A London Trader Walks the CFTC Through a Silver Market Manipulation
March 26th, 2010Via: GATA:
On March 23, 2010, GATA Director Adrian Douglas was contacted by a whistleblower by the name of Andrew Maguire. Maguire is a metals trader in London. He has been told first-hand by traders working for JPMorganChase that JPMorganChase manipulates the precious metals markets, and they have bragged to how they make money doing so.
In November 2009 Maguire contacted the CFTC enforcement division to report this criminal activity. He described in detail the way JPMorgan Chase signals to the market its intention to take down the precious metals. Traders recognize these signals and make money shorting the metals alongside JPM. Maguire explained how there are routine market manipulations at the time of option expiry, non-farm payroll data releases, and COMEX contract rollover, as well as ad-hoc events.
On February 3 Maguire gave two days’ warning by e-mail to Eliud Ramirez, a senior investigator for the CFTC’s Enforcement Division, that the precious metals would be attacked upon the release of the non-farm payroll data on February 5. On February 5, as market events played out exactly as predicted, further e-mails were sent to Ramirez while the manipulation was in progress.
More Commentary: Whistleblower Speaks Out On J. P. Morgan’s Market Manipulation – Reports Violations to the CFTC in the Silver Market
Research Credit: pookie
Governments Using Forged SSL Certificates for Man in the Middle Attack on “Secure” Web Sessions
March 25th, 2010I don’t believe in web based email solutions that purport to provide strong encryption and/or anonymity. Who knows what their applets and servers are doing? Not me. And if they rely on SSL, well, that’s ok for buying a book online, but no tinfoiler in his right mind would bet his life on SSL.
—The Ugly Truth About Online Anonymity
Via: Wired:
That little lock on your browser window indicating you are communicating securely with your bank or e-mail account may not always mean what you think its means.
Normally when a user visits a secure website, such as Bank of America, Gmail, PayPal or eBay, the browser examines the website’s certificate to verify its authenticity.
At a recent wiretapping convention, however, security researcher Chris Soghoian discovered that a small company was marketing internet spying boxes to the feds. The boxes were designed to intercept those communications — without breaking the encryption — by using forged security certificates, instead of the real ones that websites use to verify secure connections. To use the appliance, the government would need to acquire a forged certificate from any one of more than 100 trusted Certificate Authorities.
The attack is a classic man-in-the-middle attack, where Alice thinks she is talking directly to Bob, but instead Mallory found a way to get in the middle and pass the messages back and forth without Alice or Bob knowing she was there.
The existence of a marketed product indicates the vulnerability is likely being exploited by more than just information-hungry governments, according to leading encryption expert Matt Blaze, a computer science professor at University of Pennsylvania.
“If the company is selling this to law enforcement and the intelligence community, it is not that large a leap to conclude that other, more malicious people have worked out the details of how to exploit this,” Blaze said.
The company in question is known as Packet Forensics, which advertised its new man-in-the-middle capabilities in a brochure handed out at the Intelligent Support Systems (ISS) conference, a Washington, D.C., wiretapping convention that typically bans the press. Soghoian attended the convention, notoriously capturing a Sprint manager bragging about the huge volumes of surveillance requests it processes for the government.
According to the flyer: “Users have the ability to import a copy of any legitimate key they obtain (potentially by court order) or they can generate ‘look-alike’ keys designed to give the subject a false sense of confidence in its authenticity.” The product is recommended to government investigators, saying “IP communication dictates the need to examine encrypted traffic at will.” And, “Your investigative staff will collect its best evidence while users are lulled into a false sense of security afforded by web, e-mail or VOIP encryption.”
Packet Forensics doesn’t advertise the product on its website, and when contacted by Wired.com, asked how we found out about it. Company spokesman Ray Saulino initially denied the product performed as advertised, or that anyone used it. But in a follow-up call the next day, Saulino changed his stance.
“The technology we are using in our products has been generally discussed in internet forums and there is nothing special or unique about it,” Saulino said. “Our target community is the law enforcement community.”
