Manager of World’s Biggest Sovereign Wealth Fund Missing After Glider Crash

March 28th, 2010

Via: BBC:

A search is on in Morocco for a leading member of the Abu Dhabi royal family after a glider he was in crashed into an artificial lake south of Rabat.

Sheikh Ahmed bin Zayed al-Nahayan, a younger brother of Abu Dhabi’s ruler, manages what is thought to be the world’s biggest sovereign wealth fund.

The glider pilot was rescued and is in good condition, state media say.

Sheikh Ahmed was No 27 on Forbes’s list of the world’s most powerful people last year and is in his early 40s.

Abu Dhabi Investment Authority (ADIA), of which the sheikh is managing director, is believed to have assets of around $500-$700bn, including a stake in Britain’s Gatwick airport and residential property in major cities, Reuters news agency reports.

While he is a brother of Sheikh Khalifa bin Zayed, who as well as ruling Abu Dhabi heads the UAE, Sheikh Ahmed is not immediately in line for the succession.


Beijing to Sweeten Stench of Rubbish Crisis with Giant Deodorant Guns

March 28th, 2010

Via: Guardian:

Beijing is to install 100 deodorant guns at a stinking landfill site on the edge of the city in a bid to dampen complaints about the capital’s rubbish crisis.

The giant fragrance sprays will be put in place by May at the Asuwei dump site, one of several hundred tips that are the focus of growing public concerns about sanitation, environmental health and a runaway consumer culture.

Municipal authorities say they will also apply more plastic layers to cover the site in response to furious protests by local residents who have to put up with the stench when the wind blows in their direction.

The high-pressure guns, which can spray dozens of litres of fragrance per minute over a distance of up to 50m, are produced by several Chinese firms and based on German and Italian technology. They are already in use at several landfill sites, but they are merely a temporary fix.

Beijing’s waste problem – and China’s – is expanding as fast as its economy, at about 8% each year. With millions more people now able to afford Starbucks, McDonald’s, Kentucky Fried Chicken and other elements of a western, throwaway lifestyle, the landfill sites and illegal tips that ring the capital are close to overflowing.

Research Credit: sb


CIA Propaganda Strategies for Western Europe on Afghanistan

March 27th, 2010

Via: WikiLeaks:

This classified CIA analysis from March, outlines possible PR-strategies to shore up public support in Germany and France for a continued war in Afghanistan. After the dutch government fell on the issue of dutch troops in Afghanistan last month, the CIA became worried that similar events could happen in the countries that post the third and fourth largest troop contingents to the ISAF-mission. The proposed PR strategies focus on pressure points that have been identified within these countries. For France it is the sympathy of the public for Afghan refugees and women. For Germany it is the fear of the consequences of defeat (drugs, more refugees, terrorism) as well as for Germany’s standing in the NATO. The memo is an recipe for the targeted manipulation of public opinion in two NATO ally countries, written by the CIA. It is classified as Confidential / No Foreign Nationals.


Supply Fears Start to Hit Treasuries

March 27th, 2010

Via: Financial Times:

The bond vigilantes are finally flexing their muscles. A long period of stability for the US government bond market showed signs of cracking this week as a lack of investor appetite for new debt sent the benchmark 10-year yield to its highest level since last June.

For more than a year, analysts have been warning that record sized debt sales by the US Treasury were at odds with a 10-year yield sitting comfortably below 4 per cent. This week, the yield on 10-year notes jumped from 3.65 per cent to a peak of 3.92 per cent on Thursday. On Friday it was 3.87 per cent.

Chart: TreasuriesFalling inflation, rising unemployment, the housing market slump, the Federal Reserve’s policies of a near zero overnight borrowing rate and its purchase of up to $1,700bn in bonds have all helped keep Treasury yields near historic lows.

But this week the mood shifted as yields for $118bn of new US debt were much higher than forecast, sparking overall selling of Treasuries. Sentiment also deteriorated in the UK bond market after the government’s budget ahead of a general election expected in May failed to resolve doubts over future spending and debt reduction.

