Archive for the ‘Technical’ Category

Leaked docs show spyware used to snoop on US computers

Sunday, August 10th, 2014

– Truly, I think we have less and less of a chance to keep our computers secure and our communications private.  If we haven’t been hacked, it is only because there are so many of us and so few hackers/criminals to go around.   Or it’s because we have not sufficiently irritated someone in the officialdom enclosing us.

– Personally, I am considering setting up from scratch (wipe the disk and install a virgin copy of the operating system) one specific computer for my essential banking and financial activities.   This machine would be only used for these activities and nothing else.  I’ll keep its anti-vius and malware defenses fully updated and, when I am not using it, it will be turned off and disconnected.   And, when I do use it, I will shut off and disconnect the other systems on my LAN in case they are infected.

– I’m also considering changing all my passwords as well.

– Paranoid or playing the odds?  I think it is hard to tell but the saying ‘better safe than sorry’ does come to mind.

– And should I not worry so much and simply assume that my government will look out for me?  

– I Don’t think so.  They are too busy doing the bidding the corporate world.  And I am irrelevant to the corporate world useless they can use me  somehow to increase their profits.

– Nope, other than me, nobody else has my back on this.  And those who think it isn’t so will eventually find out the truth the hard way.

– dennis

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

imagesSoftware created by the controversial UK-based Gamma Group International was used to spy on computers that appear to be located in the United States, the UK, Germany, Russia, Iran, and Bahrain, according to a leaked trove of documents analyzed by ProPublica.

It’s not clear whether the surveillance was conducted by governments or private entities. Customer e-mail addresses in the collection appeared to belong to a German surveillance company, an independent consultant in Dubai, the Bosnian and Hungarian Intelligence services, a Dutch law enforcement officer, and the Qatari government.

The leaked files—which were posted online by hackers—are the latest in a series of revelations about how state actors including repressive regimes have used Gamma’s software to spy on dissidents, journalists, and activist groups.

The documents, leaked last Saturday, could not be readily verified, but experts told ProPublica they believed them to be genuine. “I think it’s highly unlikely that it’s a fake,” said Morgan Marquis-Bore, a security researcher who while at The Citizen Lab at the University of Toronto had analyzed Gamma Group’s software and who authored an article about the leak on Thursday.

The documents confirm many details that have already been reported about Gamma, such as that its tools were used to spy on Bahraini activists. Some documents in the trove contain metadata tied to e-mail addresses of several Gamma employees. Bill Marczak, another Gamma Group expert at the Citizen Lab, said that several dates in the documents correspond to publicly known events—such as the day that a particular Bahraini activist was hacked.

Gamma has not commented publicly on the authenticity of the documents. A phone number listed on a Gamma Group website was disconnected. Gamma Group did not respond to e-mail requests for comment.

The leaked files contain more than 40 gigabytes of confidential technical material, including software code, internal memos, strategy reports, and user guides on how touse Gamma Group software suite called FinFisher. FinFisher enables customers to monitor secure Web traffic, Skype calls, webcams, and personal files. It is installed as malware on targets’ computers and cell phones.

price list included in the trove lists a license of the software at almost $4 million.

The documents reveal that Gamma uses technology from a French company called Vupen Security that sells so-called computer “exploits.”

Exploits include techniques called “zero days” for “popular software like Microsoft Office, Internet Explorer, Adobe Acrobat Reader, and many more.” Zero days are exploits that have not yet been detected by the software maker and therefore are not blocked.

Vupen has said publicly that it only sells its exploits to governments, but Gamma may have no such scruples. “Gamma is an independent company that is not bound to any country, governmental organisation, etc.,” says one file in the Gamma Group’s material. At least one Gamma customer listed in the materials is a private security company.

Vupen didn’t respond to a request for comment.

Many of Gamma’s product brochures have previously been published by the Wall Street Journal andWikileaks, but the latest trove shows how the products are getting more sophisticated.

In one document, engineers at Gamma tested a product called FinSpy, which inserts malware onto a user’s machine, and found that it could not be blocked by most antivirus software.