Blaze described the vulnerability as an exploitation of the architecture of how SSL is used to encrypt web traffic, rather than an attack on the encryption itself. SSL, which is known to many as HTTPS, enables browsers to talk to servers using high-grade encryption, so that no one between the browser and a company’s server can eavesdrop on the data. Normal HTTP traffic can be read by anyone in between — your ISP, a wiretap at your ISP, or in the case of an unencrypted Wi-Fi connection, by anyone using a simple packet-sniffing tool.
In addition to encrypting the traffic, SSL authenticates that your browser is talking to the website you think it is. To that end, browser makers trust a large number of Certificate Authorities — companies that promise to check a website operator’s credentials and ownership before issuing a certificate. A basic certificate costs less than $50 today, and it sits on a website’s server, guaranteeing that the BankofAmerica.com website is actually owned by Bank of America. Browser makers have accredited more than 100 Certificate Authorities from around the world, so any certificate issued by any one of those companies is accepted as valid.
To use the Packet Forensics box, a law enforcement or intelligence agency would have to install it inside an ISP, and persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website. Then they could capture your username and password, and be able to see whatever transactions you make online.
Technologists at the Electronic Frontier Foundation, who are working on a proposal to fix this whole problem, say hackers can use similar techniques to steal your money or your passwords. In that case, attackers are more likely to trick a Certificate Authority into issuing a certificate, a point driven home last year when two security researchers demonstrated how they could get certificates for any domain on the internet simply by using a special character in a domain name.
“It is not hard to do these attacks,” said Seth Schoen, an EFF staff technologist. “There is software that is being published for free among security enthusiasts and underground that automate this.”
China, which is known for spying on dissidents and Tibetan activists, could use such an attack to go after users of supposedly secure services, including some Virtual Private Networks, which are commonly used to tunnel past China’s firewall censorship. All they’d need to do is convince a Certificate Authority to issue a fake certificate. When Mozilla added a Chinese company, China Internet Network Information Center, as a trusted Certificate Authority in Firefox this year, it set off a firestorm of debate, sparked by concerns that the Chinese government could convince the company to issue fake certificates to aid government surveillance.
In all, Mozilla’s Firefox has its own list of 144 root authorities. Other browsers rely on a list supplied by the operating system manufacturers, which comes to 264 for Microsoft and 166 for Apple. Those root authorities can also certify secondary authorities, who can certify still more — all of which are equally trusted by the browser.
The list of trusted root authorities includes the United Arab Emirates-based Etilisat, a company that was caught last summer secretly uploading spyware onto 100,000 customers’ BlackBerries.
Soghoian says fake certificates would be a perfect mechanism for countries hoping to steal intellectual property from visiting business travelers. The researcher published a paper on the risks (.pdf) Wednesday, and promises he will soon release a Firefox add-on to notify users when a site’s certificate is issued from an authority in a different country than the last certificate the user’s browser accepted from the site.
EFF’s Schoen, along with fellow staff technologist Peter Eckersley and security expert Chris Palmer, want to take the solution further, using information from around the net so browsers can eventually tell a user with certainty when they are being attacked by someone using a fake certificate. Currently, browsers warn users when they encounter a certificate that doesn’t belong to a site, but many people simply click through the multiple warnings.
“The basic point is that in the status quo there is no double check and no accountability,” Schoen said. “So if Certificate Authorities are doing things that they shouldn’t, no one would know, no one would observe it. We think at the very least there needs to be a double check.”
EFF suggests a regime that relies on a second level of independent notaries to certify each certificate, or an automated mechanism to use anonymous Tor exit nodes to make sure the same certificate is being served from various locations on the internet — in case a user’s local ISP has been compromised, either by a criminal or a government agency using something like Packet Forensics’ appliance.
One of the most interesting questions raised by Packet Forensics’ product is how often do governments use such technology and do Certificate Authorities comply? Christine Jones, the general counsel for Go Daddy — one of the net’s largest issuers of SSL certificates — says her company has never gotten such a request from a government in her eight years at the company.
“I’ve read studies and heard speeches in academic circles that theorize that concept, but we never would issue a ‘fake’ SSL certificate,” Jones said, arguing that would violate the SSL auditing standards and put them at risk of losing their certification. “Theoretically it would work, but the thing is we get requests from law enforcement every day, and in entire time we have been doing this, we have never had a single instance where law enforcement asked us to do something inappropriate.”
