Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Friday, March 14, 2014

The Gaping Holes in HTTPS and SSL Security!

Scott Ogrin, a blogger, who is a software engineer as well as an electrical and computer engineer with a BSEE and MSEE, breaks it down for you in the following article:

“ In this day and age of well-known NSA spying, everyone keeps saying that the only way to be safe is to use SSL/TLS, commonly known as "browsing with https://".

The sad reality is that HTTPS does virtually nothing to protect you from the prying eyes of alphabet soup agencies - or anybody else with enough knowledge about how these supposedly "secure" connections actually work.

It's true that connecting to web sites with SSL will certainly prevent "script kiddies" and other more winky opponents from eavesdropping on your surfing or otherwise interfering in your affairs. But as for the Real Bad Guys, forget it...

We shall begin by taking a brief dive down the rabbit hole of SSL, hopefully in a way that will make sense to even the least technically inclined among us.

This issue is, after all, so extremely important that I think everyone needs to understand what is really going on, and how web security actually works, without needing a PhD in cryptography, computer science, or engineering!

Our story begins with a little e-mail I received the other day. The basic message can be found here:
Microsoft Security Advisory (2880823)

Of course, the idea that Microsoft of all companies is warning me about security is kind of laughable, so I didn't pay much attention. Nevertheless, there was this little voice in the back of my mind that kept pestering me, so I decided to dig in and see what all the hoopla was about... or indeed if any hoopla was even warranted.
“Microsoft is announcing a policy change to the Microsoft Root Certificate Program. The new policy will no longer allow root certificate authorities to issue X.509 certificates using the SHA-1 hashing algorithm for the purposes of SSL and code signing after January 1, 2016. Using the SHA-1 hashing algorithm in digital certificates could allow an attacker to spoof content, perform phishing attacks, or perform man-in-the-middle attacks.

Microsoft recommends that certificate authorities no longer sign newly generated certificates using the SHA-1 hashing algorithm and begin migrating to SHA-2. Microsoft also recommends that customers replace their SHA-1 certificates with SHA-2 certificates at the earliest opportunity. Please see the Suggested Actions section of this advisory for more information.
Okay, so that's probably like trying to read a foreign language to most people. Even I didn't understand exactly how these hashing algorithms were used with SSL. So, I started digging. What I found nearly floored me:

MD5 considered harmful today: Creating a rogue CA certificate

Now, if you thought the M$ advisory was confusing, take a peek at the above link.

WOW! That's wild.

In summary, way back in 2008, some smart people figured out a way to make themselves a Fake SSL Certificate Authority, and they accomplished this feat by using a weakness in the MD5 hashing algorithm.  [...]
First, let's define some terms - hopefully in Plain English:

SSL Web Site Certificate

This is a digital certificate, with a digital signature, that verifies that a website is who they say they are. When you connect to a web site using SSL (HTTPS), your browser says, "Papers, please!" The remote site then sends the SSL Web Site Certificate to your browser. Your browser then verifies the authenticity of this "passport". Once verified, encrypted communications ensue. The point of the SSL Web Site Certificate is that under no circumstances should anyone else be able to create a valid, signed certificate for a web site that they do not own and operate. In order to obtain an SSL Web Site Cert, you must verify by varied means that you are the owner and operator of the web site involved. So, using HTTPS is not only for encryption of communications, but also a way to verify that the site you are communicating with is the Real Thing, and not an imposter. And of course you must pay for the certificate!

Certificate Authority (CA) Root Certificate

This is also a digital certificate, with a digital signature... But in this case, this certificate can be used to create and digitally sign normal SSL Web Site Certificates. This is the kind of certificate that a CA (Certificate Authority) has. These certificates also get passed to browser makers, and are then included in your web browser. This is so that when your browser receives an SSL Web Site cert, it can use the CA Root Certificate to verify that the Web Site Cert is in fact valid.

Certificate Authority (CA)

A CA is the kind of web site from which you would buy a valid, secure SSL Web Site Certificate to use for HTTPS on your site. For example: Verisign.com, RapidSSL.com, Geotrust.com, etc. are Certificate Authorities. They have CA Root Certificates for generating and signing valid SSL Web Site Certificates.

