US and UK spy agencies scoop up private data from 'leaky' phone apps
theguardian.com
theguardian.com
...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information.
So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system."
At this point it is perhaps not wrong to conclude that the whole internet is bjorked by these agencies. Open to snooping and manipulation at any and every level for any user.
It is time for a reboot, this time with much more focus on security.
Really now? Is that the official reasoning for not using HTTPS?
Again I ask: Any specific examples from companies or organizations that implement HTTP(S) in their products stating device power as reason for non-implementation?
That said, if they have kernel-level hacks or can intercept and decode HTTPS (or sit and listen on say, any AWS server they want), what does HTTPS really matter against the NSA?
Still, totally irresponsible - battery life is a constant struggle, but not enough to even make us consider changing our API client code.
How do you know that the apparently random stream of bits is actually properly encrypted and does not leak private data? It would be better to let the OS add the SSL layer and only let apps talk HTTP. This would give the user much more control.
I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes.
Considering Apple did that on your behalf I would be surprised if this was not the case.
http://bits.blogs.nytimes.com/2011/04/20/3g-apple-ios-device...
"Maybe apple intended this to be the case" is baseless innuendo and has no place here.
"If it's on the phone, we can get it" has separately been shown only to apply when the agencies have physical access to the device to extract data or implant malware.
You seem to want to spread the idea that spies can access the real-time location of your iPhone remotely - which is what the parent post was fearing, but for which there is no evidence. What is your motive here?
The parent comment said nothing about real-time access, but if someone has a remote exploit that gives filesystem access (and if jailbreakers can do it, then the NSA can, too), that location data file would provide a detailed history of the phone's location.
The cell tower cache you refer to does not contain that kind of data, so the data file des not provide a detailed history of the phones location. This has been shown by the people who investigated the file.
An extremely coarse location, to the resolution of cell towers can be obtained from the file, but as we know, that is available to the phone network anyway.
The parent comment talks about geolocation data at regular X minute intervals. This file does not provide that. Nor does it provide any information that the NSA can't get via the cell network about any phone. Indeed the network likely can provide triangulation.
The link you referenced is nothing but innuendo intended to implicate 'Apple' somehow.
http://www.washingtonpost.com/world/national-security/nsa-tr...
Here's a helping hand for those that don't know where to start: http://prism-break.org/
[1] https://en.wikipedia.org/wiki/Superresolution [2] http://research.microsoft.com/en-us/um/people/cmbishop/downl...
To me, this is quite telling.
The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking for "what can we get", and worry later about how it might be useful (or legal!).
This is no way to run a successful organization in the 21st century.
It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.
The problem is with the legislature (and the judiciary), voters, and the media.
The more subtle point that the parent makes is that, rather than always trying to prevent bad actors from doing bad things (e.g. murdering), a working system of checks and balances can punish the bad actors and deter future abuses. But checks and balances obviously don't work when everything is classified. The legislature and the judiciary were essentially the only two institutions that had access to this information and they did nothing about it.
You can't vote judges out of office, but if large scale surveillance is an issue important to you I'd make sure my congressman or congresswoman knew about it.
I'm just going to assume you were being sarcastic and move on.
So, because it's not hurting them in terms of success to operate this way, there's a need for external controls to prevent it. If being all-collecting hurt their effectiveness, we wouldn't need any new controls, because they'd be replaced for being unsuccessful.
Plus, the inevitable outrage generated when these tactics became public is undeniably hurting their credibility and in the long term their ability to gather information.
Except that their mission is deeply compromised by their actions: they've lowered domestic cyber-security, undermined the rule of law, and deeply shaken the public confidence in the armed forces - all of which are contrary to their core mission.
They seem to have lost sight of their high level goals in their quest for more power to accomplish specific secondary tasks.
What incentives were those? To create a police state with kind of distopian program "Overseer"? Because that's exactly what they are doing.
Once someone is a target, investigating them in general is legitimate, assuming that there is justification for regarding them as such.
It absolutely matters how broad the targeting is, but that is a separate question.
This is just one more strike into the already well-beaten dead horse of an argument that the NSA is spying in the name of preventing terrorism.
I will spell it out: the goal of the NSA surveillance is omniscience in the name of preserving the power of the state. They have made great progress toward this ideal.
As violent and primitive as the Islamic fundamentalists are, the vast, vast, vast majority of the world's 1.6 billion Muslims are not fundamentalists, nor are they terrorists, nor do they aid terrorists.
The phrases that people bookmark in a religious app book are a very far cry from demonstrable intent to commit violence, anyway. If you spied on everyone's bookmarks in religious text apps, I'm fairly certain that if you pitched it properly you could depict my own gentle mother as a genocidal crusader.
The majority are almost certainly not, but a frighteningly large minority are. For example, only 54% of Muslims in Turkey believe that suicide bombings are never justified, and 16% believe that they are sometimes or often justified: http://www.pewglobal.org/2013/09/10/muslim-publics-share-con...