The term “bond vigilantes” was coined in the 1980s when bond investors pushed up long-term yields to force central banks into taking action to curb inflation. This time, bond investors are less worried about inflation: they are fretting about huge fiscal deficits and the looming bond supply needed to finance them.

“Everyone thought we would see rising rates due to higher inflation, but it appears the bond vigilantes are demanding a higher real rate due to concerns about Treasury issuance,” says George Goncalves, head of fixed income strategy at Nomura Securities.

Worries about the debt loads of developed economies have come into focus this year amid the crisis threatening Greece and other members of the eurozone periphery.

The fact that German Bunds have outperformed both Treasuries and gilts in recent months highlights this increasing worry over public debt. Germany’s budget deficit is much lower than the US and UK and inflation there is also expected to remain low.


Pfizer to Pay $142 Million for Drug Fraud

March 26th, 2010

Pocket lint.

Via: CBC News:

Pharmaceutical giant Pfizer has been ordered to pay $142 million US in damages for fraudulently marketing gabapentin, an anti-seizure drug marketed under the name Neurontin.

A federal jury in Boston ruled Thursday that Pfizer fraudulently marketed the drug and promoted it for unapproved uses. The jury sided with California-based Kaiser Foundation Health Plan Inc. and Kaiser Foundation Hospitals, the first to try a gabapentin case against Pfizer.

Data revealed in a string of U.S. lawsuits indicates the drug was promoted by the drug company as a treatment for for pain, migraines and bipolar disorder — even though it wasn’t effective in treating these conditions and was actually toxic in certain cases, according to the Therapautics Initiative, an independent drug research group at the University of British Columbia.

The trials forced the company to release all of its studies on the drug, including the ones it kept hidden.

A new analysis of those unpublished trials by the Therapeutics Initiative suggests that gabapentin works for one out of every six or eight people who use it, at best. The review also concluded that one in eight people had an adverse reaction to the drug.

“The much larger majority of people will not get any benefit and many of them will have chronic neurotoxicity or poisoning of the brain,” said Dr. Tom Perry of the Therapeutics Initiative.


Computer-Controlled Swarm of Bacteria Builds Tiny Pyramid

March 26th, 2010

Via: IEEE:

Researchers at the NanoRobotics Laboratory of the École Polytechnique de Montréal, in Canada, are putting swarms of bacteria to work, using them to perform micro-manipulations and even propel microrobots.

Led by Professor Sylvain Martel, the researchers want to use flagellated bacteria to carry drugs into tumors, act as sensing agents for detecting pathogens, and operate micro-factories that could perform pharmacological and genetic tests.

They also want to use the bacteria as micro-workers for building things. Things like a tiny step pyramid.

The video below shows some 5000 bacteria moving like a swarm of little fish, working together to transport tiny epoxy bricks and assemble a pyramidal structure — all in 15 minutes. The video was presented at IROS last year, along with a wonderfully titled paper, “A Robotic Micro-Assembly Process Inspired By the Construction of the Ancient Pyramids and Relying on Several Thousands of Flagellated Bacteria Acting as Workers.”

The bacteria, of a type known as magnetotactic, contain structures called magnetosomes, which function as a compass. In the presence of a magnetic field, the magnetosomes induce a torque on the bacteria, making them swim according to the direction of the field. Place a magnetic field pointing right and the bacteria will move right. Switch the field to point left and the bacteria will follow suit.

Each bacterium has flagella capable of generating about 4 picoNewtons. It’s a very small amount of thrust force, but put thousands of bacteria to work together and they can move mountains. Well, micro mountains.

Several research groups are trying to develop MEMS devices that emulate the propulsion mechanisms of bacteria. Martel asks, Why mimic the bacteria when you can use the little things themselves?

Martel and his colleagues developed an electronic microcircuit that contains both the bacteria and an array of conductors that produce magnetic fields. By carefully controlling which conductors are active, the microcircuit can make the bacteria move in specific directions. A computer and an optical microscope provide a feedback loop, tracking the motion of the bacteria and adjusting the conductors to achieve the desired behavior.

In addition to pyramid building, Martel’s bacteria has done some other neat tricks, such as traveling through the bloodstreams of rats, steered by an MRI system, a la “Fantastic Voyage.”