Documents also reveal that Gamma had been working to bypass encryption tools including a mobile phone encryption app, Silent Circle, and were able to bypass the protection given by hard-drive encryption products TrueCrypt and Microsoft’s Bitlocker.

Mike Janke, the CEO of Silent Circle, said in an e-mail that “we have serious doubts about if they were going to be successful” in circumventing the phone software and that Silent Circle is working on bulletproofing its app.

Microsoft did not respond to a request for comment.

The documents also describe a “country-wide” surveillance product called FinFly ISP which promises customers the ability to intercept Internet traffic and masquerade as ordinary websites in order to install malware on a target’s computer.

The most recent date-stamp found in the documents is August 2, coincidung with the first tweet by a parody Twitter account, @GammaGroupPR, which first announced the hack and may be run by the hacker or hackers responsible for the leak.

On Reddit, a user called PhineasFisher claimed responsibility for the leak. “Two years ago their software was found being widely used by governments in the middle east, especially Bahrain, to hack and spy on the computers and phones of journalists and dissidents,” the user wrote. The name on the @GammaGroupPR Twitter account is also “Phineas Fisher.”

GammaGroup, the surveillance company whose documents were released, is no stranger to the spotlight. The security firm F-Secure first reported the purchase of FinFisher software by the Egyptian State Security agency in 2011. In 2012, Bloomberg News and The Citizen Lab showed how the company’s malware was used to target activists in Bahrain.

In 2013, the software company Mozilla sent a cease-and-desist letter to the company after a report by The Citizen Lab showed that a spyware-infected version of the Firefox browser manufactured by Gamma was being used to spy on Malaysian activists.

– To the original:  

 

Cicada 3301

Monday, December 23rd, 2013

– I’ve been a programmer and systems analyst most of my life.  I started with computers the year before I graduated from university (1976) and I’ve loved the work ever since.   Indeed, I threw over the career that my degree in Microbiology qualified me for to pursue the new (then) world of computers.

– I’ve been all around the block with this career, as you might expect, given the years I’ve spent in it.   And I was lucky (or brash enough) to have found my self in widely disparate areas of the field ranging from applications, web-based and database work to the lowest levels of operating systems written in assembly language.   

– But, no matter how much you’ve seen and how far down the rabbit hole you’ve wandered, there’s always more.  The following article brought that home to me clearly.  

– The Internet that we know is not the Internet that actually exists.  Beyond what most of us have seen as either users or programmers, there’s still another entire world out there.

– Digital spelunking, anyone?   I’ve posted links to two articles you may enjoy, below.

– dennis

= = = = = = = = = = = = = = = = = = = = = =

tunnelsWikipedia’s take

A first hand account

Tiles, the NSA and your iPhone – it’s a changing world

Monday, September 16th, 2013

“The agency, according to the documents and interviews with industry officials, deployed custom-built, superfast computers to break codes, and began collaborating with technology companies in the United States and abroad to build entry points into their products. The documents do not identify which companies have participated.”  from ProPublica

– dennis

= = = = = = = = = = = = = = = = = = =

As someone who thinks of himself as a futurist, I tend to keep my eyes peeled for patterns and connections which can, possibly, indicate something about our future.

There are two things going on now which I think are going to conjunct and increase the penetration into our personal lives of the nascent police states that most western democracies are steadily becoming.

The first thing

Is already visibly in motion.  That is the efforts of the American NSA to penetrate everyone and everything in the name of national security; as revealed by Edward Snowden’s documents.

It is now open knowledge that the NSA has broken most of the cryptology that we’ve depended on to keep our personal information safe from prying eyes.

This would include your computer passwords.

NSA

And any files you store in encrypted form.  And any files you send.  And any files you receive in encrypted form.

And, if they have access to your computer passwords, then they have full access to all your files and all your stored e-mail.

If they have all of that, then what do you have?

Bupkis – you don’t have much that’s yours, if they want it.

