Feds Are Suspects in New Malware That Attacks Tor Anonymity
August 5th, 2013Update: Phoned Home to NSA
Really?!
I find it very hard to believe that this is some sort of screw up. If you don’t know much about this type of thing, you might think, “Oh the government is incompetent, so someone made a mistake and used one of their own IPs for this attack.” No way. The whole point of something like this would be deniability from top to bottom. They definitely have extensive resources for hiding their attacks.
Someone must want people to know who did this. For what reason, though, I have no idea.
Via: Ars Technica:
Malware planted on the servers of Freedom Hosting—the “hidden service” hosting provider on the Tor anonymized network brought down late last week—may have de-anonymized visitors to the sites running on that service. This issue could send identifying information about site visitors to an Internet Protocol address that was hard-coded into the script the malware injected into browsers. And it appears the IP address in question belongs to the National Security Agency (NSA).
This revelation comes from analysis done collaboratively by Baneki Privacy Labs, a collective of Internet security researchers, and VPN provider Cryptocloud. When the IP address was uncovered in the JavaScript exploit—which specifically targets Firefox Long-Term Support version 17, the version included in Tor Browser Bundle—a source at Baneki told Ars that he and others reached out to the malware and security community to help identify the source.
Initial investigations traced the address to defense contractor SAIC, which provides a wide range of information technology and C4ISR (Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance) support to the Department of Defense. The geolocation of the IP address corresponds to an SAIC facility in Arlington, Virginia.
Further analysis using a DNS record tool from Robotex found that the address was actually part of several blocks of IP addresses permanently assigned to the NSA. This immediately spooked the researchers.
—
Via: Wired:
Security researchers tonight are poring over a piece of malicious software that takes advantage of a Firefox security vulnerability to identify some users of the privacy-protecting Tor anonymity network.
The malware showed up Sunday morning on multiple websites hosted by the anonymous hosting company Freedom Hosting. That would normally be considered a blatantly criminal “drive-by” hack attack, but nobody’s calling in the FBI this time. The FBI is the prime suspect.
“It just sends identifying information to some IP in Reston, Virginia,” says reverse-engineer Vlad Tsrklevich. “It’s pretty clear that it’s FBI or it’s some other law enforcement agency that’s U.S.-based.”
If Tsrklevich and other researchers are right, the code is likely the first sample captured in the wild of the FBI’s “computer and internet protocol address verifier,” or CIPAV, the law enforcement spyware first reported by WIRED in 2007.
Court documents and FBI files released under the FOIA have described the CIPAV as software the FBI can deliver through a browser exploit to gathers information from the target’s machine and send it to an FBI server in Virginia. The FBI has been using the CIPAV since 2002 against hackers, online sexual predator, extortionists and others, primarily to identify suspects who are disguising their location using proxy servers or anonymity services, like Tor.
The code has been used sparingly in the past, which kept it from leaking out and being analyzed or added to anti-virus databases.
FBI Agents Gave Informants Permission to Break the Law Thousands of Times in 2011
August 4th, 2013Via: USA Today:
The FBI gave its informants permission to break the law at least 5,658 times in a single year, according to newly disclosed documents that show just how often the nation’s top law enforcement agency enlists criminals to help it battle crime.
The U.S. Justice Department ordered the FBI to begin tracking crimes by its informants more than a decade ago, after the agency admitted that its agents had allowed Boston mobster James “Whitey” Bulger to operate a brutal crime ring in exchange for information about the Mafia. The FBI submits that tally to top Justice Department officials each year, but has never before made it public.
Agents authorized 15 crimes a day, on average, including everything from buying and selling illegal drugs to bribing government officials and plotting robberies. FBI officials have said in the past that permitting their informants — who are often criminals themselves — to break the law is an indispensable, if sometimes distasteful, part of investigating criminal organizations.
Britain: Companies Give GCHQ Unlimited Access to Data on Undersea Fiber Optic Cables
August 3rd, 2013Via: Guardian:
Some of the world’s leading telecoms firms, including BT and Vodafone, are secretly collaborating with Britain’s spy agency GCHQ, and are passing on details of their customers’ phone calls, email messages and Facebook entries, documents leaked by the whistleblower Edward Snowden show.
BT, Vodafone Cable, and the American firm Verizon Business – together with four other smaller providers – have given GCHQ secret unlimited access to their network of undersea cables. The cables carry much of the world’s phone calls and internet traffic.
In June the Guardian revealed details of GCHQ’s ambitious data-hoovering programmes, Mastering the Internet and Global Telecoms Exploitation, aimed at scooping up as much online and telephone traffic as possible. It emerged GCHQ was able to tap into fibre-optic cables and store huge volumes of data for up to 30 days. That operation, codenamed Tempora, has been running for 20 months.
On Friday Germany’s Süddeutsche newspaper published the most highly sensitive aspect of this operation – the names of the commercial companies working secretly with GCHQ, and giving the agency access to their customers’ private communications. The paper said it had seen a copy of an internal GCHQ powerpoint presentation from 2009 discussing Tempora.
