Submit a link Features Reviews Podcasts Video Forums More ▾

Phone phreakers' anthem

Brad sez, "A few decades ago, phone phreaks spent all of their free time learning about the Bell telephone system and making free phone calls to each other. This song by Bonecage attempts to capture that era, and the footage for the video was contributed by phone phreaks (and ex-phone phreaks) around the world."

Eternal vigilance app for social networks: treating privacy vulnerabilities like other security risks

Social networking sites are Skinner boxes designed to train you to undervalue your privacy. Since all the compromising facts of your life add less than a dollar to the market-cap of the average social network, they all push to add more "sharing" by default, with the result that unless you devote your life to it, you're going to find your personal info shared ever-more-widely by G+, Facebook, Linkedin, and other "social" services.

Arvind Narayanan has proposed a solution to this problem: a two-part system through which privacy researchers publish a steady stream of updates about new privacy vulnerabilities introduced by the social networking companies (part one), and your computer sifts through these and presents you with a small subset of the alerts that pertain to you and your own network use.

Read the rest

US intel chief's insane new secrecy directive forbids intel employees from "unauthorized" contact with reporters


U.S. Director of National Intelligence James Clapper. (Kevin Lamarque/Reuters)

The US Director of National Intelligence has issued a Directive [PDF] that forbids most intelligence community employees from talking to journalists about “intelligence-related information” unless they have explicit authorization to do so.

Intelligence community employees “must obtain authorization for contacts with the media” on any intel-related matters, and “must also report… unplanned or unintentional contact with the media on covered matters,” according to the Directive signed by James Clapper.

Read the rest

HOPE X conference: Dissent in NYC


Emmanuel from 2600 writes, "It should come as no surprise that dissent is playing a prominent role at the HOPE X conference this July in New York. So many technological developments of late involve standing up to authority and questioning the status quo. Whether it's using social media to organize people into doing something worthwhile, exposing security holes in the face of threats and lawsuits, becoming a whistleblower by using the information and technology we have access to, or just getting the word out about the latest laws, restrictions, and threats to our freedom and privacy, a lot of what we talk about constitutes one form or another of dissent. And it feels pretty good and healthy to speak out and share knowledge."

Read the rest

Edward Snowden: "Vladimir Putin must be called to account on surveillance just like Obama"


Vladimir Putin during the nationwide phone-in in Moscow. Photograph: RIA Novosti/Reuters

Today's question-and-answer session on Russian TV between NSA whistleblower Edward Snowden and Russian President Vladimir Putin did not go as Snowden had hoped. "I questioned the Russian president live on TV to get his answer on the record, not to whitewash him," Snowden says in an op-blog in the Guardian:

Read the rest

Appeals court overturns conviction of Andrew “weev” Auernheimer in iPad hacking case


Andrew “Weev” Auernheimer, in 2012. Photo: pinguino.

Notorious hacker and troll weev was released from prison this evening. A federal appeals court today overturned his conviction in a case of significance for all security researchers.

Weev exposed a security flaw in AT&T's website and obtained the personal data of more than 100,000 iPad users. He was charged with violating the Computer Fraud and Abuse Act (CFAA), and sentenced to three and a half years in prison. Today's ruling says prosecutors did not have the right to charge him in a state where none of the alleged crimes occurred.

Read the rest

Glenn Greenwald and Laura Poitras enter the US for first time since Snowden leaks

A first since they began reporting on the material leaked by NSA whistleblower Edward Snowden: Glenn Greenwald and Laura Poitras, landing in the United States. There have been concerns that the US might detain them if they entered the country.

(Disclosure: I'm on the board of the Freedom of the Press Foundation with all three)

Playground removes "safety" rules; fun, development and injuries ensue


The Swanson School in Auckland, NZ, quietly eliminated all the rules against "unsafe play," allowing kids to play swordfight with sticks, ride scooters, and climb trees. It started when the playground structures were torn down to make way for new ones, and the school principal, Bruce McLachlan, noticed that kids were building their own structures out of the construction rubble. The "unsafe" playground has resulted in some injuries, including at least one broken arm, but the parents are very supportive of the initiative. In particular, the parents of the kid with the broken arm made a point of visiting the principal to ask him not to change the playground just because their kid got hurt.

The article in the Canadian National Post notes that Kiwis are less litigious, by and large, than Americans, and that they enjoy an excellent national health service, and says that these two factors are a large contributor to the realpolitik that makes the playground possible. But this is still rather daring by Kiwi standards.

Read the rest

Google Maps' spam problem presents genuine security issues


Bryan Seely, a Microsoft Engineer demonstrated an attack against Google Maps through which he was able to set up fake Secret Service offices in the company's geo-database, complete with fake phone numbers that rang a switch under his control and then were forwarded to real Secret Service offices, allowing him to intercept and record phone-calls made to the Secret Service (including one call from a police officer reporting counterfeit money). Seely was able to attack Google Maps by adding two ATMs to the database through its Google Places crowdsourcing tool, verifying them through a phone verification service (since discontinued by Google), then changing them into Secret Service offices. According to Seely, the disabling of the phone-verification service would not prevent him from conducting this attack again.

