Search This Blog

Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Thursday, 28 November 2013

Facebook Wants to Listen to Your Phone Calls





App requires users agree to be monitored by microphone at any time without their permission


Cellphone users who attempt to install the Facebook Messenger app are asked to agree to terms of service that allow the social networking giant to use the microphone on their device to record audio at any time without their permission.

As the screenshot below illustrates (click for enlargement), users are made to accept an agreement that allows Facebook to “record audio with the microphone….at any time without your confirmation.”

Sunday, 23 June 2013

Oversharing: Facebook accidentally leaks six million users’ data





Facebook says that it is “upset and embarrassed” after six million users’ phone numbers and email addresses were accidentally shared with their online contacts.


The bug – which revealed the private information of other Facebook users when someone downloaded their own personal data onto their hard drive – existed for more than  year, and was uncovered by the site’s White Hat Program, in which independent security experts are rewarded with bonuses for detecting network vulnerabilities.

Facebook disabled the Download Your Information tool, through which the data was obtained, for 24 hours last week without warning to fix the issue, before acknowledging the existence of the bug on Friday evening.

“We currently have no evidence that this bug has been exploited maliciously and we have not received complaints from users or seen anomalous behavior on the tool or site to suggest wrongdoing,” Facebook reassured users on its blog.

While some users in the comments section underneath applauded the network for voluntarily admitting the existence of the design flaw, others said that they had contacted legal counsel, dissatisfied with a mere apology (Facebook sent an email informing those affected that their account had been compromised).

The company – which has more than 1.1 billion users – says that the vast majority of the numbers and emails was shared with no more than one other person.

Facebook is one of a number of leading US tech companies in the spotlight after security expert Edward Snowden leaked documents that showed that it is a part of the National Security Agency’s (NSA) PRISM program, which collects extensive personal data from millions.

But the social network denies that the NSA has direct access to its servers, and says that it provided US authorities with personal data from 18-19,000 individual accounts in the second half of last year, each time after a substantiated request.

The company has said that it protects its members’ data “aggressively”.


RT



Saturday, 8 June 2013

How to Keep the NSA at Bay: The Tricks From Privacy Experts





Do government surveillance disclosures have you fearing Uncle Sam’s reach? Winston Ross looks at PGPs, secret phone apps, and burners like The Wire to cloak your digital trail.


It’s a fairly safe bet that most people are in one of four camps about all this National Security Agency-spying-on-Americans business: uninformed, apathetic, pissed off, or paranoid.

For the uninformed, it’s probably a good time to get up to speed. Before you know it, Barack Obama will personally be hiding in your closet.

For the apathetic, Dude, WAKE UP: You think because you live in the suburbs and you work at an insurance company that Big Brother will never come for you? What about that affair with your office secretary last year? What if her brother gets caught up in some kind of sting operation and they check his phone records and then her phone records and then police show up at your door asking why you called her 50 times last week, while your wife is sitting in the living room? What if they transpose a digit or two and mix you up with a suspected terrorist and break down your door in the middle of the night and shoot your dog? OK never mind, just flip back to The Bachelor.

For those of you either pissed off or paranoid, it’s time you understand that there are plenty of ways to cloak yourself from Uncle Sam, especially if they’re not already parked in a white van outside your apartment building (if that’s the case, say even the most clever privacy advocates, you’re probably fucked).

But wait, you hardly ever use the Internet? Your digital trail is pretty small? Skip on over to MyShadow if you believe that nonsense. There, you can find out exactly what kind of a shadow your computer and mobile-phone usage casts. It’s pretty scary and fascinating.

For those of you still understandably freaked out: If you just want to avoid getting caught up in the dragnet, having your phone/email/search history handed over by some spineless attorney at Verizon or Google or Facebook, there are ways to hide from Uncle Sam:

Encrypt yourself. If you’re using Facebook and Gmail in the same Pollyannish fashion that most of us do, you gotta wrap that up. Get to know “E2E” (end to end) encryption, says Dan Auerbach, staff technologist at the Electronic Frontier Foundation. It doesn’t mean you have to find some obscure email provider and kiss your (online) social networks goodbye, but it does mean if you want to have super-secret communication with certain super-secret people, you both must install software such as OTR to be all stealthy about it. Which software depends on which operating system and device you’re hoping to cloak, of course, but all that info is a few clicks away. “It’s very easy to use,” Auerbach tells The Daily Beast.

PGP it. A slightly beefier encryption option: PGP, short for “pretty good privacy.” That refers to software that can encrypt chat communications, emails, and more. Symantec offers one kind of PGP software, but there are many more options out there. Just remember that both sneaky users have to be using it, or it’s pointless.