The criminal hackers of the world would be overjoyed to have that sort of access.   If they did, your computers would be full of malware, trojans and key loggers before you could blink.

I suppose we can just hope that the folks in the NSA that have access to this sort of power are using it exclusively for the public good.

The second thing

Has only just recently come into play.   These are the little devices called “Tilesthat you may have seen advertised.  They’ve been sold on-line now for a few months and the first deliveries are scheduled for winter 2013/2014.  I bought one recently for $18.95 USD out of curiosity.

Tile

Tiles help you find things.  They are about an inch square, made of white plastic, about 1/8 of an inch thick and they have a small hole on one corner so you can tie or attach them to things.  You can also stick them onto things with two-sided adhesive.

They have a non-replaceable battery in them that runs for about a year and they communicate back and forth via the Bluetooth short-range radio.   They come with an application program that runs on your iPhone and the program can help you find  one of your Tiles if you’ve lost it and whatever it is attached to like your keys, or your backpack or whatever.

If, for example, you’ve lost your keys, you fire up the Tile application program and ask it to locate the Tile attached to your keys.

If you are within about 50 to 150 feet or so of your keys (the range varies with terrain), the application program will show you on your iPhone where the Tile (and your keys) are … out in the garage.

Ah!  And then you remember that you laid them down on the work bench when your phone rang as you were getting the groceries out of your car.

One more thing about Tiles.  If you really lose something, like your motorcycle is missing through theft, and you were thoughtful enough to have had a Tile attached to it, you can contact the Tile people and they will put out an alert on that Tile.

Once a Tile has an alert on it, any iPhone in the world running the Tile application program that passes with 50 to 150 feet or so of your sought-after Tile, will silently send a message to the Tile people indicating that it ‘saw’ your Tile and provide the GPS location where it was.

The person carrying the iPhone running the Tile application program that located your Tile won’t even know any of this happened.

So, where ever folks are wandering around with the Tile application program on their iPhones, a quiet and constant search is being made all the time for lost Tiles (and whatever’s attached to them).

So, how does this link to the NSA and future developments?

Well, it goes like this.

The first thing to realize is that the NSA folks are certainly smarter than the average bear.  They could, and probably already have, made something very much like the Tile.  Something that’s a lot smaller, harder to detect, has better range, longer battery life and etc.  Let’s call these special NSA versions NSATiles.

The second thing to recognize is that the NSA already has the technology to break and enter into virtually any computer they want to; including our iPhones.

So, if they wish to, they can populate most of the world’s iPhones with a sweet little bit of hidden software that none of us would know about that does just what the Tile application program does; except for NSA’s purposes.

Mmm. Perhaps, I’m not thinking this through clearly?

Why should they need to insert new clandestine software into our iPhones from the outside?

The recent news from Edward Snowden has also revealed that the NSA has, under national security laws, forced some of the major software companies in the US to install ‘backdoors‘ into their software so the NSA can go in and look at what it wants to even while users of that software think their privacy is secure.   Moreover, the NSA has enjoined these companies to say nothing of this; again under the threat of national security laws.

So, why couldn’t the NSA have pressured Apple to add NSATile detection and reporting software?  They’ve done a lot of this sort of thing already.  And, Apple couldn’t warn us without breaking the law.

In short, there’s no reason why the NSA cannot use our millions iPhone devices to clandestinely scan the world for NSATiles that the NSA is interested in tracking.

And, when your iPhone sees such an NSATile, it will silently “phone home”  to the NSA and report it along with its GPS coordinates.  Nice, eh?

So, we will be an entire world of folks wandering around with iPhones doing the NSA’s bidding and looking for anyone or anything that the NSA wants to track geographically.  Terrorists, demonstrators, spies, packages, books, animals, us … you name it.

And all of us doing NSA’s bidding unknowingly.

Will this happen?

The real question, I think, given that capabilities described already exist, is why wouldn’t it be happening now?   After all, knowledge is power and this is government we’re talking here.