One of their current projects is developing an autonomous bacterial microrobot. They plan to use standard CMOS processes to create a chip containing both electronics and bacteria. The bacteria would reside in micro-reservoirs designed to generate thrust. For control, small conductors inside each reservoir would produce magnetic fields.

Several of these microrobots could then be used to perform tasks collectively, perhaps one day swimming inside our bodies, delivering drugs, detecting disease, and fixing an organ here, a blood vessel there. Who knew bacteria could be good robots?

UPDATE: If you’re wondering which ancient pyramid inspired the researchers — and is shown in the video on the left bottom corner — it’s the Djoser step pyramid, in Egypt, which the researcher note was “an important, initial milestone in the history of man-made structures.”


Social Security to See Payout Exceed Pay-In This Year

March 26th, 2010

Via: New York Times:

The bursting of the real estate bubble and the ensuing recession have hurt jobs, home prices and now Social Security.

This year, the system will pay out more in benefits than it receives in payroll taxes, an important threshold it was not expected to cross until at least 2016, according to the Congressional Budget Office.

Stephen C. Goss, chief actuary of the Social Security Administration, said that while the Congressional projection would probably be borne out, the change would have no effect on benefits in 2010 and retirees would keep receiving their checks as usual.

The problem, he said, is that payments have risen more than expected during the downturn, because jobs disappeared and people applied for benefits sooner than they had planned. At the same time, the program’s revenue has fallen sharply, because there are fewer paychecks to tax.

Analysts have long tried to predict the year when Social Security would pay out more than it took in because they view it as a tipping point — the first step of a long, slow march to insolvency, unless Congress strengthens the program’s finances.

Related: America’s Impending Master Class Dictatorship


WikiLeaks Statement on Recent Events

March 26th, 2010

Via: WikiLeaks:

EDITORIAL:U.S. must stop spying on WikiLeaks

Fri Mar 26 08:44:46 UTC 2010

Over the last few years, WikiLeaks has been the subject of hostile acts by security organizations. In the developing world, these range from the appalling assassination of two related human rights lawyers in Nairobi last March (an armed attack on my compound there in 2007 is still unattributed) to an unsuccessful mass attack by Chinese computers on our servers in Stockholm, after we published photos of murders in Tibet. In the West this has ranged from the overt, the head of Germany’s foreign intelligence service, the BND, threatening to prosecute us unless we removed a report on CIA activity in Kosovo, to the covert, to an ambush by a “James Bond” character in a Luxembourg car park, an event that ended with a mere “we think it would be in your interest to…”.

Developing world violence aside, we’ve become used to the level of security service interest in us and have established procedures to ignore that interest.

But the increase in surveillance activities this last month, in a time when we are barely publishing due to fundraising, are excessive. Some of the new interest is related to a film exposing a U.S. massacre we will release at the U.S. National Press Club on April 5.

The spying includes attempted covert following, photographng, filming and the overt detention & questioning of a WikiLeaks’ volunteer in Iceland on Monday night.

I, and others were in Iceland to advise Icelandic parliamentarians on the Icelandic Modern Media Initiative, a new package of laws designed to protect investigative journalists and internet services from spying and censorship. As such, the spying has an extra poignancy.

The possible triggers:

* our ongoing work on a classified film revealing civilian casualties occurring under the command of the U.S, general, David Petraeus.
* our release of a classified 32 page US intelligence report on how to fatally marginalize WikiLeaks (expose our sources, destroy our reputation for integrity, hack us).
* our release of a classified cable from the U.S. Embassy in Reykjavik reporting on contact between the U.S. and the U.K. over billions of euros in claimed loan guarantees.
* pending releases related to the collapse of the Icelandic banks and Icelandic “oligarchs”.

We have discovered half a dozen attempts at covert surveillance in Reykjavik both by native English speakers and Icelanders. On the occasions where these individuals were approached, they ran away. One had marked police equipment and the license plates for another suspicious vehicle track back to the Icelandic private VIP bodyguard firm Terr. What does that mean? We don’t know. But as you will see, other events are clear.

