HNHacker News
TopNewBestAskShowJobs

csoghoian

256 karma · joined September 24, 2011

submissionscomments
csoghoian··on Block cookie banners on Firefox
The successor to Do Not Track is the Global Privacy Control, which companies are required to respect in several states, including California and Colorado. Support for GPC is already built into Firefox and Brave, but must be enabled in the privacy settings. Users of other browsers can get the benefits of the GPC opt-out using third party extensions like EFF's Privacy Badger.

See: https://globalprivacycontrol.org/

csoghoian··on Tox: Decentralized and Encrypted Instant Messaging
The Open Technology Fund provides free security audits for open source projects.

Apply here: https://apply.opentech.fund/red-team-lab/

csoghoian··on Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say
DHS is a law enforcement agency, which regularly uses surveillance techniques, some of which exploit security flaws in devices and software. When you share information about security flaws with DHS, you're sharing them with ICE and the Secret Service.

The FTC, in contrast, is a consumer protection agency. They don't kick down doors and they don't arrest people.

And yes, many security researchers have shared their prepublication research with the FTC.

csoghoian··on Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say
So you didn't tell the Federal Trade Commission, even though they previously investigated (and punished) HTC for doing something similar?
csoghoian··on Secret Backdoor in Some U.S. Phones Sent Data to China, Analysts Say
This seems very similar (or perhaps even worse) than the fact pattern in the HTC/Carrier IQ case. https://www.ftc.gov/news-events/blogs/business-blog/2013/02/...

Did you provide the Federal Trade Commission with an advance copy of your report, or just DHS? If not, why not?

csoghoian··on Rule 41 Proposes to Grant New Hacking Powers to the Government
I think that some webcam indicator lights are vulnerable to remote disabling. Although it is certainly possible that some are not, I and most other users have no way of knowing which lights are reliable, and which ones are vulnerable.

As such, I put a Band-Aid over my webcam.

Now if only I could figure out an equally easy way to reliably disable my laptop microphone without opening up the laptop and cutting the cable.

csoghoian··on Rule 41 Proposes to Grant New Hacking Powers to the Government
1. My employer, the ACLU, filed two comments in the Rule 41 process.

The first, before public comments were even solicited, resulted in DOJ dropping one of their proposed changes to rule 41, which would have permitted the gov to piggyback from a hacked target's computer to a cloud account (such as Dropbox or Google), rather than the gov going to the cloud provider with a warrant.

While our first comment does indeed describe and quote from some alternative language proposed by Orin Kerr, I don't think it is fair to describe that as evidence of ACLU approval of hacking of users whose location cannot be determined. For example, in that comment, we note that:

[U]nder Professor Kerr’s language, the government would still be able to obtain warrants to use malware, zero-day exploits, and other techniques that raise serious constitutional and policy questions.

2. While some public interest groups and tech policy advocates are publicly (or, in some cases, privately) embracing the idea of giving law enforcement formal, regulated hacking powers, in a desperate attempt to push back against legislative pressure for crypto backdoors, I'm thankful that the ACLU has not done so. If the organization does at some point decide to come out in favor of law enforcement hacking, I strongly doubt my name will be on that document.

[I'll note, however, that one of the great perks that come with working for the ACLU is that it's perfectly OK to disagree with some of the organizations' official policy positions. I'm not forced to tow the company line publicly on issues in which I disagree.]

3. Just so all of my cards are on the table. I'm volunteering, unpaid, as an expert for the defense in several of the Playpen FBI watering hole cases. I am strongly opposed to bulk hacking, enough so to volunteer my time to helping to fight the FBI's use of this outrageous surveillance technique.

