Tuesday, February 8, 2011

Anonymous Hacks Security Firm Investigating It; Releases E-mail

A U.S. security firm that claimed to have uncovered the real identity of Anonymous members responsible for a recent spate of web site attacks became a victim of Anonymous itself, when members of the online vigilante group breached the company’s network and stole more than 60,000 internal e-mails.
The group posted the e-mail spool Sunday on the Pirate Bay torrent site for anyone to download and sift through.

HBGary Federal, which does classified work for the U.S. federal government among other security work, claimed it had been working with the FBI to unmask hackers behind recent denial-of-service attacks against PayPal, Visa, MasterCard and Amazon. Members of Anonymous — a loosely structured group of internet troublemakers — had organized the mass attacks after the companies suspended accounts used by WikiLeaks to receive donations and host documents. More recently, members of the group directed denial-of-service attacks against government web sites in Tunisia and Egypt.

Last month, the FBI announced it had executed more than 40 search warrants against people suspected of participating in the WikiLeaks-related attacks. British police also arrested five men in relation to the attacks.
The hack against HBGary Federal occurred after the Financial Times published a story on Saturday quoting Aaron Barr, CEO of the company. Barr said his company’s researchers had uncovered clues to the real identities of top members of Anonymous by monitoring chat rooms and Facebook groups they frequented. Barr identified a co-founder of the group, who goes by the name Q, and said he planned to give some of the information to the FBI. He also planned to present his findings at the RSA Security Conference in San Francisco next week.

On Sunday, Anonymous ridiculed the company’s research skills and the accuracy of its data in a press release posted at Daily Kos, mocking the company’s “infiltration of our entirely secret IRC server anonops.ru and in particular our ultra-classified channels #opegypt, #optunisia, and, of course, #reporters, which itself is the most secret of all.”

In addition to the sudden disappearance of Anonymous leader Q, Anonymous co-founder Justin Bieber also disappeared just before his top-secret mission to Eritrea to offer physical succour to the rebels, suggesting that Mubarak is in our base, eating our Cheetos, likely with military support authorized by Hill Dawg

The group then hacked into the HBGary Federal web site and e-mail servers, and replaced the web site content with a lengthy message taunting the security firm for failing to protect its own network and for trying to gain attention by marketing its research on Anonymous.

“Your recent claims of ‘infiltrating’ Anonymous amuse us, and so do your attempts at using Anonymous as a means to garner press attention for yourself. How’s this for attention?,” the message reads. “You’ve tried to bite at the Anonymous hand, and now the Anonymous hand is bitch-slapping you in the face.”
The hackers then posted a file purporting to contain the research that Barr had collected on Anonymous members as well as more than 50,000 e-mails in Barr’s account. The group claimed to have financial details for the company and threatened to erase content on the company servers.

Exposed Email Alert!: Facebook Must Explain Privacy Practices to Congres...

Exposed Email Alert!: Facebook Must Explain Privacy Practices to Congres...: "Analysis: Congressmembers say they want answers regarding Facebook’s data disclosure. Facebook's plan to give developers access to users' a..."

Exposed Email Alert!: Zuckerberg IM's Won't Help Facebooks Privacy Issue...

Exposed Email Alert!: Zuckerberg IM's Won't Help Facebooks Privacy Issue...: "Facebook CEO Mark Zuckerberg and his company are suddenly facing a big new round of scrutiny and criticism about their cavalier attitude tow..."

Exposed Email Alert!: Calif. juror ordered to turn over Facebook posts

Exposed Email Alert!: Calif. juror ordered to turn over Facebook posts: "SACRAMENTO, Calif. – A California judge has ordered a juror to turn over Facebook messages he posted during the trial of several alleged gan..."

Saturday, February 5, 2011

Thursday, February 3, 2011

Secure Client Information Exchange: SURPRISE! Leaked Emails Show Fox News' Exec's Atte...

Secure Client Information Exchange: SURPRISE! Leaked Emails Show Fox News' Exec's Atte...: "Media Matters has uncovered even more internal Fox emails revealing a purported network-wide campaign to link Barack Obama to 'Marxists' and..."

Secure Client Information Exchange: Pakistan to cut BB services for foreign missions-s...

Secure Client Information Exchange: Pakistan to cut BB services for foreign missions-s...: "Pakistani authorities have asked mobile telephone operators to stop BlackBerry services to foreign missions in the country amid concern abou..."

Patterns of Misconduct: FBI Intelligence Violations from 2001 - 2008

Excerpt:

......In response, the email service provider returned two CDs containing the full content of all emails in the accounts. The FBI eventually (and properly) sequestered the CDs, notified the email provider of the overproduction, and re-issued an NSL for the originally requested header information; but, in response to the second NSL, the email provider again provided the FBI with the full content of all emails in the accounts.

Compounding the service providers’ problematic over-disclosure, the scope of the FBI’s authority to issue NSLs for electronic transactional records rests on unsettled and unclear legal grounds. The FBI’s NSL authority under the Electronic Communications Privacy Act (ECPA) allows the government to issue NSLs to traditional telephone service providers for non-content subscriber information and toll billing records — essentially, the name, address, length of service, and local and long distance call records.30 ECPA also provides the authority to issue NSLs for "electronic communications transactional records." However, the exact scope of this remains unclear: according to the DOJ, "electronic communications transactional records" include "those categories of information parallel to . . . toll billing records for ordinary telephone service."31 What, exactly, "those categories of information" constitute — possibly including, for example, email "header" information, IP addresses, URLs, or other information — remains unclear.

Third-parties not only willingly cooperated with FBI NSLs when the legal justification was unclear, however: they responded to NSLs without any legal justification at all. In one instance, when requesting financial records from a bank under the Right to Financial Privacy Act, the FBI used language and statutory citations from ECPA — a statute entirely unrelated to financial records — for its legal authority; nevertheless, the financial institution complied with the FBI’s legally deficient request........

Read Full Article

As International Privacy Day is Celebrated, Governments Continue to Chip Away at Privacy Rights

"Effective data protection is vital for our democracies and underpins other fundamental rights and freedoms." - Viviane Reding, Vice-President of the European Commission and Commissioner for Justice, Fundamental Rights and Citizenship.

Last Friday, privacy advocates and government officials in countries across the world celebrated the 5th annual International Privacy Day — even as individual privacy is threatened by surveillance proposals and security breaches worldwide. This day commemorates the first legally binding international agreement on data protection – the Council of Europe’s Convention 108- which was opened for signature on January 28th, 1981. Last week’s celebration marked the 30th anniversary of Convention 108, which has served as a foundation for many countries’ national data protection laws. It is an opportunity to raise public awareness about privacy threats and to urge governments to protect citizen's privacy rights.

Read Full Article