down a web page). Essentially, even without being a part of Anonymous you become part simply by clicking a link on Twitter.

Are these people now linked with Anonymous and liable for any action the group does? These are serious questions that really need to be addressed if an announcement is made that Anonymous is a "stateless" organization. This also makes it very important to understand what protesting on the internet is allowed and what is not allowed. Sure Anonymous does steal information, but the information they steal seems to be fairly unsecured and not encrypted. It's time to have a real talk about all this means.