The goal of all these tactics is to make it hard for the government to get you.
Make secret phone calls. Phone calls are a little tougher, Auerbach says. There once was a cool app called RedPhone that could encrypt phone calls, but it’s no longer being maintained. Nowadays, the best bet is probably Silent Circle, which last October released a “surveillance-proof” smartphone app that lets people make secure phone calls and text messages. The company has released a data-transfer version of the app that lets users send files—photos, spreadsheets, blueprints—from one user to the next. The user can set a nifty timer that “burns” whatever’s sent from both devices after five minutes, or however long you want it to be, Bond-style.

Go even deeper. If you’re already under the microscope, doing whatever you’re trying to secretly do without detection is going to be pretty difficult. Most of what everyone’s in a tizzy about at the moment is the kind of broad, dragnet-style spying where the government gobbles up huge data banks and mines through them for links and clues. But if you’re foolish enough to press on with your evil plans anyway, three words: anonymize, anonymize, anonymize.

Tor is a good place to start. It’s a free software that routes your communication through a series of intermediaries, explains Smari McCarthy, executive director of the International Modern Media Institute. It cloaks virtually everything you do on the Web: watching porn, buying drugs on Silk Road, stalking your ex’s Facebook page, watching porn, watching porn in one window while stalking your ex’s Facebook page in another, and so on.

Get a burner. If you don’t know what a burner is, go watch all five seasons of The Wire and then come back and finish reading this. (It’s great television.) If the NSA really wants to find out what you’re doing, they can make like a hacker and just break right into the software of whatever device you’re on using what’s known as a “zero-day exploit.” The only surefire way to prevent that is to be constantly changing up your devices.

The safest way to use a burner is not for very long, but buying a new cellphone, laptop, or tablet once a week can get expensive. If you want to hang on to the same one, advises Nicholas Weaver, a researcher at the International Computer Science Institute in Berkeley, Calif., just be sure to take it to a crowded place every time you use it and don’t bring any of your other devices with you. If the government matches up your burner use with a ping from a cellphone tower to your regular phone, you’re screwed.

More on that, from Weaver, here.

Cover your tracks.

If you stay logged into Facebook (like most of us do,) then every single time you visit a Web page with a “like” button on it, that Web page is tattling back to Facebook that you just went there, Weaver says, which means when the government can just subpoena Facebook records to figure out where you’ve been. Logging in and out all the time is a nuisance, of course. But so is having a SWAT team rip up your apartment. So at least set up your Web browsers to clear cookies all the time. That’s a start.

Check out Tails. It’s a little piece of software that can live on a thumb drive or DVD, and it can boot your whole operating system from any computer, anytime. So you can set it up with all the encryption software you want and it’s all pre-loaded.

OK, am I cool now? Probably not. If the government wants to get you, they’ll get you. The goal of all these tactics is to make it hard for the government to get you, hard enough that if they really want to muck around with your life, they’re going to have to invest in enough resources to sneak past the firewalls.

“What you can do is try to make it more expensive for somebody such as the NSA to monitor you successfully,” McCarthy told The Daily Beast. “If you keep raising the price, they’re either going to have to commit to targeting you as an individual or accept that they’re just not going to get your stuff.”



 Winston Ross

Tuesday, 12 February 2013

CIA Admits Full Monitoring of Facebook and Other Social Networks




Most people use social media like Facebook and Twitter to share photos of friends and family, chat with friends and strangers about random and amusing diversions, or follow their favorite websites, bands and television shows.


 But what does the US military use those same networks for? Well, we can’t tell you: That’s “classified,” a CENTCOM spokesman recently informed Raw Story.

One use that’s confirmed, however, is the manipulation of social media through the use of fake online “personas” managed by the military. Recently the US Air Force had solicited private sector vendors for something called “persona management software.” Such a technology would allow single individuals to command virtual armies of fake, digital “people” across numerous social media portals.

These “personas” were to have detailed, fictionalized backgrounds, to make them believable to outside observers, and a sophisticated identity protection service was to back them up, preventing suspicious readers from uncovering the real person behind the account. They even worked out ways to game geolocating services, so these “personas” could be virtually inserted anywhere in the world, providing ostensibly live commentary on real events, even while the operator was not really present.


When Raw Story first reported on the contract for this software, it was unclear what the Air Force wanted with it or even if it had been acquired. The potential for misuse, however, was abundantly clear.

A fake virtual army of people could be used to help create the impression of consensus opinion in online comment threads, or manipulate social media to the point where valuable stories are suppressed.

Ultimately, this can have the effect of causing a net change to the public’s opinions and understanding of key world events.

Wired.com published an article how US spies are making investments in the Company In-Q-Tel in order to monitor your blogs and read your tweets.

