Atlas of Surveillance
atlasofsurveillance.org
atlasofsurveillance.org
this is the most scary part.
While the programmes could no longer be seen or heard, the screen still functioned as a surveillance device, as after Winston is taken into the Ministry of Love, the audio of his meeting with O'Brien with the telescreen "off" is played back to Winston.
A legal mandate avoids the race-to-the-bottom trend.
Often commonweal is a better guiding light than "choice".
https://en.wikipedia.org/wiki/Race_to_the_bottom
Sophie Zawistowska was offered a choice. Did her utility benefit by it?
Whether that data is accessible by law enforcement is a completely separate issue. A proper solution would be limiting this access and requiring consent and transparency, not removing infrastructure options because you think you know better than everyone else about what's best for them.
Your proposed (and grossly insufficient) remedy is one form of legal mandate.
I'd strongly commend Shoshana Zuboff, Hanna Arendt, and Paul Baran, amongst numerous others:
"On the Engineer's Responsibility in Protecting Privacy", Paul Baran, 1968:
https://www.rand.org/pubs/papers/P3829.html
Another view was expressed by AI pioneer and Nobel Laureate (economics) Herbert Simon:
"The privacy issue has been raised most insistently with respect to the creation and maintenance of longitudinal data files that assemble information about persons from a multitude of sources. Files of this kind would be highly valueable for many kinds of economic and social research, but they are bought at too high a price if they endanger human freedom or seriously enhance the opportunities of blackmailers. While such dangers should not be ignored, it should be noted that the lack of comprehensive data files has never been the limiting barrier to the suppression of human freedom. The Watergate criminals made extensive, if unskillful, use of electronics, but no computer played a role in their conspiracy. The Nazis operated with horrifying effectiveness and thoroughness without the benefits of any kind of mechanized data processing."
https://pdfs.semanticscholar.org/a9e7/33e25ee8f67d5e670b3b7d...
There is, of course, one slight problem with Simon's argument: The Nazis did make heavy use of mechanised data processing, provided and supported by IBM. Edwin Black documents this meticulously in his book IBM and the Holocaust:
Infrastructure and third-party vendors need to be managed against risk. This is no different than using Gmail vs your own hosted email box. Same with a million other services. Are you claiming that they should all be shutdown now?
Legal issues need to be fixed by legal solutions, not by disallowing the service from existing.
It would go against this and lots of legal precedent supporting it, so definitely an uphill battle.
It's the difference between surveillance and mass surveillance. The latter is the bigger problem and warrants will solve it.
And most importantly a paper trail that can be picked apart in court.
....
Wrapped in a weatherproof container roughly the size of a watermelon, each ShotSpotter sensor combines microphones, hardware, software and a clock linked to the Global Positioning System, which uses satellites and radio navigation to pinpoint precise times and locations.
In the cacophonous urban environment, sensors are calibrated to ignore all sounds except for those that most closely match the “impulsive” sound of an explosion, said James Beldock, a senior vice president for ShotSpotter.
“It’s a very, very sharp wave,” Beldock said. “No other sound works that way.”
The blast of a gun is different from other explosive sounds because it is directional, meaning that the noise changes its frequency as the bullet moves through space. A person may hear a gunshot a half-mile away if the gun is fired toward him. But a person 200 yards away may hear nothing if the gun is fired away from him.
Once sensors register a potential gunshot, they transmit the data to the ShotSpotter computer network for analysis. The computer server compares the time that each sensor logged the sound to calculate the likely location of its source, a process of triangulation and multilateration.
“That sound will reach a sensor 100 yards away at a different time than it reaches a sensor 200 yards away,” Beldock explained.
The more sensors that capture the noise, the more accurate the location. A sound detected by 10 sensors can be located to within two feet, he said.
The computer system also classifies the likely source of the sound based on its sharpness, frequency and consistency across sensors. This is critical, because other impulsive sounds — including fireworks, backfires and helicopters — can also trigger the remote sensors.