4. The FBI being able to remotely activate webcams without the light turning on is not an "unsourced anonymous claim".

From the Washington Post story, linked to in my comment above:

The FBI has been able to covertly activate a computer’s camera — without triggering the light that lets users know it is recording — for several years, and has used that technique mainly in terrorism cases or the most serious criminal investigations, said Marcus Thomas, former assistant director of the FBI’s Operational Technology Division in Quantico.

csoghoian··on Rule 41 Proposes to Grant New Hacking Powers to the Government
I've researched this issue extensively, and I've not found a case before where a thousand people in the same place were searched pursuant to a single search warrant, let alone a thousand people or items located in different places around the country.

On the issue of courts authorizing the searching of wrong people, we don't know if the court in Freedom Hosting even knew that the government would deliver the malware to innocent people who were merely visiting other websites hosted from the same server as the contraband sites targeted by the warrant. We don't know this, because three years later, the freedom hosting search warrant is still sealed.

csoghoian··on Rule 41 Proposes to Grant New Hacking Powers to the Government
The FBI has been using malware since at least 2003 [1], probably a few years before that. Today, the FBI has a dedicated team, the Remote Operations Unit, based out of Quantico, which does nothing but hack into the computers and mobile phones of targets. According to one former top FBI official, among the team's many technical capabilities, is the ability to remotely enable a webcam without the indicator light turning on [2].

Although DOJ has been using malware for nearly fifteen years, it never sought a formal expansion of legal authority from Congress. There has never been a Congressional hearing, nor do DOJ/FBI officials ever talk explicitly about this capability.

The Rule 41 proposal before this advisory committee was the first ever opportunity for civil society groups, including my employer, the ACLU, to weigh in. We, along with several other groups, submitted comments and testified in person.

Our comments can be seen here [3,4]. Incidentally, it was while doing the research for our second comment that I discovered that the FBI had impersonated the Associated Press as part of a malware operation in 2007 [5].

Ultimately, the committee voted to approve the change to the rules requested by DOJ. In doing so, the committee dismissed the criticism from the civil society groups, by saying that we misunderstood the role of the committee, that the committee was not being asked to weigh in on the legality of the use of hacking by law enforcement, and that "[m]uch of the opposition [to the proposed rule change] reflected a misunderstanding of the scope of the proposal...The proposal addresses venue; it does not itself create authority for electronic searches or alter applicable statutory or constitutional requirements."

[1] http://www.nytimes.com/2016/04/14/technology/fbi-tried-to-de...

[2] https://www.washingtonpost.com/business/technology/2013/12/0...

[3] https://www.aclu.org/sites/default/files/assets/aclu_comment...

[4] https://www.aclu.org/files/assets/aclu_comment_on_remote_acc...

[5] http://bigstory.ap.org/article/23f882720e564b918d83abb18cd5d...

csoghoian··on Rule 41 Proposes to Grant New Hacking Powers to the Government
This isn't just about the district where the judge is based. There is also the bigger question of whether or not judges should be authorizing bulk hacking operations.

The three Tor watering hole operations (Freedom Hosting, Torpedo and Playpen) are the only cases we know of where DOJ has obtained a warrant from a single judge which it then used to conduct searches on hundreds or thousands of computers. DOJ did not seek new powers to conduct bulk searches/hacks from Congress, they just went ahead and got an ex-parte warrant from a judge. In the case of Freedom Hosting, it looks like they also screwed up and then hacked the computers of innocent people visiting other, non contraband sites, hosted on the same server.

I think that reasonable people can disagree about whether or not it makes sense to allow a judge to sign a warrant to hack a single computer in an unknown location which is probably outside of his or her district. Bulk hacks are very, very different, and a very new thing for our legal system.

csoghoian··on Anatomy of a Co-Branded Credit Card
Pay an award booking service to find you the best flights possible. There are several out there, and they know a lot more than you about how to find obscure flights/routing. it's worth the $150.
csoghoian··on Johns Hopkins researchers poke a hole in Apple’s encryption
Actually, weev neither wrote the script nor ran it. Those were done by his codefendant.

Weev took the data provided to him by his codefendant and gave it to Gawker.

csoghoian··on White House Names Dr. Ed Felten as Deputy U.S. Chief Technology Officer
The Federal Trade Commission is an independent agency. They don't take orders from the President.