In-Q-Tel, the investment arm of the CIA and the wider intelligence community, is putting cash into Visible Technologies, a software firm that specializes in monitoring social media. It’s part of a larger movement within the spy services to get better at using “open source intelligence” – information that’s publicly available, but often hidden in the flood of TV shows, newspaper articles, blog posts, online videos and radio reports generated every day.

Visible crawls over half a million web 2.0 sites a day, scraping more than a million posts and conversations taking place on blogs, online forums, Flickr, YouTube, Twitter and Amazon. (It doesn’t touch closed social networks, like Facebook, at the moment.) Customers get customized, real-time feeds of what’s being said on these sites, based on a series of keywords.

“That’s kind of the basic step – get in and monitor,” says company senior vice president Blake Cahill.

Then Visible “scores” each post, labeling it as positive or negative, mixed or neutral. It examines how influential a conversation or an author is. (“Trying to determine who really matters,” as Cahill puts it.) Finally, Visible gives users a chance to tag posts, forward them to colleagues and allow them to response through a web interface.

In-Q-Tel says it wants Visible to keep track of foreign social media, and give spooks “early-warning detection on how issues are playing internationally,” spokesperson Donald Tighe tells Danger Room.

Of course, such a tool can also be pointed inward, at domestic bloggers or tweeters. Visible already keeps tabs on web 2.0 sites for Dell, AT&T and Verizon. For Microsoft, the company is monitoring the buzz on its Windows 7 rollout. For Spam-maker Hormel, Visible is tracking animal-right activists’ online campaigns against the company.


“Anything that is out in the open is fair game for collection,” says Steven Aftergood, who tracks intelligence issues at the Federation of American Scientists. But “even if information is openly gathered by intelligence agencies it would still be problematic if it were used for unauthorized domestic investigations or operations. Intelligence agencies or employees might be tempted to use the tools at their disposal to compile information on political figures, critics, journalists or others, and to exploit such information for political advantage. That is not permissible even if all of the information in question is technically ‘open source.’”

Visible chief executive officer Dan Vetras says the CIA is now an “end customer,” thanks to the In-Q-Tel investment. And more government clients are now on the horizon. “We just got awarded another one in the last few days,” Vetras adds.

Tighe disputes this – sort of. “This contract, this deal, this investment has nothing to do with any agency of government and this company,” he says. But Tighe quickly notes that In-Q-Tel does have “an interested  end customer” in the intelligence community for Visibile. And if all goes well, the company’s software will be used in pilot programs at that agency. “In pilots, we use real data. And during the adoption phase, we use it real missions.”

Neither party would disclose the size of In-Q-Tel’s investment in Visible, a 90-person company with expected revenues of about $20 million in 2010. But a source familiar with the deal says the In-Q-Tel cash will be used to boost Visible’s foreign languages capabilities, which already include Arabic, French, Spanish and nine other languages.

Visible has been trying for nearly a year to break into the government field. In late 2008, the company teamed up with the Washington, DC, consulting firm Concepts & Strategies, which has handled media monitoring and translation services for U.S. Strategic Command and the Joint Chiefs of Staff, among others. On its website, Concepts & Strategies is recruiting “social media engagement specialists” with Defense Department experience and a high proficiency in Arabic, Farsi, French, Urdu or Russian. The company is also looking for an “information system security engineer” who already has a “Top Secret SCI [Sensitive Compartmentalized Information] with NSA Full Scope Polygraph” security clearance.

The intelligence community has been interested in social media for years. In-Q-Tel has sunk money into companies like Attensity, which recently announced its own web 2.0-monitoring service. The agencies have their own, password-protected blogs and wikis – even a MySpace for spooks. The Office of the Director of National Intelligence maintains an Open Source Center, which combs publicly available information, including web 2.0 sites. Doug Naquin, the Center’s Director, told an audience of intelligence professionals in October 2007 that “we’re looking now at YouTube, which carries some unique and honest-to-goodness intelligence…. We have groups looking at what they call ‘citizens media’: people taking pictures with their cell phones and posting them on the internet. Then there’s social media, phenomena like MySpace and blogs.”

But, “the CIA specifically needs the help of innovative tech firms to keep up with the pace of innovation in social media. Experienced IC [intelligence community] analysts may not be the best at detecting the incessant shift in popularity of social-networking sites. They need help in following young international internet user-herds as they move their allegiance from one site to another,” Lewis Shepherd, the former senior technology officer at the Defense Intelligence Agency, says in an e-mail. “Facebook says that more than 70 percent of its users are outside the U.S., in more than 180 countries. There are more than 200 non-U.S., non-English-language microblogging Twitter-clone sites today. If the intelligence community ignored that tsunami of real-time information, we’d call them incompetent.”