....
> The blast of a gun is different from other explosive sounds
> “It’s a very, very sharp wave,” Beldock said. “No other sound works that way.”
> Other impulsive sounds — including fireworks, backfires and helicopters — can also trigger the remote sensors
They're calibrated just to hear explosions, and in fact _no other explosive sound works that way_, but then they're triggered by...helicopters? Which are not propelled by explosions?
All that to say that helicopter blades can create similar pressure waves as gunshots. Supersonic bullets passing overhead make very distinctive sounds, but the noise of the gunshot itself is much less unique. I never really got comfortable living in places with a large number of cars that backfired a lot, because I couldn't easily tell it apart from gunfire.
Define "explode".
Any chemical reaction that produces more outputs than inputs by volume can explode if you trap that pressure.
The flame front on gunpowder isn't fast enough to make a pressure wave that sounds like a bang if there's nothing to trap the combustion byproducts (like the space behind a bullet as it travels down the barrel).
You can harmlessly set off gunpowder (old school black powder and equivalents) as a party trick. Don't try that with Semtex.
I'm not an acoustics expert but I think it's going to be fundamentally very hard if not impossible to build a shotspotter type system that both works in an urban environment (where sound bounces off all sorts of things) and doesn't get a false positive from things like motorcycles backfiring.
Next time you're near a helicopter in flight, notice that the "whap whap whap" chopping sound is more prominent at certain angles. Because it's constructive interference the pressure wave can be quite large and sharp... just like a gunshot, I guess?
> Only two seconds before a gunshot and four seconds after a gunshot are recorded, the company claims.
If they were recording full conversations on purpose without permission that would expose a lot of liability, and unless every customer is in on it (I doubt these distributed public entities are coordinated) I think there would be some documented story by now.
[0] https://splinternews.com/is-nyc-s-new-gunshot-detection-syst...
(In Baghdad prior to 2009) https://venturebeat.com/2009/04/29/shotspotter-refines-gunsh...
(2013 Washington, DC article with tech overview) https://www.washingtonpost.com/investigations/shotspotter-de...
(Baltimore, MD 2018 installation) https://www.baltimoresun.com/news/crime/bs-md-ci-shotspotter...
Recent DC news https://wtop.com/dc/2020/07/court-docs-officer-was-called-aw...
"The D.C. police’s Shotspotter system was turned off for the [Fourth of July, 2020] holiday, presumably because fireworks would have set it off constantly."
Netsential.com [1] was a Houston-based software dev, hosting, and cloud provider. I lived most of my life in Houston, and they are loosely connected to an old ISP called Texas.net and a more recent data center company called Data Foundry.
Something like 630+ websites were hosted by Netsential. All of them DHS fusion centers, multi state intel sharing groups, police training outfits, etc. The source code leaked as well for all of these websites. Extremely poorly done ASP.net rigged together "web apps" with CSV files being used for the backend data tier.
Here is the most fascinating thing. 7 years ago, as part of the Edward Snowden document dump, a single page screenshot of an list of the Top 16 addresses the NSA was targeting in North America appeared.
#16 on that list [2], codenamed WAXTITAN, was the IP address 64.9.146.208, which belonged and belongs to Netsential/YHC Corporation [3].
The question now I think is who in the world are these other 15 IP addresses, all of which are scattered around typically rural North America?
[1] - netsential.com
[2] - https://snowdenarchive.cjfe.org/greenstone/collect/snowden1/...
[3] - https://blog.12security.com/darkness-at-noon-01-waxtitan/
I do not currently work in law enforcement or intelligence, but for various reasons from some years ago to the present I have been a member of one of the fusion-center-type communities which Netsential hosts. A small amount of my personal information is included in the breach as a result, but of course, this is far from the first time that's happened to me.