U.S. sources told Icelandic state media’s deputy head of news, that the State Department was aggressively investigating a leak from the U.S. Embassy in Reykjavik. I was seen at a private U.S Embassy party at the Ambassador’s residence, late last year and it is known I had contact with Embassay staff, after.

On Thursday March 18, 2010, I took the 2.15 PM flight out of Reykjavik to Copenhagen–on the way to speak at the SKUP investigative journalism conference in Norway. After receiving a tip, we obtained airline records for the flght concerned. Two individuals, recorded as brandishing diplomatic credentials checked in for my flight at 12:03 and 12:06 under the name of “US State Department”. The two are not recorded as having any luggage.

Iceland doesn’t have a separate security service. It folds its intelligence function into its police forces, leading to an uneasy overlap of policing and intelligence functions and values.

On Monday 22, March, at approximately 8.30pm, a WikiLeaks volunteer, a minor, was detained by Icelandic police on a wholly insignificant matter. Police then took the opportunity to hold the youth over night, without charge–a highly unusual act in Iceland. The next day, during the course of interrogation, the volunteer was shown covert photos of me outside the Reykjavik restaurant “Icelandic Fish & Chips”, where a WikiLeaks production meeting took place on Wednesday March 17–the day before individuals operating under the name of the U.S. State Department boarded my flight to Copenhagen.

Our production meeting used a discreet, closed, backroom, because we were working on the analysis of a classified U.S. military video showing civilian kills by U.S. pilots. During the interrogation, a specific reference was made by police to the video—which could not have been understood from that day’s exterior surveillance alone. Another specific reference was made to “important”, but unnamed Icelandic figures. References were also made to the names of two senior journalists at the production meeting.

Who are the Icelandic security services loyal to in their values? The new government of April 2009, the old pro-Iraq war government of the Independence party, or perhaps to their personal relationships with peers from another country who have them on a permanment intelligence information drip?

Only a few years ago, Icelandic airspace was used for CIA rendition flights. Why did the CIA think that this was acceptable? In a classified U.S. profile on the former Icelandic Ambassador to the United States, obtained by WikiLeaks, the Ambassador is praised for helping to quell publicity of the CIA’s activities.

Often when a bold new government arises, bureaucratic institutions remain loyal to the old regime and it can take time to change the guard. Former regime loyalists must be discovered, dissuaded and removed. But for the security services, that first vital step, discovery, is awry. Congenitally scared of the light, such services hide their activities; if it is not known what security services are doing, then it is surely impossible to know who they are doing it for.

Our plans to release the video on April 5 proceed.

We have asked relevant authorities in the Unites States and Iceland to explain. If these countries are to be treated as legitmate states, they need to start obeying the rule of law. Now.

—Julian Assange (editor@wikileaks.org)


A London Trader Walks the CFTC Through a Silver Market Manipulation

March 26th, 2010

Via: GATA:

On March 23, 2010, GATA Director Adrian Douglas was contacted by a whistleblower by the name of Andrew Maguire. Maguire is a metals trader in London. He has been told first-hand by traders working for JPMorganChase that JPMorganChase manipulates the precious metals markets, and they have bragged to how they make money doing so.

In November 2009 Maguire contacted the CFTC enforcement division to report this criminal activity. He described in detail the way JPMorgan Chase signals to the market its intention to take down the precious metals. Traders recognize these signals and make money shorting the metals alongside JPM. Maguire explained how there are routine market manipulations at the time of option expiry, non-farm payroll data releases, and COMEX contract rollover, as well as ad-hoc events.

On February 3 Maguire gave two days’ warning by e-mail to Eliud Ramirez, a senior investigator for the CFTC’s Enforcement Division, that the precious metals would be attacked upon the release of the non-farm payroll data on February 5. On February 5, as market events played out exactly as predicted, further e-mails were sent to Ramirez while the manipulation was in progress.