(I know, because I worked there for a year)

csoghoian··on Why Clinton’s Private Email Server Was Such a Security Fail
You might want to look at this:

https://dnshistory.org/dns-records/mail.clintonemail.com

http://whois.arin.net/rest/net/NET-24-187-234-184-1/pft

csoghoian··on GPG and Me
You say "Redphone? Whisper? and various other projects - while very cool - didn't achieve even as much popularity as GnuPG"

The Axolotl protocol that was created for Whisper System's TextSecure is now used, by default, by Cyanogenmod (10 million users) and the Android version of WhatsApp (more than 500 million installs from the play store).

I'd say Moxie's tech has been pretty widely adopted.

csoghoian··on Once-starving GnuPG crypto project gets a windfall. Now comes the hard part
I pitch stories regularly to reporters. Dan is by far one of the best reporters in the business, and is the person I go to whenever I have something that is interesting, but far too technical for the mainstream press. He always does an excellent job with it, particularly if I give him a few days.

I've worked with plenty of unprofessional reporters who butcher stuff, and don't care about the details. Dan isn't like that.

csoghoian··on Americans’ Cellphones Targeted in Secret U.S. Spy Program
The US Marshals are not the only federal law enforcement agency doing something like this. According to documents I obtained through a FOIA in 2012, ICE has purchased an airbourne mounting kit and paid for airbourne training for their Stingray II cell phone tracking gear. See: https://www.documentcloud.org/documents/479397-#document/p44

Anyone interested in learning more about IMSI catchers and their use by US law enforcement agencies might be interested in this law review article I wrote. http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2437678

csoghoian··on 'Secret agents' warning removed from Chrome incognito tab
As one of the complainers (and the person who filed the bug you linked to), I'm happy to see Google make some progress here. I'm even happier to see that they hired Adrienne Felt, who is excellent, and are letting her improve the usability of Chrome's warnings.
csoghoian··on Google Taking Aim at Device Modders in Android 4.4 KitKat
Why wouldn't the FBI or NSA just demand the encryption keys and then sign their malware?
csoghoian··on EFF Has Lavabit’s Back in Contempt of Court Appeal
The government obtained a 2703(d) order for the stored non-content data of a particular user (suspected to be Snowden, but redacted from the court documents). They then obtained a pen register order, for real-time metadata about that same user. Lavabit told them they couldn't comply, so the government sought to use the 3rd party assistance language in the pen register statute to compel the company to provide its private SSL keys. The government then followed up with a grand jury subpoena and Stored Communications Act warrant specifically seeking Lavabit's private SSL keys.

So, no. The warrant the government obtained was not specifically for the data relating to Mr Snowden, but rather, was for the SSL keys.

csoghoian··on Yahoo wins motion to declassify court documents in PRISM case
Yahoo still doesn't use HTTPS by default, for email or search.

Not using HTTPS is huge, gift-wrapped present to the NSA. It also means that the NSA can get Yahoo users' communications without even having to bother Yahoo, as they can get it with the assistance of backbone networks. Lower legal compliance costs for Yahoo, and the NSA gets what they need.

Seriously, Yahoo is awful on privacy and security. Don't reward them with your business.

csoghoian··on How Microsoft handed the NSA access to encrypted messages
Having worked at the FTC for a year in the team that goes after companies for violating consumers' privacy, I can comfortably say that you are 100% right on that point.

The FTC (unfortunately) does not police deceptive statements about government surveillance.

csoghoian··on DecryptoCat
If Syrian rebels aren't using computers, why would pro-government forces bother to send them malware? See: https://www.eff.org/deeplinks/2012/12/iinternet-back-in-syri...

Your unsupported claim that the "majority of cryptographic transmissions are for child pornography and drug purchases" is insanely wrong.

