Showing posts with label GCHQ. Show all posts
Showing posts with label GCHQ. Show all posts

Wednesday, August 24, 2016

One small error on the Internet ...



This interesting Guardian article, "The takeover: how police ended up running a paedophile site", is discussed by Bruce Schneier.

Two high-profile, security-savvy paedophiles were taken down based on the smallest of errors.

The paedophile site
“... ran as a company or business,” Rouse says. Senior administrators took charge of individual boards, grouped around categories such as boys or girls, hardcore or non-nude. Users had to upload material at least every 30 days or risk exile. Each of its 45,000 accounts were ranked according to the quality of their output, with a “producer’s area” walled off to all but the most feted.

At the top was one man, “effectively the CEO”. He regularly started his messages with the cheery greeting “hiyas”.
The article explains how that one idiosyncrasy was enough to identify him.

The second paedophile took exhaustive steps to cleanse his uploaded material of any identifying information.
"Access to the full suite of Huckle’s material provided the breakthrough. It was not what he photographed, but what he photographed with. Embedded in some of his images, overlooked when he swept the files of metadata, was the brand and model of his Olympus camera. A tiny clue – but enough.

"Officers exhaustively swept photography sites such as Flickr and TrekEarth for photos taken in south-east Asia using the make and model."
Following that flimsy thread was, it turned out, enough.

I've long been convinced that it's essentially impossible to stay secret on the Internet if a major intelligence agency is on your case.

The article describes a fair amount of labour-intensive Internet searching by Australian police, but it's not hard to see how that could be mostly automated. And if the intelligence agency is allowed AI-based filtering of generic Internet streams, then security through obscurity doesn't really work either.

It would be interesting to know how agencies such as the NSA and GCHQ assess the Internet tradecraft of Islamic fundamentalists. Based on the levels of smartness and training we've heard about to date, I would guess that to any efficient agency with legal access to the right tools the wannabe terrorist is effectively saying, "Here's where I live. Come on in, rummage freely and stay as long as you want."

I think this explains the lack of successful attacks (touch wood) that we've seen in the UK the last few years. It's certainly not for want of attempts.

Of course, if your communications security agency is not up to speed - Hello, Belgium? - even incompetent jihadis can still make it happen.

Friday, April 01, 2016

ISIS infosec seems to be rubbish

How ISIS does information security

CNN reports:
"Last summer, a French student was arrested in Paris on suspicion of a plot to take hostages at a concert hall. His name was Reda Hame. According to a transcript of his interrogation obtained by CNN, Hame claimed he had been provided weapons training, including in the use of Kalashnikovs, by Abaaoud in a park in Raqqa in early June. But he'd backed out of the plot when he arrived in France."
According to security researcher the grugq, CNN further reported:
"Hame also revealed to interrogators that ISIS had set up an elaborate encrypted communication system so that it could keep in touch with its European operatives.

"While with ISIS in Raqqa, he said he was instructed to encrypt communications with a software tool called “Truecrypt,” which authorities found on a thumb drive he had been given by Abaaoud. Hame said he had been taught to copy a message into the software, select an encryption option and then paste the message into a password-protected sharing site."
The grugq asks: "How Crap Is This System?"

It's pretty bad - Errata Security has a post suggesting how any half-decent intelligence agency might hack into this ISIS protocol.

ISIS won't have any autonomous cryptographic capabilities - you have to be a first-world state to do that kind of thing right. It's forced to use third party tools and systems. But it's very, very difficult as amateurs to design a system that the NSA, GCHQ or half a dozen other competent organisations can't address.

If the ISIS operatives are not using a VPN, then a 'listener on the wire' will get the IP addresses of dead-drop users. As Errata Security explained, TrueCrypt volumes are not hard to detect in transit. Metadata like IP addresses lead straight to identities. But I doubt that most VPNs are safe either, not when their logs and traffic can also be monitored.

Perhaps the bad guys should just send a courier, clunky as that sounds. But last I heard, couriers speak in plain, not ciphertext; they say that bugging with microphones is pretty good these days.

I like a one-time pad, but distributing it is the trick. If you send those very long random bit sequences on a USB drive, how do you know the intelligence services haven't covertly grabbed and copied it in transit? And then you're toast.

I begin to see why ISIS has been so singularly unsuccessful in the UK this last decade.

---

Note: from one of the comments: "Counterterror experts who reviewed this protocol tell me it reminds them of what al-Qaeda did for yrs: saving "drafts" in Yahoo inboxes" - (these were apparently in plaintext).

*Head-in-hands*.