I think you have somewhat of a misunderstanding about Netsential's service offerings. While they do provide physical hosting, that is not their primary product, they are not used for "managing the physical servers (think Dell blade computers for instance) that these websites ran on top of" as you say in the blog post. This is only incidental. Their primary product is the software, which is not very good from either a code quality or user experience perspective, but is reasonably unique in its capabilities. They offer a completely "turnkey" solution, including for example a telephone technical support/customer service line for users of the portals that they staff and handles routine things like password resets.
They're not a hosting company, they are primarily a SaaS operation that also does some custom software development.
So it's not at all true that there's no reason to use them over a cheaper service like Azure. These organizations would need to hire some other company to develop the software if they did that, and that would end up costing them more because they'd be looking at a semi-custom project (COTS CMS solutions would partially meet the needs) rather than "just another license" with Netsential.
in that list of program names, i remember seeing WILDCHOCOBO and DARKTHUNDER in other Snowden files.
here is WILDCHOCOBO
https://search.edwardsnowden.com/docs/SPINALTAPMakingPassive...
page 19 of that is very very interesting. it lists around 100 NSA programs that are all part of some kind of global passive CNE implanted on hundreds of servers that provides ingest/exfil to feed back home into XKEYSCORE.
DARKTHUNDER is also on there.
the odd thing is that slidedeck is about NSA program JOLLYROGER tracking SD cards via their unique hardware volume IDs.
why would NSA TAO be hacking MSPs like Netsential at all? why is NSA spying on Fusion Centers, who get their reports from FBI, who themselves got the data to write the reports from NSA SIGINT? why is NSA spying on regional and local Law Enforcement further down the food chain? NSA already has that data. NSA wouldnt even need to use TAO and CNE to collect data from Netsentia. They could just ask for the data.
my best guess is it's some kind of Inside Threat monitoring system. TAO hacks into those systems to install CNE implants that watch for SD cards being inserted, to detect rogue Fusion Center and LE personnel who are bulk stealing files by copying them onto SD cards.
but that seems like a really dumb thing to do. why not just disable the SD card readers and/or remove the hardware? a PC in a Fusion Center shouldnt even have an SD card reader.
ironic, since Snowden roughly implied in his recent autobiography that the way he stole millions of NSA's top secret files was by sneaker net'ing them home using SD cards.
LOL NSA has been screwing up its defense against SD cards for at least a decade and that screw up is what made Snowden possible.
i bet dozens of Russian and Chinese and Israeli moles have stolen far more than Snowden ever took from NSA using
I think US agencies have sort of realized this mistake now, and actually for the last couple of years. The former NSA directors have said some revealing comments that reflect pretty authentic looking doubt, shame, and guilt over the various pathways programs took (with the exception of perhaps Admiral John Poindexter).
Perhaps agencies like the DHS, which when it was created was the largest reorganization of government since the Department of Defense was created in 1947, have not yet learned...
presumably those other 15 IPs are MSPs similar to Netsentia. maybe Phineas Phisher better target those IPs to breach and leak them too.
now that i think of it, maybe every IP address appearing in any Snowden leak should be probed to see if it still leads to interesting goodies.
That some random hosting company Netsential, not even a Microsoft Partner was chosen, makes both me and apparently the NSA suspicious.
More than likely DataFoundry is a front company. DataFoundry, which definitely is a real company, was ultimately hosting the Nestential sites. Their founders are former Peace Corps [1] recruits from the 1970's. They look like nice people but definitely not engineering experts. Also everyone at the company has been in place for nearly its entire existence. That is a tell-tale sign of fraud, a tech company should have massive movement within its executive ranks during these last two decade boom years. Also no one I know has done business with them, and even their customer list seems pretty thin when you realized almost all of them have the same one or two Private Equity owners...
[1] - https://www.datafoundry.com/blog/meet-founders-ron-carolyn-y...
"In addition to Texas.Net and Data Foundry, Ron and Carolyn established a Usenet company, Giganews, and an Internet security solutions company, Golden Frog, which provides one of the world’s leading VPN services, VyprVpn."