The document identified for the first time which telecoms companies are working with GCHQ’s “special source” team. It gives top secret codenames for each firm, with BT (“Remedy”), Verizon Business (“Dacron”), and Vodafone Cable (“Gerontic”). The other firms include Global Crossing (“Pinnage”), Level 3 (“Little”), Viatel (“Vitreous”) and Interoute (“Streetcar”). The companies refused to comment on any specifics relating to Tempora, but several noted they were obliged to comply with UK and EU law.
NSA Collects ‘Word for Word’ Every Domestic Communication, Says Former Analyst
August 3rd, 2013Via: PBS:
JUDY WOODRUFF: Both Binney and Tice suspect that today, the NSA is doing more than just collecting metadata on calls made in the U.S. They both point to this CNN interview by former FBI counterterrorism agent Tim Clemente days after the Boston Marathon bombing. Clemente was asked if the government had a way to get the recordings of the calls between Tamerlan Tsarnaev and his wife.
TIM CLEMENTE, former FBI counterterrorism agent: On the national security side of the house, in the federal government, you know, we have assets. There are lots of assets at our disposal throughout the intelligence community and also not just domestically, but overseas. Those assets allow us to gain information, intelligence on things that we can’t use ordinarily in a criminal investigation.
All digital communications are — there’s a way to look at digital communications in the past. And I can’t go into detail of how that’s done or what’s done. But I can tell you that no digital communication is secure.
JUDY WOODRUFF: Tice says after he saw this interview on television, he called some former workmates at the NSA.
RUSSELL TICE: Well, two months ago, I contacted some colleagues at NSA. We had a little meeting, and the question came up, was NSA collecting everything now? Because we kind of figured that was the goal all along. And the answer came back. It was, yes, they are collecting everything, contents word for word, everything of every domestic communication in this country.
JUDY WOODRUFF: Both of you know what the government says is that we’re collecting this — we’re collecting the number of phone calls that are made, the e-mails, but we’re not listening to them.
WILLIAM BINNEY: Well, I don’t believe that for a minute. OK?
I mean, that’s why they had to build Bluffdale, that facility in Utah with that massive amount of storage that could store all these recordings and all the data being passed along the fiberoptic networks of the world. I mean, you could store 100 years of the world’s communications here. That’s for content storage. That’s not for metadata.
Metadata if you were doing it and putting it into the systems we built, you could do it in a 12-by-20-foot room for the world. That’s all the space you need. You don’t need 100,000 square feet of space that they have at Bluffdale to do that. You need that kind of storage for content.
JUDY WOODRUFF: So, what does that say, Russell Tice, about what the government — you’re saying — your understanding is of what the government does once these conversations take place, is it your understanding they’re recorded and kept?
RUSSELL TICE: Yes, digitized and recorded and archived in a facility that is now online. And they’re kind of fibbing about that as well, because Bluffdale is online right now.
And that’s where the information is going. Now, as far as being able to have an analyst look at all that, that’s impossible, of course. And I think, semantically, they’re trying to say that their definition of collection is having literally a physical analyst look or listen, which would be disingenuous.
Serco: The Company That Is Running Britain
August 3rd, 2013Via: Guardian:
From prisons to rail franchises and even London’s Boris bikes, Serco is a giant global corporation that has hoovered up outsourced government contracts. Now the NHS is firmly in its sights. But it stands accused of mismanagement, lying and even charging for non-existent work.
Research Credit: afterhours
Albert Einstein Did Not Want to Associate with Israeli Terrorists
August 3rd, 2013I was able to find the letter on Sotheby’s site: 21 June 2007, 10:00 AM, New York, 159 Einstein, Albert.
Via: Deir Yassin Remembered:
Prior to the creation of the State of Israel, two Jewish terrorist groups were working to cleanse Palestine of its Arab inhabitants and its British occupiers. The more brutal of these groups was Lohamei Herut Yisrael (Fighters for the Freedom of Israel) also known as the LEHI or the Stern Gang after its founder Avraham Stern.
Much of the financial support for these Jewish terrorists came from the United States. The Stern Gang received money collected under the more perfidious name, American Friends of the Fighters for the Freedom of Israel. Mr. Shepard Rifkin was the executive director after the UN Partition of Palestine and prior to the creation of Israel in May 1948.
Against his better judgment Rifkin solicited Albert Einstein to help the Stern Gang raise American money for arms to drive out the Arabs and help create a Jewish state. On April 10th, the day after the infamous massacre of Arabs at Deir Yassin, Einstein replied calling the Stern Gang terrorists and misled criminals.
Einstein’s single-page letter on his embossed stationery (see below) was auctioned at Sotheby’s on June 21, 2007. It was purchased by Daniel McGowan, executive director of Deir Yassin Remembered, for $8,500 plus $1,700 commission and $175 shipping and has since been resold.