---

Our transition to a Planetary Hospital

Interesting and reasonably accessible article via Jess Riedel, "Mutation and Human Exceptionalism: Our Future Genetic Load" by Michael Lynch, GENETICS March 1, 2016. From the abstract:
"What is exceptional about humans is the recent detachment from the challenges of the natural environment and the ability to modify phenotypic traits in ways that mitigate the fitness effects of mutations, e.g., precision and personalized medicine.

"This results in a relaxation of selection against mildly deleterious mutations, including those magnifying the mutation rate itself. The long-term consequence of such effects is an expected genetic deterioration in the baseline human condition, potentially measurable on the timescale of a few generations in westernized societies, and because the brain is a particularly large mutational target, this is of particular concern.

"Ultimately, the price will have to be covered by further investment in various forms of medical intervention. "
The famous population geneticist W. D. Hamilton coined the phrase "Planetary Hospital", explained by Bruce Charlton like this:
"It is becoming hard to avoid the conclusion that we have been, for several generations, living in what WD Hamilton (in Narrow Roads of Gene Land, Volume 2) called the Planetary Hospital - in other words, a world in which almost everyone is suffering from significant genetic damage, and an increasing proportion of the population are suffering from genetic disease. "
The dystopian effects of relaxed selection and the removal of purifying selection are well-documented in the population genetics literature. The effects in just a few generations are, however, slight (c. 1% per generation).

Despite Dr Charlton's vividly-expressed concerns. I like to think we may still avoid Idiocracy.

Saturday, January 24, 2015

Time to enter the Dark Web?



Here are three (mildly) transgressive Internet links you might or might not care to follow:

  1. Recently-deceased Leon Brittan's link to that paedophile ring
  2. The Sun's Page 3 website
  3. Adolf Hitler's "Mein Kampf"

Let's suppose you clicked on any of the above, who knows you've done it?

Ignoring the person standing behind you, then anyone who clicks "back" on your browser, who looks at your browser history or perhaps who inspects your machine's cookies. You can address this problem, partially, by using private browsing - although any downloads will still be on your machine, and who knows about temp files buried away?

If you had logged into Google, or Amazon, or other website owners, then they certainly know where you went, keep extensive records, .. and could be subpoenaed.

They also know your location. You may be unaware that your browser can run a script asking the operating system for the WiFi SSID you're currently attached to. The big players like Google keep vast databases which link SSIDs with their geographical location: this is how Google Maps magically knows where you are. Hard to stop this happening without disabling scripts, which will stop most websites working.

Even if you were maximally careful on your own machine, your ISP - the provider of your Internet service - keeps a record of your site-visits. It can correlate your personal details (name, address, bank details) with your allocated IP address and link that with the websites you visit.

Normally this is like, who cares? These logs get to Terabyte size and no human scans them. They're expensive to keep and are wiped after some months. But the Government is pushing to legally mandate ISPs to keep these records, on everyone, for at least a year - and make them available to the security services. Is it time to get worried?

If the proposal gets through (and there's a good case for it on anti-terrorist grounds) then everyone can potentially be hoovered-up by a log-searching algorithm. Perhaps one day soon they'll start to care about 'mildly-transgressive' Internet behaviour, and your name will go down on a file somewhere. Between Google's profiling us for targeted advertising, and GCHQ tagging us for subversion, most of us might want to draw a line somewhere.

A common response is to suggest using Internet proxies (eg anonymouse, vtunnel) for any web searches beyond the most anodyne. But these are cumbersome and ad-infested - and who knows what the proxy guys are doing with the correlation between your identity and your surfing information (which they have even if your target sites don't),

The best answer is an Internet VPN service, which unfortunately involves paying some modest fee. Your traffic goes through an encrypted tunnel (eg IPsec) and is proxied at the VPN service provider's Internet breakout point. The rest of the Internet doesn't see your IP address so your web searches appear to come from the VPN service provider; meanwhile your ISP only sees your traffic going to the VPN service provider and has no idea where it's destined for afterwards. It only remains to trust the VPN service provider to not keep your transaction logs for any length of time. When 'The Man' comes asking for the last six months of your usage, there's nothing to show. This is quite a big business for a variety of reasons (watching BBC iPlayer when out of the UK is one) and the market leaders appear trustworthy enough - their business depends upon it.

They tell a good story but I somehow doubt that these VPN service providers can really evade an after-the-fact subpoena. The utility is to prevent speculative trawling.

Do we care enough? Today, probably not .. but it's nice to know we have the option going forwards.

Note: Private Internet Access was named PC Magazine's Editor's Choice in 2013. Read their review.