More Commentary: Whistleblower Speaks Out On J. P. Morgan’s Market Manipulation – Reports Violations to the CFTC in the Silver Market

Research Credit: pookie


Governments Using Forged SSL Certificates for Man in the Middle Attack on “Secure” Web Sessions

March 25th, 2010

I don’t believe in web based email solutions that purport to provide strong encryption and/or anonymity. Who knows what their applets and servers are doing? Not me. And if they rely on SSL, well, that’s ok for buying a book online, but no tinfoiler in his right mind would bet his life on SSL.

—The Ugly Truth About Online Anonymity

Via: Wired:

That little lock on your browser window indicating you are communicating securely with your bank or e-mail account may not always mean what you think its means.

Normally when a user visits a secure website, such as Bank of America, Gmail, PayPal or eBay, the browser examines the website’s certificate to verify its authenticity.

At a recent wiretapping convention, however, security researcher Chris Soghoian discovered that a small company was marketing internet spying boxes to the feds. The boxes were designed to intercept those communications — without breaking the encryption — by using forged security certificates, instead of the real ones that websites use to verify secure connections. To use the appliance, the government would need to acquire a forged certificate from any one of more than 100 trusted Certificate Authorities.

The attack is a classic man-in-the-middle attack, where Alice thinks she is talking directly to Bob, but instead Mallory found a way to get in the middle and pass the messages back and forth without Alice or Bob knowing she was there.

The existence of a marketed product indicates the vulnerability is likely being exploited by more than just information-hungry governments, according to leading encryption expert Matt Blaze, a computer science professor at University of Pennsylvania.

“If the company is selling this to law enforcement and the intelligence community, it is not that large a leap to conclude that other, more malicious people have worked out the details of how to exploit this,” Blaze said.

The company in question is known as Packet Forensics, which advertised its new man-in-the-middle capabilities in a brochure handed out at the Intelligent Support Systems (ISS) conference, a Washington, D.C., wiretapping convention that typically bans the press. Soghoian attended the convention, notoriously capturing a Sprint manager bragging about the huge volumes of surveillance requests it processes for the government.

According to the flyer: “Users have the ability to import a copy of any legitimate key they obtain (potentially by court order) or they can generate ‘look-alike’ keys designed to give the subject a false sense of confidence in its authenticity.” The product is recommended to government investigators, saying “IP communication dictates the need to examine encrypted traffic at will.” And, “Your investigative staff will collect its best evidence while users are lulled into a false sense of security afforded by web, e-mail or VOIP encryption.”

Packet Forensics doesn’t advertise the product on its website, and when contacted by Wired.com, asked how we found out about it. Company spokesman Ray Saulino initially denied the product performed as advertised, or that anyone used it. But in a follow-up call the next day, Saulino changed his stance.

“The technology we are using in our products has been generally discussed in internet forums and there is nothing special or unique about it,” Saulino said. “Our target community is the law enforcement community.”

Blaze described the vulnerability as an exploitation of the architecture of how SSL is used to encrypt web traffic, rather than an attack on the encryption itself. SSL, which is known to many as HTTPS, enables browsers to talk to servers using high-grade encryption, so that no one between the browser and a company’s server can eavesdrop on the data. Normal HTTP traffic can be read by anyone in between — your ISP, a wiretap at your ISP, or in the case of an unencrypted Wi-Fi connection, by anyone using a simple packet-sniffing tool.

In addition to encrypting the traffic, SSL authenticates that your browser is talking to the website you think it is. To that end, browser makers trust a large number of Certificate Authorities — companies that promise to check a website operator’s credentials and ownership before issuing a certificate. A basic certificate costs less than $50 today, and it sits on a website’s server, guaranteeing that the BankofAmerica.com website is actually owned by Bank of America. Browser makers have accredited more than 100 Certificate Authorities from around the world, so any certificate issued by any one of those companies is accepted as valid.

To use the Packet Forensics box, a law enforcement or intelligence agency would have to install it inside an ISP, and persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website. Then they could capture your username and password, and be able to see whatever transactions you make online.

Technologists at the Electronic Frontier Foundation, who are working on a proposal to fix this whole problem, say hackers can use similar techniques to steal your money or your passwords. In that case, attackers are more likely to trick a Certificate Authority into issuing a certificate, a point driven home last year when two security researchers demonstrated how they could get certificates for any domain on the internet simply by using a special character in a domain name.