Given the default use of HTTPS by Google, Hotmail (Live.com), Twitter and most recently Facebook, it is almost certain that the legitimate traffic to/from those sites vastly outnumbers, by several orders of magnitude, whatever encrypted data is sent by folks exchanging child pornography images or buying drugs via silk road.

You don't know what you're talking about.

csoghoian··on Court Order told Yahoo that Prism does not require a warrant [pdf]
There appears to be a bit of a conflict between the cardinal rule you were taught when you worked at NSA of not collecting information on US persons with the current practices of the NSA.

The Section 215 program in which the NSA has been collecting metadata about every domestic telephone call would appear to violate that rule, even if, as we are told, only a couple dozen NSA employees can query the database, and even if they only use it for investigations related to terrorism.

Likewise, the non-us persons targeting rules leaked last week suggest that the NSA has ongoing access to GSM Home Location Register data for the entire United States. While this doesn't pinpoint someone's location to a house or street, we're still talking about the NSA getting city-level location data for hundreds of millions of innocent Americans.

See page 6 of: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi...

Given how compartmentalized NSA is, it seems quite reasonable that your former team (which, I assume, penetrated the computers of foreign targets) would have no contact at all with the teams tasked with collecting domestic communications.

csoghoian··on Court Order told Yahoo that Prism does not require a warrant [pdf]
Justin, have you read the recently leaked NSA rules outlining how they define a non-US person for the purpose of FAA surveillance?

See: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi..., page 4, paragraph 1.

If the NSA does not know whether someone is a US person or a foreigner, the agency assumes that the person is a foreigner. That matters a lot if, for example, you're using Tor.

You might also want to look at the recently leaked minimization rules, which permit the retention of purely domestic communications collected under the FAA, if that information can be used to develop and exploit security vulnerabilities. Given where you work now, and what you work on, that might be somewhat important.

See: http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi..., page 5, paragraph 3.

csoghoian··on Facebook paid $4.5K for disclosure of my user account exploit
Cody, on his own blog, described the sale of the vulnerability as follows:

In 2010, we (the startup I was running with friends at the time, UPM) decided to license the opening technology to a locksmithing company for law enforcement purposes.

If it is "laughable to suggest that Cody in any way enabled the USG to break into hotel rooms", then why would he describe the sale as "for law enforcement purposes"?

csoghoian··on Facebook paid $4.5K for disclosure of my user account exploit
If researchers in this community are going to sell security vulnerabilities to the government, I think that fact should be well known.

daeken's work on hotel locks got a lot of press, but the fact that he had two years earlier sold that info to a company for "law enforcement purposes" hasn't gotten nearly the press attention it deserves.

Martin Muench and Chaouki Bekrar have openly embraced what they do. As much as I dislike the path they follow, I have to at least respect them for being up front about the business they're in.

If you're going to help governments covertly break into people's homes, computers, and smartphones, you should wear it with pride.

csoghoian··on Facebook paid $4.5K for disclosure of my user account exploit
And by many people, you include yourself, right?

Long before you disclosed the vulnerability in Onity hotel locks to the public, the startup you had co-founded "licensed" the same flaw to Lockmasters Security Institute, a company that trains law enforcement agencies, special ops, and intelligence agencies in covert entry techniques.

You gave LSI's government customers a pretty big head start before you bothered to disclose that flaw to the general public.

csoghoian··on Apple's iMessage encryption trips up feds' surveillance
Given that high-value zero days are mostly bought by governments from defense contractors and security companies.

There. Fixed that for you.

csoghoian··on I am under surveillance by Canadian agents, my computer has been backdoored
Although the details of the gov's investigation and harassment of Jake are largely shrouded in secrecy, his harassment at the border began right after giving a keynote at HOPE 2010 in place of Julian Assange, as the only US citizen identified in the media as a member of the Wikileaks team.

Although I think what the US government has done to Jake is quite clearly a disgusting abuse of power, let us not kid ourselves by somehow believing that the state has gone after him because he has publicly advocated for the use of strong crypto.

Page 1 of 2Next →