Research Credit: almaverdad2
Major Outage on Several Webhosting Companies Owned by Endurance International Group
August 2nd, 2013There’s a huge webhosting outage this morning on domains associated with Endurance International Group companies. BlueHost is one of those companies, and both cryptogon.com and cryptogon.net have been affected.
The sites are going up and down, so if you notice this, there’s no need to let me know. Just try back in a couple of hours and they will probably/hopefully have this sorted out.
Al-Qaeda Backers Receive U.S. Government Contracts in Afghanistan
August 2nd, 2013Via: Bloomberg:
Supporters of the Taliban and al-Qaeda in Afghanistan have been getting U.S. military contracts, and American officials are citing “due process rights” as a reason not to cancel the agreements, according to an independent agency monitoring spending.
The U.S. Army Suspension and Debarment Office has declined to act in 43 such cases, John Sopko, the Special Inspector General for Afghanistan Reconstruction, said today in a letter accompanying a quarterly report to Congress.
“I am deeply troubled that the U.S. military can pursue, attack, and even kill terrorists and their supporters, but that some in the U.S. government believe we cannot prevent these same people from receiving a government contract,” Sopko said.
The 236-page report and Sopko’s summary provide one of the watchdog agency’s most critical appraisals of U.S. performance in helping to build a stable Afghanistan as the Pentagon prepares to withdraw combat troops by the end of next year.
“There appears to be a growing gap between the policy objectives of Washington and the reality of achieving them in Afghanistan, especially when the government must hire and oversee contractors to perform its mission,” said Sopko, whose post was mandated by Congress.
Research Credit: conceptualdecay
‘Not a Crisis, but an Economic Transition’: Australia to Impose Levy on Bank Deposits
August 2nd, 2013Via: BBC:
Australia has unveiled a levy on some bank deposits to raise money towards a fund aimed at safeguarding against a banking collapse.
Deposits up to A$250,000 will have to pay a levy of 0.05% from January 2016.
It will be imposed on banks and not account holders. But banks have warned costs may be passed on to customers.
The move comes as the government warned of slower economic growth and a much bigger budget deficit than it had previously forecast.
Australia’s economic growth over the past few years has been powered mainly by the success of its resources sector.
Demand from countries such as China resulted in a commodities boom – which helped sustain the country’s growth through the global financial crisis.
However, growth in those economies has slowed recently, driving down demand for commodities as well as their prices.
That has not only affected Australia’s economic growth but also hurt the government’s tax revenues.
On Friday, the government lowered its growth forecast. It now expects the economy to grow by 2.5% in the current financial year, down from its previous projection of 2.75%.
It warned that slowing economic growth was likely to result in a rise in unemployment.
“Australia is undergoing an economic transition. Not a crisis, but an economic transition that needs careful economic management,” Mr Bowen said.
“This transition has been brought about by the China mining investment boom coming to an end.”
He added that as expansion in the mining sector slows, “non-mining sectors of the economy will need to lead growth in future”.
Sweden: Peak Garbage
August 2nd, 2013The number of times that the word oil appears in this piece: Zero. A lot of that stuff that they’re burning is made out of petroleum. In other words, they’re burning a lot of oil.
Via: New York Times:
This is a city that imports garbage. Some comes from England, some from Ireland. Some is from neighboring Sweden. It even has designs on the American market.
“I’d like to take some from the United States,” said Pal Mikkelsen, in his office at a huge plant on the edge of town that turns garbage into heat and electricity. “Sea transport is cheap.”
Oslo, a recycling-friendly place where roughly half the city and most of its schools are heated by burning garbage — household trash, industrial waste, even toxic and dangerous waste from hospitals and drug arrests — has a problem: it has literally run out of garbage to burn.
The problem is not unique to Oslo, a city of 1.4 million people. Across Northern Europe, where the practice of burning garbage to generate heat and electricity has exploded in recent decades, demand for trash far outstrips supply. “Northern Europe has a huge generating capacity,” said Mr. Mikkelsen, 50, a mechanical engineer who for the last year has been the managing director of Oslo’s waste-to-energy agency.
Yet the fastidious population of Northern Europe produces only about 150 million tons of waste a year, he said, far too little to supply incinerating plants that can handle more than 700 million tons. “And the Swedes continue to build” more plants, he said, a look of exasperation on his face, “as do Austria and Germany.”
Stockholm, to the east, has become such a competitor that it has even managed to persuade some Norwegian municipalities to deliver their waste there. By ship and by truck, countless tons of garbage make their way from regions that have an excess to others that have the capacity to burn it and produce energy.
“There’s a European waste market — it’s a commodity,” said Hege Rooth Olbergsveen, the senior adviser to Oslo’s waste recovery program. “It’s a growing market.”
…
In a hierarchy of environmental goals, Mr. Haltbrekken said, producing less garbage should take first place, while generating energy from garbage should be at the bottom. “The problem is that our lowest priority conflicts with our highest one,” he said.
“So now we import waste from Leeds and other places, and we also had discussions with Naples,” he added. “We said, ‘O.K., so we’re helping the Neapolitans,’ but that’s not a long-term strategy.”