How extremely curious -- they are & have been a major seller of Usenet access & "privacy"/VPN services for the past few decades; hmm.
No particular technical expertise is involved in running these sorts of companies, those staff are hired. The top-level executive management is more reminiscent of commercial real estate than anything technical---it's buying land, building buildings, and putting tenants in them.
That the owners of the company have been involved in Usenet and VPN services is quite unsurprising---these are both industries that are technically simple, easy to get into, and can show a pretty quick profit. The up-front capital involved to get into them is having rack space and connectivity... things that, as owners of a colo outfit, they already had on hand. VPN services also have a high degree of customer overlap and can share infrastructure with usenet, so there is a VERY high degree of overlap between usenet providers and VPN providers---to the extent that it's more suspicious if a Usenet provider doesn't share owners with a VPN provider.
https://www-nytimes-com.cdn.ampproject.org/c/s/www.nytimes.c...
I think it just wasn't tested very well in Firefox. The third party map is blanking out for me at widths over 2048 pixels in a Firefox window. That's what I get for using an ultrawide monitor, I guess.
[0] https://mediaprogram.maps.arcgis.com/apps/instant/interactiv...
1. Officer receives information $A through inadmissible means (which may be illegal, but not necessarily)
2. With information $A, officer is able to "prove" that a suspect perpetrated a given crime
3. Officer pieces together proof from possible unrelated, but admissible evidence - $B and $C, let's say.
4. And this is the part where I don't know that perjury is what we're talking about: Officer simply testifies to the truth of $B and $C, and that the suspect committed the crime in question.
Eg, they plant a hidden camera in your house, see you packing drugs and puting them in your car in your own garage, and driving away. Since they got the info that you had the drugs from illegally set cameras, they can't just stop and search your car, but they can "randomly" stop you for a traffic check, and just "randomly" have a drug sniffing dog present, which finds the drugs in your car.
If the judges let this go through, the police would use more illegal methods (illegal searches, etc.) to gather data, then just "randomly" detect crime, and then the state would win cases.... and we (the people) don't want that. That's why, if you prove, that they knew the drugs were there from an illegal source of information, everything derived from that illegal source should be dropped as a illegally obtained evidence, to disincentivise the use of illegal methods.
Basically, the officer saying they randomly stopped you, would be a lie (=perjury), because they stopped you due their illegal cameras.
"When you see on the news that Police randomly stopped a car and discovered a huge cache of drugs... you don't actually think that's random, do you?"
TBH I had never thought about it before but now I recognize this pattern everywhere.
If you "did nothing wrong", you also drive like you did nothing wrong (5-10 over), hit some yellow lights, etc.
If you know you have a bag of drugs in your car, and a police vehicle pulls at a stop next to you, you can panic.
Also if they do stop you, becase you (eg.) didnt use your turn signal, most people just sigh., give some excuse ("I wanted to, but that black car came, and i had to go around, and the cat, and the wipers, and this and that"), and calmly wait for a ticket... people with drugs usually act different.
And thirdly, police usually know all the drug dealers in their area, know their cars, and just have to catch them with enough drugs to make it worthwile.... so they probably get stopped a bit more often than a normal random commuter does, even if neither of them use turn signals regularly.
https://www.reuters.com/article/us-dea-sod-idUSBRE97409R2013...
https://www.deamuseum.org/wp-content/uploads/2015/08/042215-...
Oh, it definitly happens.
But officers also make fishing stops all the time too.
>But the end does not justify the means, due to the fact that it is a violation of their 4th Amendment specifically the right to be secure in their persons, houses, papers, and effects.
You're greatly underestimating how many people who unironically oppose due process and civil rights because it "helps the bad guys", they themselves "don't have anything to hide", and "if you're being investigated, you probably did something wrong".
Yeah, like being born a Jew in Germany a little over a century ago.
The meaning of "something wrong" can change over time.
Doesn’t that feel like a huge violation of your privacy?
