Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Friday, September 13, 2013

NSA masqueraded as Google to spy on web users - report

http://rt.com/news/nsa-disguised-google-spy-801/

The NSA used ‘man in the middle’ hack attacks to impersonate Google and fool web users, leaks have revealed. The technique circumvents encryption by redirecting users to a copycat site which relays all the data entered to NSA data banks.

Brazilian television network Globo News released a report based on classified data divulged by former CIA worker Edward Snowden on Sunday. The report itself blew the whistle on US government spying on Brazilian oil giant Petrobras, but hidden in amongst the data was information the NSA had impersonated Google to get its hands on user data.

Globo TV showed slides from a 2012 NSA presentation explaining how the organization intercepts data and re-routes it to NSA central. One of the convert techniques the NSA uses to do this is a ‘man in the middle’ (MITM) hack attack.

This particular method of intercepting internet communications is quite common among expert hackers as it avoids having to break through encryption. Essentially, NSA operatives log into a router used by an internet service provider and divert ‘target traffic’ to a copycat MITM site, whereupon all the data entered is relayed to the NSA. The data released by Edward Snowden and reported on by Globo News suggests the NSA carried out these attacks disguised as Google.

When the news broke about the NSA gathering information through internet browsers, tech giants such as Google and Yahoo denied complicity, maintaining they only handover data if a formal request is issued by the government.

"As for recent reports that the US government has found ways to circumvent our security systems, we have no evidence of any such thing ever occurring. We provide our user data to governments only in accordance with the law," said Google spokesperson Jay Nancarrow to news site Mother Jones.

Google, along with Microsoft, Facebook and Yahoo, has filed a lawsuit against the Foreign Intelligence Surveillance Court (FISA) to allow them to make public all the data requests made by the NSA.

“Given the important public policy issues at stake, we have also asked the court to hold its hearing in open rather than behind closed doors. It's time for more transparency," Google’s director of law enforcement and information security, Richard Salgado, and the director of public policy and government affairs, Pablo Chavez, wrote in a blog post on Monday.

The tech giants implicated in NSA’s global spying program have denied criticism that they could have done more to resist NSA spying. Marissa Mayer, CEO of Yahoo, claimed that speaking out about the NSA’s activities would have amounted to ‘treason’ at a press conference in San Francisco on Wednesday.

In Yahoo’s defense, she argued that the company had been very skeptical of the NSA’s requests to disclose user data and had resisted whenever possible. Mayer concluded that it was more realistic to work within the system,” rather than fight against it.

Sunday, November 18, 2012

Mainstream media now openly admits the FBI and CIA are reading all your emails

 http://www.naturalnews.com/038020_FBI_surveillance_emails.html#ixzz2CbpoE46Y

(NaturalNews) For years, those of us who have tried to warn the American public that Big Brother monitors all Internet users were demonized, vilified and ridiculed.

Now, the mainstream media has proven us correct.

"The U.S. government -- and likely your own government, for that matter -- is either watching your online activity every minute of the day through automated methods and non-human eavesdropping techniques, or has the ability to dip in as and when it deems necessary -- sometimes with a warrant, sometimes without," ZDNet reported earlier this month. "That tin-foil hat really isn't going to help. Take it off, you look silly."

The Petraeus case

Where's the proof that the government has this capability?

You might recall a fellow by the name of (retired) Gen. David Petraeus. He's been in the news lately.

This four-star general-turned-CIA chief just resigned his post after news broke that he had engaged in an extra-marital affair with is biographer, herself a West Point graduate and former Army officer.

What led to this shocking discovery was Petraeus' use, of all things, Google's online email service, Gmail.

According to federal law, mind you, authorities are not legally permitted to electronically snoop around in your email box.

"The government can't just wander through your emails just because they'd like to know what you're thinking or doing," Stewart Baker, a former assistant secretary at the Homeland Security Department who's now in private law practice, told The Associated Press. "But if the government is investigating a crime, it has a lot of authority to review people's emails."

Or, in the case of the CIA, if the agency wants to track a suspect ostensibly for "national security" purposes. Ditto the NSA.

The wrangling of Petraeus' email account has certainly landed him in a world of trouble, but his story has also, once again, ignited a new the debate over when, how and why governments and law enforcement agencies alike are able to access the email accounts of ordinary citizens - even if they head up the most powerful spy agency in the world.

Granted, experts say "the little people" needn't worry much about having their online presence tracked. Agencies like the CIA generally tend to have bigger fish to fry, so to speak. But nevertheless, the technology to pilfer email accounts at will obviously exists.

"Forget ECHELON, or signals intelligence, or the interception of communications by black boxes installed covertly in data centers," writes Zack Whittaker for ZDNet. "Intelligence agencies and law enforcement bodies can access - thanks to the shift towards Web-based email services in the cloud - but it's not as exciting or as Jack Bauer-esque as one may think or hope for."

(Editor's Note: ECHELON, for those who are unfamiliar with it, is the name of "a global Communications Interception (COMINT) system created by the United States, the United Kingdom, Canada, Australia and New Zealand to routinely and indiscriminately monitor and record all forms of electronic communications worldwide (both military and civilian) and overseen by the National Security Agency," according to one published description of the program.)

How the top CIA official got busted

When he set up his private Gmail account, Petraeus used a pseudonym and composed email messages but never sent them. They were instead saved as drafts. His lover, Paula Broadwell, would then log in under the same account, read the drafts then reply to them in the same manner - as a draft, without actually sending the message.

The exchanges would not be sent across the networks through Google's data centers, which would make it nearly impossible for the NSA or any other ELINT (electronic intelligence) agency (like Britain's GCHQ or the Israeli Mossad) to "read" the messages while they are in transit between accounts.

Other sinister operators - terrorists, pedophiles and the like - have been known to use the same trick to avoid detection, ZDNet reported.

"But surely IP addresses are logged and noted? When emails are sent and received, yes. But the emails were saved in draft and therefore were not sent. However, Google may still have a record of the IP addresses of those who logged into the account," the report said.

In the end, the FBI used a little-know law called the Stored Communications Act, which is part of the Electronic Communications Privacy Act, as the basis for getting a warrant to view Petraeus' private Gmail account. And that's how agents found the stored messages that were never actually sent.

"Once it knew Ms. Broadwell was the sender of the threatening messages, the FBI got a warrant that gave it covert access to the anonymous email account," the BBC's Mark Ward reported.

Sources:

http://www.zdnet.com

http://finance.yahoo.com

http://actionamerica.org/echelon/echelonwhat.html