VeriSign, the net’s largest Certiicate Authority, echoes GoDaddy.
“Verisign has never issued a fake SSL certificate, and to do so would be against our policies,” said vice president Tim Callan.
Matt Blaze notes that domestic law enforcement can get many records, such as a person’s Amazon purchases, with a simple subpoena, while getting a fake SSL certificate would certainly involve a much higher burden of proof and technical hassles for the same data.
Intelligence agencies would find fake certificates more useful, he adds. If the NSA got a fake certificate for Gmail — which now uses SSL as the default for e-mail sessions in their entirety (not just their logins) — they could install one of Packet Forensics’ boxes surreptitiously at an ISP in, for example, Afghanistan, in order to read all the customer’s Gmail messages. Such an attack, though, could be detected with a little digging, and the NSA would never know if they’d been found out.
Despite the vulnerabilities, experts are pushing more sites to join Gmail in wrapping their entire sessions in SSL.
“I still lock my doors even though I know how to pick the lock,” Blaze said.
More: EFF: New Research Suggests That Governments May Fake SSL Certificates
Pope Failed to Defrock an American Priest Who Molested Hundreds of Deaf Boys
March 25th, 2010Via: Telegraph:
The sex abuse scandal enveloping the Catholic Church moved closer to Pope Benedict XVI today with revelations that in the 1990s the then Cardinal Joseph Ratzinger failed to defrock an American priest who molested hundreds of deaf boys, despite receiving letters from a number of American bishops pleading with him to act.
Internal correspondence from bishops in Wisconsin directly to Cardinal Ratzinger, warning him and other top Vatican officials that failure to act could embarrass the church, have been unearthed as part of a lawsuit, according to The New York Times.
The case, against the Archdiocese of Milwaukee, involves the Reverend Lawrence Murphy, who worked at the St John’s School for the Deaf in St Francis, Wisconsin, from 1950 to 1974, starting as a teacher and rising to director.
He allegedly molested up to 200 pupils, preying on his victims in their dormitories, on class excursions and even at his mother’s country house.
Britain: Teacher ‘Shot Dead’ In School Science Stunt
March 25th, 2010Remember this one?
Children Traumatized by ‘War of Worlds’ Abduction of Teacher
Via: Sky / Yahoo:
A school has been forced to apologise after faking the murder of a teacher that terrified pupils thought was real.
Children as young as 10 – including one whose dad is said to have been shot dead – were left in tears as a science teacher was ‘gunned down’ in the playground.
But it turned out to be a stunt organised as part of a science project at Blackminster Middle School in Evesham.
Colleagues pretended to try and resuscitate ‘victim’ Richard Kent as the traumatised kids were led away.
Ten minutes later he was paraded unharmed before the stunned youngsters in the school hall.
Headteacher Terry Hollands told Sky News Online that Mr Kent is a popular teacher who often “plays the dame”.
He has admitted the violent role play was “a step too far” amid complaints from parents.
Horrified pupils have posted comments about the stunt on social networking site Facebook.
One called it “sick”, while another wrote: “Most of us were so scared we were crying.”
Mr Hollands has apologised for upsetting the children and vowed not to repeat the trick, in which a clapper board was used to simulate gunfire.
He said: “On reflection the time lag between the clapper board and the hall was too long.”
“It should have been seconds rather than minutes so it was made instantly clear what had happened.”
Mr Hollands confirmed the school will not use violent role play exercises in the future.
Potato or Tomato?
March 25th, 2010Research Credit: ottilie
Cryptogon Readers Send Contributions
March 25th, 2010Thank you.
MW $20
LJ $10
Cryptogon Reader Signs Up for Hosting with BlueHost
March 25th, 2010Thanks to the owner of jessicagrable.com for signing up for hosting with BlueHost. Cryptogon received $90.
Loose Units in Hemet Torching City Vehicles, Setting Potentially Deadly Traps for Police
March 25th, 2010Via: AP:
Four municipal trucks were set ablaze in a rural Riverside County town plagued by bizarre booby trap attempts to kill police officers, and authorities said Wednesday the fire may be linked to the earlier attacks.
“Everyone is worried, everyone is being careful,” Hemet police Lt. Duane Wisehart said. “You get scared a little bit and then you get angry. It keeps happening.”