“It is not hard to do these attacks,” said Seth Schoen, an EFF staff technologist. “There is software that is being published for free among security enthusiasts and underground that automate this.”

China, which is known for spying on dissidents and Tibetan activists, could use such an attack to go after users of supposedly secure services, including some Virtual Private Networks, which are commonly used to tunnel past China’s firewall censorship. All they’d need to do is convince a Certificate Authority to issue a fake certificate. When Mozilla added a Chinese company, China Internet Network Information Center, as a trusted Certificate Authority in Firefox this year, it set off a firestorm of debate, sparked by concerns that the Chinese government could convince the company to issue fake certificates to aid government surveillance.

In all, Mozilla’s Firefox has its own list of 144 root authorities. Other browsers rely on a list supplied by the operating system manufacturers, which comes to 264 for Microsoft and 166 for Apple. Those root authorities can also certify secondary authorities, who can certify still more — all of which are equally trusted by the browser.

The list of trusted root authorities includes the United Arab Emirates-based Etilisat, a company that was caught last summer secretly uploading spyware onto 100,000 customers’ BlackBerries.

Soghoian says fake certificates would be a perfect mechanism for countries hoping to steal intellectual property from visiting business travelers. The researcher published a paper on the risks (.pdf) Wednesday, and promises he will soon release a Firefox add-on to notify users when a site’s certificate is issued from an authority in a different country than the last certificate the user’s browser accepted from the site.

EFF’s Schoen, along with fellow staff technologist Peter Eckersley and security expert Chris Palmer, want to take the solution further, using information from around the net so browsers can eventually tell a user with certainty when they are being attacked by someone using a fake certificate. Currently, browsers warn users when they encounter a certificate that doesn’t belong to a site, but many people simply click through the multiple warnings.

“The basic point is that in the status quo there is no double check and no accountability,” Schoen said. “So if Certificate Authorities are doing things that they shouldn’t, no one would know, no one would observe it. We think at the very least there needs to be a double check.”

EFF suggests a regime that relies on a second level of independent notaries to certify each certificate, or an automated mechanism to use anonymous Tor exit nodes to make sure the same certificate is being served from various locations on the internet — in case a user’s local ISP has been compromised, either by a criminal or a government agency using something like Packet Forensics’ appliance.

One of the most interesting questions raised by Packet Forensics’ product is how often do governments use such technology and do Certificate Authorities comply? Christine Jones, the general counsel for Go Daddy — one of the net’s largest issuers of SSL certificates — says her company has never gotten such a request from a government in her eight years at the company.

“I’ve read studies and heard speeches in academic circles that theorize that concept, but we never would issue a ‘fake’ SSL certificate,” Jones said, arguing that would violate the SSL auditing standards and put them at risk of losing their certification. “Theoretically it would work, but the thing is we get requests from law enforcement every day, and in entire time we have been doing this, we have never had a single instance where law enforcement asked us to do something inappropriate.”

VeriSign, the net’s largest Certiicate Authority, echoes GoDaddy.

“Verisign has never issued a fake SSL certificate, and to do so would be against our policies,” said vice president Tim Callan.

Matt Blaze notes that domestic law enforcement can get many records, such as a person’s Amazon purchases, with a simple subpoena, while getting a fake SSL certificate would certainly involve a much higher burden of proof and technical hassles for the same data.

Intelligence agencies would find fake certificates more useful, he adds. If the NSA got a fake certificate for Gmail — which now uses SSL as the default for e-mail sessions in their entirety (not just their logins) — they could install one of Packet Forensics’ boxes surreptitiously at an ISP in, for example, Afghanistan, in order to read all the customer’s Gmail messages. Such an attack, though, could be detected with a little digging, and the NSA would never know if they’d been found out.

Despite the vulnerabilities, experts are pushing more sites to join Gmail in wrapping their entire sessions in SSL.

“I still lock my doors even though I know how to pick the lock,” Blaze said.

More: EFF: New Research Suggests That Governments May Fake SSL Certificates


« Previous Page — Next Page »