Agreed.
And a lot of people will miss an important point: for every dealer caught using 'parallel construction', countless of innocent citizens would have to be surveyed to score a "hit".
Perjury may or may not be the correct or most applicable transgression. Point is, if $A is what led to the collection of $B, then $B should be inadmissible. Presenting $B at trial is a violation of rights.
But in any case, whether the principle applies to a given instance is something that needs to be tested in court, and parallel construction is deliberately depriving the court of the ability to make a determination.
The main incentive for paralleling something is to protect the source, to maintain its effectiveness.
Parallel Reconstruction is used to avoid scrutiny of the original source of evidence. Even when used to legitimate ends (and I have doubts how often it's used as such), there are fundamental problems with dodging accountability.
2. With information $A, officer is able to "prove" that a suspect perpetrated a given crime
3. Knowing information $A, officer makes up bullshit showing that he reached $A solely from investigating leads from $B and $C.
4. $A is now admissible because the officer can show a link leading to $A from $B and $C, but he wouldn't have been able to without actually knowing what $A was.
For example, if I gave you a billion files to go through and find one thing, you probably wouldn't be able to. If I gave you the same billion files and told you file X was the one you should look at, you can say "oh I knew to look in X because of <bullshit>".
I'd be interested to see what a clean-room-like proposal would look like for evidence collection. I.e. independent agencies that can't share evidence/information between them.
Of course, then a 9/11 happens and there's lots of hand-wringing about how "we had all the data we needed, the agencies just weren't allowed to talk to each other". Ugh...
I'm not sure why you'd want that. The reason why it's outlawed in the first place is because it's illegal search and seizure. Making it look like you obtained it legitimately doesn't right any wrongs, any more than making a murder look like an "accident" makes murder okay.
In these cases, the notion that there is something to be reverse engineered was obtained by illegal means.
Intentionally and materially lying to the court is clearly perjury.
If a random search wasn't a random search, it's perjury to testify that it was a random search. Good luck proving it, though.
So combatting willful ignorance would be the first step, but my optimism meter broke a while ago.
https://en.m.wikipedia.org/wiki/Brady_v._Maryland
Under Brady, the prosecution is compelled by the Constitution to share all evidence with the defense, in order for the defense to be able to potentially challenge it.
Parallel Construction is secret evidence that is intentionally scrubbed from the Court record in order to keep the existence of illegal mass surveillance concealed. You can't challenge Parallel Construction in Court, because the evidence doesn't exist, and even if your defense attorney did have it, that evidence would be inadmissable based on State Secrets being invoked. Meanwhile, we all know domestic mass surveillance is happening, yet our Govt has to pretend it is not happening.
The Emperor truly has no clothes.
Why is our Govt going to such an extreme length of destroying decades of jurisprudence and risking reducing our Justice System to a farcical Kangaroo Court like in the USSR?
As the wise maxim from Watergate goes, "it's not the crime, it's the cover up."
Parallel Construction was invented, deployed and standardized as routine policy for one purpose: to prevent the Gov'ts illegal domestic mass surveillance from being challenged in Court, by preventing anyone from gaining legal standing against it.
Why doesnt the Govt just admit what we already know? "Yeah, we're spying on all of you, all of your cell phones, your emails and web browsing and Internet comms, we have it all and we search your data for crimes to charge you with."
If FedGov admitted the truth, all mass surveillance would be shut down by SCOTUS for violating not only the 4th Amendment, but also Brady and dozens of other laws. But wait, it gets worse. FedGov made the biggest blunder that compounds the error of their original sin. FedGov did not even KEEP TRACK of which collected evidence is Parallel Construction and which is normal evidence. That means hundreds of thousands of decided criminal cases would need to be tossed, because FedGov has no way to go back and comply with Brady, even to say "we are certain that no NSA SIGINT was used as Parallel Construction in your case."
