Friday, February 18, 2011

House Extends Controversial Parts of Patriot Act

A Federal Agent Can Seize Your Corporate Emails Without A Search Warrant or Judicial Review. Confidential Corporate Communications Are Under Attack From "Internet Security Firms", Governments, and Opportunistic In-House IT Employees




Secure Email

SCIE

Senate Approves Short-Term Extension of Patriot Act

Your Confidential Corporate Emails Are Subject To Confiscation Without Warrant or Cause.



Secure Email

SCIE

Glenn Greenwald Explains HBGary/ChamberLeaks

Which "Security Firm" Will Be (has been) Retained to Obtain Your Company's Confidential Communications?

Who Wants Your Inside Information and Why?



SCIE

Anonymous victim HBGary goes to ground

The computer security company hacked by members of activist group Anonymous has gone to ground as further revelations about its activites leak online.

HBGary has cancelled its appearances at public events, saying that members of staff had been threatened.

It follows the release of internal documents which appear to show the firm offered to smear Wikileaks' supporters.

HBGary officials said the online messages could have been altered prior to publication.

The company's founder, Greg Hoglund had been scheduled to give a talk at the RSA Security conference in San Francisco this week, but pulled out at the last minute.

The company also withdrew from an associated exhibition.

"In an effort to protect our employees, customers and the RSA Conference community, HBGary has decided to remove our booth and cancel all talks," it said in a statement posted on its website.

According to e-mails that Anonymous claims to have taken from HBGary's servers, the company had proposed a plan to undermine Wikileaks.

At the time, the whistleblowing website was planning to release documents relating to Bank of America.

The leaked emails also suggest that HBGary had discovered evidence that US officials were attempting to monitor visitors to websites affiliated to al Qaeda.

These messages have been posted online via the Anonymous-supported site Anonleaks.ru.

Government payload

In a message to colleagues, dated 16 November 2009, Mr Hoglund allegedly wrote that he had obtained a document taken from a jihadist website.

"I think it has a US govvy payload buried inside," the e-mail said.

The note also urges colleagues not to open the programme unless they were in a locked-down environment.

"Don't let it fone (sic) home unless you want black suits landing on your front acre," it adds.

In e-mails from early January 2011, it is claimed that Mr Hoglund sent out proposals to develop a spying program, known as a rootkit, that would run on Windows-based computers.

"There isn't anything like this publicly," the proposal stated. It would be "almost impossible to remove" or detect.

Read Full Article

SCIE

Thursday, February 17, 2011

Newly Released Documents detail FBI's Plan to Expand Federal Surveillance Laws

EFF just received documents in response to a 2-year old FOIA request for information on the FBI’s "Going Dark" program, an initiative to increase the FBI's authority in response to problems the FBI says it's having implementing wiretap and pen register/trap and trace orders on new communications technologies. The documents detail a fully-formed and well-coordinated plan to expand existing surveillance laws and develop new ones. And although they represent only a small fraction of the documents we expect to receive in response to this and a more recent FOIA request, they were released just in time to provide important background information for the House Judiciary Committee’s hearing tomorrow on the Going Dark program.
We first heard about the FBI’s Going Dark program in 2009, when the agency’s Congressional budget request included an additional $9 million to fund the program (on top of the $233.9 million it already received). Late last year, the New York Times linked the program to a plan to expand federal surveillance laws like the Communications Assistance to Law Enforcement Act (CALEA). We issued FOIA requests to the FBI in 2009 for information on Going Dark and in 2010 for information on the agency’s plans to update CALEA. These are the first documents we’ve received since we filed our lawsuit against the agency late last year. The documents provide rare insight into the agency’s multi-year strategy to increase its power to surveil our communications.

Here’s What the Documents Show:

What is the "Going Dark" Program?

The name "Going Dark" is cryptic, and the FBI’s public statements about the program are even more so. Nevertheless, FBI’s Operational Technology Division states that the program is one of the FBI’s "top initiatives" and has "gotten attention so far from high ranking officials in other federal, state, and local agencies and from industry." (GD4, p. 110).1 The FBI has told reporters in emails that Going Dark is:

the program name given to the FBI’s efforts to utilize innovative technology; foster cooperation with industry; and assist our state, local, and tribal law enforcement partners in a collaborative effort to close the growing gap between lawful interception requirements and our capabilities.

(GD2, p1). The FBI has also said that the term "Going Dark" does not refer to a specific capability,

but is a program name for the part of the FBI, Operational Technology Division's (OTD) lawful interception program which is shared with other law enforcement agencies. The term applies to the research and development of new tools, technical support and training initiatives.

(GD2, p 8). Behind this rhetoric, the documents detail a program set up to address the FBI’s allegations that communications providers’ technologies prevent the agency from implementing wiretap and pen register/trap and trace orders – essentially, the FBI alleges it is "'in the dark' by the loss of evidence, that [it] would be lawfully entitled to, due to advances in technology, antiquated ELSUR laws, and or lack of resources, training, [and] personnel," (GD4, p. 120), and the FBI needs new laws and new tools to bring this evidence into the light

Read Full Article

Secure Client Information Exchange

Wednesday, February 16, 2011

India still demanding RIM BES email access

The Indian government has not blocked BlackBerry Enterprise Server services within the country, even though Research In Motion did not meet the 31 January deadline to comply with its demands.

The Indian authorities are still demanding that the BlackBerry maker provide access to corporate email services that use BlackBerry Enterprise Server, according to The Economic Times of India.

In a bid to appease Indian officials, RIM provided access to its BlackBerry Messenger (BBM) service and BlackBerry Internet Service (BIS) email in January. However, the authorities are reportedly not satisfied with the concession and are pushing for full corporate email access.

Read Full Article

Secure Client Information Exchange

secure email

HBGary e-mails are a treasure trove for social engineers

HBGary e-mails are a treasure trove for social engineers

Secure Client Information Exchange: The powerful law firm at the center of the WikiLea...

Secure Client Information Exchange: The powerful law firm at the center of the WikiLea...: "One of the big outstanding questions in the story of the plot to undermine WikiLeaks and Salon's Glenn Greenwald, as well as a separate plan..."