This should not be particularly surprising. Fundamentalism also runs strong in Christianity. Nearly half of all Americans are creationists, believing that the earth is only a few thousand years old, and that people did not evolve (we're not talking Catholic-style "god used evolution" creationism here, we're talking straight up "literal talking snake" creationsim): http://www.gallup.com/poll/155003/hold-creationist-view-huma...
People take religion seriously, film at 11.
What percent of Americans believe drone attacks are justified?
What does "fundamentalism" have to do with any of this?
Someone, please tell me I'm wrong.
You can be walking down the street and an hour later, unbeknownst to you, your picture makes it to the front page of reddit. It could be that you were skipping work that day, and told your boss you were sick. Or perhaps picking up an engagement ring.
This sort of free-for-all will only get worse as technologies like Google Glass and the so-called "Internet of Things" become mainstream. Your life is now a commodity for internet voyeurism and, possibly, witch hunts.
The tech is ripe for turning citizens against citizens. "Turn in your neighbor for un-American activities" sort of stuff.
If you're using Android, I'd highly recommend using a combination of XPrivacy [1] and Android Firewall [2] (iptables frontend).
To make your life easier, disallow everything from accessing the net in Android Firewall. Then, for those apps which you've allowed net access, further tweak what they're allowed to access in XPrivacy. As a rule, turn off account info, clipboard, location, contacts, and storage.
Not perfect, but a decent solution.
[1] https://github.com/M66B/XPrivacy
[2] https://play.google.com/store/apps/details?id=com.jtschohl.a...
I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.
Of course, if your open source apps request any data related to your activities (such as detailed map data about your current location, even without your exact location, or routing information for TCP packets), you're leaking data about yourself again.
No need for any code weaknesses in the app. Open source is not your saviour here!
Which isn't to say that I don't think open source is a necessary condition for security. But I don't see that sort of audit getting done for everything that your average user is going to run on their phone.
These caches of information exist all over the place. While I'd prefer NDA/GCHQ to not slurp and store this stuff at least they have a duty to keep it secret. I am a lot more bothered by my ISP keeping that stuff. They're a lot less competant and have many fewer access controls.
"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."
Privacy or correspondence... "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence"
“Once you have something that grows faster than education grows, you're always going to get a pop culture.” - Alan Kay
That's a good point and a good reason why it's irresponsible for these newspapers to post the details about this technology. This kind of CI doesn't work as well once everybody knows what you're doing. It also gives a road map to more oppressive governments looking for ways to spy on their citizens.
The documents do not make it clear how much of the information that can be taken from apps is routinely collected, stored or searched, nor how many users may be affected.
Right, so this is just publishing some details of NSA/GCHQ counterintelligence technology without saying how they are using it. Unless they have some evidence of wide scale deployment of these techniques, how is this surprising? Do we not expect spy agencies to develop surveillance technology?
Given that the net effect of these programs, so far as anyone in the government has been able to demonstrate, ranges from zero to trivially small, rendering these programs inoperative will have a zero or trivial positive effect for the terrorists.
I suspect that you're reply that the govt's inability to demonstrate the program's efficacy is because such a demonstration would necessarily reveal so much that the programs would be rendered ineffective in the process. Too damned bad. At some point we've got to touch base with the philosophical foundation on which the government is built. Ultimately, we are the masters, and the government operates only as we allow it to. Allowing the government to circumvent so many of the liberties which the Bill of Rights guarantees will be conserved for the people is to turn the design of our government on its head.
Ooga-booga! TERRORISTS!!!11!!
Still waiting for a list of "terrorists" caught by this program.
This is just sad. Western governments are the oppressive governments. That we have the “moral high ground” is a lie that’s been used as a weapon by these same warmongering immoral people that have always been in charge. “American exceptionalism” is an immoral indefensible position.
To still be trying to state that our governments are the only ones morally worth to use these military weapons, after all the revelations of torture, lying into war, detaining people for life without trial, kidnaping, assassinations, spying, etc, is to willfully refuse to break out of the military propaganda that you've been subjected to.
If you think Western governments are the oppressive ones, what do you think about the governments of China, Russia, and Iran?
The US has 2.5 times the number of prisoners as Russia, with 1.2 times as many per capita.
The US has 27.5 times the number of prisoners as the UK, with 5.0 times as many per capita. (Interestingly, China has less prisoners per capita than the UK.)
So you can make a lot of points about the relative quality of those prison experiences (and they might be valid points), but in terms of sheer volume of people that are incarcerated by their own government, the US outstrips both China and Russia by a wide margin - in both absolute and per capita terms.
If anything they are just making it harder to find the needle (terrorist threat) in the haystack (their dragnet of data). At the end of the day maybe they don't care about finding the needle anymore.
Its not all about finding criminals. But when you've found one, you want to know where he's at, who he's associating with etc.
On Android java side we have a tool called:
sable/soot
Which I am recently learning to use..
> Soot is a Java optimization framework
Seems to be a Java static analysis tool and not related to Android permissions (although maybe related to security).
https://play.google.com/store/apps/details?id=dev.ukanth.ufi...