The Govt doesnt know!!! If you remember the news from a few years ago where NSA was still retaining all domestic data collected between 2001-2007, and Congress morons were grandstanding "hur dur, NSA is holding American's data forever, we must force NSA to delete it"--the real reason for that was not because NSA wanted to retain your 20 year old emails. It was because NSA knew Brady could be a legal nuke used to annihilate NSA if the Court ever gave standing for someone to challenge Parallel Construction. NSA saved all that data in anticipation of saving its own neck. If NSA had to tell a Judge, "we purged all data about every case between 2001-2007, so we have no way to comply with Brady even if we didnt do anything wrong", that would sink NSA in Court. The FISC Judges would shutdown NSA the same day.
but guess what? Congress won that debate and forced NSA to delete the old data collected under STELLARWIND. now NSA has jumped out of the plane without a parachute.
someday there will be a Parallel Construction case that causes the sky to fall. it's inevitable.
what's going to happen? NSA, FBI, CIA and DOJ will be reigned in by some Judge? the old way will be restored and Law and Order in a mostly fair justice system will be the norm again?
lol of course not. FedGov and the Deep State will NEVER give up their power to mass surveil. instead, they will be forced to invent some new Law that allows them to continue business as usual. and that law will be openly and extremely Totalitarian and it will slowly shift America away from being a Democratic Republic towards being a Monarchical Empire.
Parallel construction is a completely normal and legitimate process. People who use it like a spooky term akin to "enhanced interrogation" or "extraordinary rendition" are just loudly signalling they have little firsthand knowledge of law enforcement.
I don't think arguing against the legitimacy of the investigative means used to acquire evidence is ever an admissible argument by which to contest that evidence before a jury. If those investigative means were a poisonous tree, that's an argument you make to the judge to preclude admission of that evidence in the first place, before either side gets to contest any evidence.
I think lawyering over whether parallel construction is lying or not is tactically silly. You'll be on much firmer ground arguing that parallel constructions completely undercuts the point of the "fruit of the poisonous tree" doctrine, which is to disincentivize illegal means of investigation.
Withholding evidence from the defense is very incompatible with our justice system.
Is this your best effort attempt at assuming good faith?
> "parallel construction is inadmissible evidence laundering."
Well, it's concealing a source, which is what I said. If you have an informant who's life would be in danger if they were revealed, then anything they tell you would have to be paralleled. There's nothing illegal about their evidence, they would just never testify to it.
Your position seems to be that there are legitimate reasons it was introduced. I don't disagree with that. That doesn't mean that the process doesn't involve lying in court to deprive people of their rights.
You say "conceal a source" but that is precisely depriving the accused of their explicit constitutional right to be "confronted with the witnesses against them".
(I will note that I've definitely been speaking with a US focus - not all of my comments will generalize.)
For instance, protesters don't exactly wear body cameras, but they have been using cell phone cameras to document police violence. Many of the other technologies listed (license plate readers, facial recognition, etc..) could also be used, though it would be harder to use those things as effectively as cameras are used now.
[1] https://www.goodreads.com/book/show/40796190-eyes-in-the-sky
[2] https://www.theatlantic.com/technology/archive/2019/08/milit...
However, because law enforcement and wealth inequality is what it is, I'm somewhat open to surveillance system in certain areas of BH that are high risk targets. I hope these systems aren't used against regular residents and only actual threats. But, of course, that's a fallacy.
There has been a police shortage since the early 2010's where most departments only had a 1/3 of the manpower that was needed. Now with public sentiment against the police, I'm sure the police shortages will increase, eventually forcing the government to rely on more surveillance, AI, and robotics to fill the gap.
That being said, the police force has a pretty stellar reputation of not looking for trouble and bad cops are usually shown the door pretty quickly. The rest of FL though is a mess, traffic light cameras everywhere, licence plate scanners, stingray. You name it they are decked out with it.
https://supporters.eff.org/collaborate-atlas-surveillance
so that the whole thing can also be further developed worldwide