In a related development

There’s a parallel development involving very similar technology, see this article which I just encountered today by coincidence.

It is about something called iBeacon which is part of Apple’s newly released iOS 7 software.

This new iBeacon technology will be coming to a shopping center near you soon and it’s going to be talking to your iPhone as you walk by the stores.  It’s going to be trying to sell  you things.

Personal – 13 Apr 2013

Friday, April 12th, 2013

– My partner, Colette, and I are wrapping up four months in Wellington, New Zealand, this weekend and preparing to spend two weeks touring New Zealand’s North Island by car before we travel across the Cook Strait via ferry to the South island and then by train back to Christchurch.

– I’ve really conceived a love for Wellington.  What a vibrant, beautiful and pleasant a city it is.  We’ve been over most of it on foot and by bus these four months.  We’ve sat in on Parliament’s question and answer sessions, visited endless coffee shops and restaurants, hosted a few friends with us, made use of the libraries, theaters, free concerts, talks and various cultural and ethnic street events.

– Another event that transpired during our time here was that Colette wrapped up 12 years with the New Zealand Ministry of Justice and is now a free agent.

– And yet another event was that it looks like I will finally be paid out for the apartment I lost in Christchurch in the February 2011 earthquake there.  And that money, when it arrives, will augment my income nicely and give me a bit more flexibility which is never a bad thing.

– While I’ve been here I’ve been digging into programming iPhone and iPad apps and I’ve come up to speed nicely.  In fact, just today, I bid my first job to write an app.

– That’s the news.

– Cheers from New Zealand, my friends,

-dennis

 

How to implement Globals in Objective-C – Updated

Monday, February 18th, 2013

– Oh, the embarrassment of premature technical wisdom ejaculation.

– Since I wrote all the stuff, below, I’ve had a big rethink about Globals and realized that the method of implementing them that I’d adopted was seriouly lame.

– I went back and thought through how I’d done it before in the Microsoft Win32 OOP world and I reasoned my way through to doing the same thing here, and, it is sooooo much simpler and way faster.  That’s what I get for cook-booking off someone else’s code without understanding it.

– It still baffles me, when you go searching for it, why the information out there about how to implement Globals in Objective-C is such a dog’s breakfast.

– But, I know how to do it now and I’m going to write it up here and maybe that will aid someone else on a search to answer the same question.

– So, below, you will find my new method and code and the old stuff is gone.

-dennis

*—————————————————–*

Create a class, UtlGen.  In it we put general utility methods that we can call from anywhere.

Create a file, globals.h, where we can declare our globals variables.  In it I have the following line:

UtlGen * g_pUtl;

This creates a pointer to an instance of the UtlGen class.

I want this pointer to be (globally) visible from anywhere in my program so I need to place it outside of any blocks.  I’d also like to put in a place that makes sense to other programmers.  To me, there are two obvious choices.  One is in the main.m file and the other is in the AppDelegate.m file.  Main.m is the first place where execution begin and the AppDelegate.m is the second.   I select the AppDelegate.m file because I think folks don’t generally expect you to mess with the main.m file.

Near the top of the AppDelegate.m file, I import the global.h file like so:

#import “myprogramAppDelegate.h”
#import “global.h”   <— global variables live here.
@implementation myprogramAppDelegate

We also instantiate and release the UtlGen object in the AppDelegate. module.   The very first method called in AppDelegate.m is:

-(BOOL) application( … and so on …

Inside this method, we add the line:

g_pUtl = [[UtlGen alloc] init]; 

This is how we instantiate the UtlGen object and assign its pointer to the global variable, g_pUtl.

In the -(void) dealloc method of the AppDelegate module, we add the following line:

[UtlGen release];

And that’s how we release the object’s memory when the app shuts down.

In the myprogram-Prefix.pch file, I place the following line in with the other imports:

#import “UtlGen.h”

This file contains the precompiled definitions that are visible to all modules.  Importing UtlGen.h here means that the methods (and their prototypes) available in the UtlGen object will be visible everywhere.