Someone called police around 11:10 p.m. Tuesday to report a fire in the parking lot at Hemet City Hall, located within two blocks of the police department, Police Chief Richard Dana said. No one was hurt.
Police were working with state and federal investigators to determine the cause of the blaze, which sent flames several feet above the trucks in the cab and hood area. The white trucks were for use by code enforcement officers.
Early indications were that some kind of flammable substance was used and not an explosive, Dana said.
Hemet, a traditionally quiet retirement city about 90 miles southeast of Los Angeles, has been rocked by a series of booby trap attacks against police officers in recent weeks.
“We are operating under the theory (the fire) is connected to the other assaults,” Dana said.
On Dec. 31, a natural gas pipe was rerouted into the headquarters of a gang task force. The building filled with flammable vapor, but an officer smelled the danger before anyone was hurt.
In a second attack, some kind of ballistic device rigged to a security fence at the same building went off when an officer opened the gate, but the bullet missed.
The third attack involved a deadly device found under a police officer’s unmarked car after the officer drove to a convenience store.
Dana said there has been at least one other booby trap uncovered, but he declined to release details. In the past week or so, officers have received threats daily, either on their non-emergency telephone lines or via e-mail.
“They say things like, ‘It’s too bad they missed, the next one’s gonna get you,'” Dana said.
Investigators believe the attacks are the work of more than one individual, partly because of the sheer volume of activity.
Wisehart said a confidential informant last week overheard two people talking about how they were going to blow up a Hemet police car over the weekend. The informant told the Riverside County Sheriff’s deputies, who notified Hemet authorities.
Agents were working to determine if all the trucks in Tuesday’s fire were set ablaze at once or if the fire had gone from one vehicle to the next, said Keith Krolczyk, resident agent in charge of the Bureau of Alcohol, Tobacco, Firearms and Explosives in Riverside. He said the vehicles were “severely damaged.”
Police initially suspected the Vagos, California’s largest outlaw motorcycle gang, may be involved in the booby trap attacks. Authorities last week arrested 35 members of the Vagos in Riverside County as part of a crackdown across the state and in Arizona, Nevada and Utah. The district attorney’s office was still reviewing cases and did not immediately know how many people had been charged.
Gang enforcement officers monitored a group of gang members at a funeral two days before the first attack, leading investigators to wonder if the gang felt affronted.
But Dana on Wednesday distanced himself from the theory.
“We have since started looking at other things” he said. “They are a group that is on the investigation list but there are other groups, too.”
A $200,000 reward has been offered for information leading to the arrest and conviction of those responsible for the attacks.
WikiLeaks Indicating Their Personnel Are Under Physical Surveillance
March 25th, 2010There is a WikiLeaks tweet related to a, “Pentagon murder-coverup” that isn’t appearing in their feed, however, it does show up as an individual tweet via the permalink. It states:
# WikiLeaks to reveal Pentagon murder-coverup at US National Press Club, Apr 5, 9am; contact press-club@sunshinepress.org
It was posted at 6:43 AM Mar 22nd.
The other recent tweets are below.
Via: Twitter:
# To those worrying about us–we’re fine, and will issue a suitable riposte shortly. about 6 hours ago via bit.ly
# We have airline records of the State Dep/CIA tails. Don’t think you can get away with it. You cannot. This is WikiLeaks.
# We have been shown secret photos of our production meetings and been asked specific questions during detention related to the airstrike.
# If you know more about the operations against us, contact https://secure.wikileaks.org/
# One related person was detained for 22 hours. Computer’s seized.That’s http://www.skup.no
# Two under State Dep diplomatic cover followed our editor from Iceland to http://skup.no on Thursday.
# If anything happens to us, you know why: it is our Apr 5 film. And you know who is responsible.
# WikiLeaks is currently under an aggressive US and Icelandic surveillance operation. Following/photographing/filming/detaining.
Thanks, From the Morgue.
Saudis Claim to Have Stopped Attacks on Energy Infrastructure
March 24th, 2010Via: Reuters:
Saudi Arabia said it had arrested 113 al Qaeda militants including suicide bombers who had been planning attacks on energy facilities in the world’s top oil exporter.