As Dune Lawrence points out, this is a higher-stakes version of a common spam-attack on Google Maps practiced by locksmith, carpet cleaning, and home repair services. Spammers flood Google Maps with listing for fake "local" companies offering these services, and rake in high commissions when you call to get service, dispatching actual local tradespeople who often charge more than you were quoted (I fell victim to this once, when I had a key break off in the lock of my old office-door in London and called what appeared to be a "local" locksmith, only to reach a call-center who dispatched a locksmith who took two hours to arrive and charged a huge premium over what I later learned by local locksmiths would have charged).

A detailed post by Dan Austin describes this problem, points out that Google is more than four years late in delivering promised fixes to the problem, and offers solutions of his own. He suggests that the high Google Adwords revenue from spammy locksmiths and other services is responsible for the slow response to the problem.

Read the rest

Spyware increasingly a part of domestic violence

Australian Simon Gittany murdered his girlfriend, Lisa Harnum, after an abusive relationship that involved his surveillance of her electronic communications using off-the-shelf spyware marketed for purposes ranging from keeping your kids safe to spotting dishonest employees. As Rachel Olding writes in The Age, surveillance technology is increasingly a factor in domestic violence, offering abusive partners new, thoroughgoing ways of invading their spouses' privacy and controlling them.

The spyware industry relies upon computers -- laptops, mobile devices, and soon, cars and TVs and thermostats -- being insecure. In this, it has the same goals as the NSA and GCHQ, whose BULLRUN/EDGEHILL program sought to weaken the security of widely used operating systems, algorithms and programs. Every weakness created at taxpayer expense was a weakness that spyware vendors could exploit for their products.

Likewise, the entertainment industry wants devices that are capable of running code that users can't terminate or inspect, so that they can stop you from killing the programs that stop you from saving Netflix streams, running unapproved apps, or hooking unapproved devices to your cable box.

And Ratters, the creeps who hijack peoples' webcams in order to spy on them and blackmail them into sexual performances, also want computers that can run code that users can't stop. And so do identity thieves, who want to run keyloggers on your computer to get your banking passwords. And so do cops, who want new powers to insert malware into criminals' computers.

There are a lot of ways to slice the political spectrum -- left/right, authoritarian/anti-authoritarian, centralist/decentralist. But increasingly, the 21st century is being defined by the split between people who think your computer should do what you tell it, and people who think that you can't be trusted to control your own computer, and so they should be able to run code on it against your will, without your knowledge, and to your detriment.

Pick a side.

Spyware's role in domestic violence [Rachel Olding/The Age]

(via Geek Feminism)

Basecamp, Meetup hit by extortionist's 20Gb/s DDoS

If you're a Basecamp user who couldn't get into your account yesterday, here's why: the company refused to pay ransom to a criminal who hit them with a 20Gb/s denial-of-service flood, apparently by the same person who attacked Meetup, who uses gmail addresses in this pattern: "dari***@gmail.com." Cory 7

Assistant AG admits he doesn't understand what Weev did, but he's sure it's bad

Andrew “weev” Auernheimer is serving a 41-month sentence for visiting a publicly available webpage and revealing that AT&T had not secured its customers' sensitive financial information. Now, weev's lawyers are appealing, and in the opening day's arguments, Assistant US Attorney Glenn Moramarco admitted I don’t even understand what [Auernheimer actually did.]" Then he compared it to blowing up a nuclear power-plant. Cory 33

Self-directed Crypto 101 online course

Crypto 101 is a free online course on practical, applied cryptography: " everything you need to understand complete systems such as SSL/TLS: block ciphers, stream ciphers, hash functions, message authentication codes, public key encryption, key agreement protocols, and signature algorithms." Cory 5

Fedbizopps: the US government's searchable database of defense-contractor opportunities


Dave from the Electronic Frontier Foundation sez, "The government often makes itself more accessible to businesses than the general public. For Sunshine Week, we compiled this guide to using FedBizOpps to keep an eye on surveillance technology contracts."

Fedbizopps is a weird, revealing window into the world of creepy surveillance, arms, and technology contractors who build and maintain the most oppressive and unethical parts of the apparatus of the US government. Everything from drone-testing of biological and chemical weapons to license plate cameras to weaponized bugs and other malware are there. The EFF post also has links to data-mining tools that help estimate just how much money the private arms dealers extract from the tax-coffers.

Read the rest

Samsung Galaxy back-door allows for over-the-air filesystem access


Developers from the Replicant project (a free Android offshoot) have documented a serious software back-door in Samsung's Android phones, which "provides remote access to the data stored on the device." They believe it is "likely" that the backdoor could provide "over-the-air remote control" to "access the phone's file system."

At issue is Samsung's proprietary IPC protocol, used in its modems. This protocol implements a set of commands called "RFS commands." The Replicant team says that it can't find "any particular legitimacy nor relevant use-case" for adding these commands, but adds that "it is possible that these were added for legitimate purposes, without the intent of doing harm by providing a back-door. Nevertheless, the result is the same and it allows the modem to access the phone's storage."

The Replicant site includes proof-of-concept sourcecode for a program that will access the file-system over the modem. Replicant has created a replacement for the relevant Samsung software that does not allow for back-door access.

Read the rest