Now, we are ready to use any of the methods in the UtlGen object from any module.

Let’s use a hypothetical method called ‘twiceMe’ in the UtlGen object.

In the application, we have a class, someClass, which is implemented in the someClass.m file.  In this file is the implementation of a method, ‘doMath’.  In the doMath method, we will call the twiceMe method of the UtlGen object to double the value of an integer we pass to it.

In the someClass.m file we do this:

@implementation someClass
extern UtlGen * g_pUtl;

-(void) doMath
{
int n = [g_pUtl twiceMe:2];

The extern tells the compiler that the g_pUtl variable has been defined elsewhere (over in AppDelegate, remember?).  In doMath, we call the twiceMe property of the UtlGen object and pass it a ‘2’ and it returns a ‘4’ to us which we place into ‘n’.

That’s it.

 *——————————————————*

A Tale of Two Internets

Friday, February 15th, 2013

– I worked for a company up until a year ago that was heavily involved in e-Commerce.  They are a great group of people and I doubt that any of them would see themselves as adding to the world’s inequalities.  

– But as they say, “No single rain drop see itself as responsible for the flood.

– But they, like all such e-Commerce facilitators, are striving to develop the technology to ‘read’ the customer more and more.  And the quote, below, shows where some of this is going.  And it might not be pretty.

– dennis

= = = = = = = = = = = = = = = = = = = =

“For the past decade, e-commerce sites have altered prices based on your Web habits and personal attributes. What is your geography and your past buying history? How did you arrive at the e-commerce site? What time of day are you visiting? An entire literature has emerged on the ethics, legality and economic promise of pricing optimization. And the field is advancing quickly: last September, Google received a patent on technology that lets a company dynamically price electronic content. For instance, it can push the base price of an e-book up if it determines you are more likely to buy that particular item than an average user; conversely, it can adjust the price down as an incentive if you are judged less likely to purchase. And you won’t even know you are paying more than others for the exact same item.”

– To the original article in Scientific American:

New tech – hotspots

Monday, August 27th, 2012

I encountered a very cool technology today.   A cellular hot-spot.    

This is a cell phone that can access the Internet via the cellular system and which then rebroadcasts the Internet access to other devices around itself via WiFi.

In the case I’ve found, it is an Android HTC  phone, tethered to the T-Mobile network here in the U.S.   The app itself is called “Hot-Spot” and it came with the HTC Android phone.

I’m told that cell providers like AT&T and T-Mobile here in the U.S. are not enthusiastic about the “Hot-Spot” concept and they are working out how to either block folks from sharing their signal or to charge them for the extra devices accessing the Internet via the hotspot.

There are also free-lance apps around (not from the cell phone maker) that can do this but I’ve read that these can be buggy.  One such is “MyWi”.

If you know more about all of this or have corrections to what I’ve posted here, let me know.

Dennis

The greedy are everywhere…

Wednesday, July 4th, 2012

– In the U.S., in Europe, and even here in my beloved New Zealand.

– They put on suits, they carry a briefcase, they do ‘deals’ and it all looks brilliant and magical.

– But, sometimes, someone goes behind the scenes and traces some of this ‘business’ and finds that a lot of it is ‘funny business’.

– What would you think of an investment company that did big deals for the purpose of making profits for their investors and, when the dust had settled, the deals were done and all the contracts and the fine print were all read out and traced – you found out that the bankers and the company’s principals made far more profit from all of the money shuffling than any of their poor investors did?

– I think it stinks.   And yet I also think that many business types live and thrive in just this way and consider themselves brilliant,.  And that they consider the rest of us as just their sheep in need of a shearing and too dumb to know we’re being hard done by.

– This bit of fun happened here in New Zealand though the business itself reached around the globe to London as well.  

– No matter.  In fact, all the better.   The more abstract, the further afield, the less normal people can relate to the doings, the better.   Big money moving in the shadows.

– Here in New Zealand, the National Government, under John Key, a former Wall Street type, wants to sell public assets to raise money.   After reading this expose on the investment company, EPIC, I’ll be most curious to  ‘follow the money’ when the Key government does begin to sell those assets.  

– Who will be doing the deals and who will be making enormous profits from the fees along they way?  Why do I suspect that they will be business types like Key?  Types who are telling themsleves all along the way that the fact that they are getting rich is only incidental to the good they are doing for the country.

– Yeah, right.

– Dennis

– – – – – – – – – – – – – – –

The rather curious case of Epic’s fee payments

(this from stuff.co.nz an opinion piece by Tim Hunter)

OPINION: After years of study, there is growing acceptance that homo sapiens has evolved into two distinct branches. One comprises the vast bulk of humanity, the other comprises individuals known as bankers.

Although superficially alike, the latter can be distinguished by their skin, which is thicker than normal. It also has special properties giving unusual adhesion to most forms of money.

In tests using a drained swimming pool filled with Zimbabwean currency, bankers were found to emerge from the pool with up to 25 per cent more cash sticking to them than the non-banking control group.

Scientists initially hypothesised an epidermal layer of tiny hooks, like Velcro, to explain the effect, but now favour a theory of electro-magnetic attraction at the cellular level.

Edinburgh University’s department of parapsychology is also testing observations that bankers can detect the contents of a wallet within a range of about five metres, even through stud walls.

These attributes are an advantage in financial transactions, and Chalkie reckons there could be something like this going on in an investment structure called Equity Partners Infrastructure Company (Epic). Basically, Chalkie’s study of accounts and documents with small print suggests Epic has paid out millions more in fees to bankers and their ilk than it has to its investors.

– Definitely, you should read more here…

Scrap heap may be last stop for secret slice of Navy history

Monday, April 30th, 2012

– An interesting bit of U.S. Naval history.  It’s hard to imagine all the secret projects that are carried out that we’ll never hear anything about.   Here’s one which the curtains, finally, have been taken down on so we can see what was done.  

– I’m not much for military stuff but I admit I found this fascinating and spent a long time poring through the interior shots of this one-of-a-kind ship.

– Dennis

= = = = = = = = = = = =

A secret chapter in American naval research could soon reach an ignoble close when a rusty barge and its once-classified contents leaveSuisun Bay for the scrap heap.

Slipping through the sea like a black mirage on catamaran legs, the 164-foot Sea Shadow looks like something Darth Vader might fly. It is the world’s only ship built to be invisible, assembled secretly in Redwood City in 1985 by the U.S. Navy and contractor Lockheed Martin at an estimated cost of $50 million.

Sea Shadow’s purpose was to test radar-cloaking technology and other naval engineering innovations. Many of its breakthroughs can be seen in present-day Navy warships.

Even at nearly 30 years old, Sea Shadowremains the most radical ship afloat.

– More…

– Direct to the photos…

 

Supreme Court Shoots Down Warrantless GPS Tracking

Tuesday, January 24th, 2012

The U.S. Supreme Court might have delivered a big blow Monday to GPS surveillancetechniques used by law enforcement.

In effect, the justices ruled that long-term surveillance of a vehicle by attaching a GPS device without an extended warrant is a violation of the Fourth Amendment.

In three separate opinions, the nine justices confirmed that law enforcement’s placement in 2004 of a GPS tracking device on the vehicle of accused drug trafficker Antoine Jones’ vehicle for a period of 28 days constituted a “search,” as defined by previous case law concerning the Fourth Amendment.

The justices differed, however, on the particulars of how the GPS technology was utilized.

A joint FBI-police team in Washington, D.C., had a warrant, but it was only authorized for use within a 10-day period and only in the District of Columbia. Officers waited until the 11th day to attach the GPS device and did so in Maryland, outside of the warrant’s jurisdiction.

Writing for a five-justice majority, Antonin Scalia, joined by Chief Justice John Roberts and Justices Anthony Kennedy, Clarence Thomas and Sonia Sotomayor, believed that further justification was needed before using a GPS device in the situation.

– More…