It's helpful to understand that with all these certificates, there is a "chain of command". SSL Web Site Certificates are validated and authenticated using CA Root Certificates. CA Root Certificates are validated with yet higher-authority certificates, all the way up the pyramid to The One Great Root Certificate, which is like the God of Certificates. Thus, each lower-ranking certificate is verified up the chain of command. This all happens behind the scenes, and you have no idea it's occurring.
Piece of cake, right?

Now, where do these hash algorithms like MD5, SHA-1, and SHA-2 come into play?

All certificates contain information, like:
  • Web site domain (www.mysite.com)
  • Site location (country, state, etc.)
  • Site owner info (company name)
  • Period of validity
This information is verified before a certificate is issued. Once verified, a hash of the data is generated. This hash acts as the digital signature for the certificate. The only thing you really need to understand about hash algorithms is that what is supposed to happen is this:
  1. Data of any length (30 characters, 3000 characters, 40MB, whatever) is passed into the hash algorithm
  2. The hash algorithm chops up the data and mathematically processes it, thereby spitting out a signature – or digital fingerprint – of the data
  3. The hash of no two chunks of data should ever be the same – just as the fingerprints of no two people should ever be the same
  4. The hash output is always the same size, regardless of the size of the input data (just like a fingerprint – no matter the size of the person)
Right. There is such a thing as a “hash collision”. This is when you have 2 hashes that are identical, but they were generated from different data. That’s like if you and your neighbor suddenly had the same thumbprint. OOPS!

Now, think about that for a minute... If the police were using these hashes, or thumbprints, to verify your identity, they might mistake you for your neighbor, or your neighbor for you, if you "had the same thumbprint". If they did no other checking, and just relied on that thumbprint, they might very well "authenticate" your identities completely incorrectly. BIG OOPS!

This is exactly what happened with the MD5 SSL attack outlined at the above link.

These smarty-pants people were able to carefully buy a valid SSL Web Site Certificate from RapidSSL in 2008. Before they did that, they created their own CA Root Certificate in such a way that the hash (fingerprint) of their valid, just-purchased Web Site Cert was identical to the hash of the FAKE CA Root Certificate that they created out of thin air.

Since RapidSSL had just said, "Dudes, this Web Site Certificate fingerprint is valid!", and since this was the same fingerprint on the fake CA Root Cert, the forged CA Root Certificate becomes valid.

Now, recall that a CA Root Certificate - as long as it has a valid hash/fingerpint that will validate up the "chain of authority" - can be used to generate a valid SSL Web Site Certificate for any web site in the world... And neither you, nor RapidSSL, nor your browser will ever know that anything is amiss.

Why is this a problem? For starters, consider a man-in-the-middle attack.


 You want to go to https://www.gmail.com. But some "hackers" have used another type of hack to insert their server between you and Gmail. Normally, this would not be possible, because you're using HTTPS! You're SAFE!

WRONG!

As far as anyone knows, you are connected to gmail.com over HTTPS. But in reality, what's happening is this:
  1. You try to connect to https://www.gmail.com
  2. The attacker diverts your request (perhaps using DNS cache poisoning or some other such attack) to a fake server
  3. Since Attacker's Server contains a falsely generated, perfectly valid SSL Web Site Certificate using the tricks outlined above, your browser doesn't know any better. Everything appears to be legit.
  4. You begin doing e-mail, but all your data is actually going encrypted to Attacker's Server, being decrypted and recorded/modified, and then Attacker's Server then passes the data on to the real https://www.gmail.com (using Gmail's actual, valid SSL cert).
  5. You have absolutely no clue that your "secure" communications are not secure in the least!
In other words, SSL / HTTPS means that the connection between your browser and the destination server at the URL you're visiting is supposed to be encrypted. But due to the fact the certain types of SSL certificates (which help handle the encryption) can be forged, an attacker could set up their fake server that pretends to the be the real destination server, and thus insert themselves in the middle of the connection. When that is done, the attacker has control over the connection and the data, and can thus decrypt your data, manipulate it, and/or pass it on to the real intended destination server.

Now, isn't that a daisy?

"But wait!" you say. "Isn't it therefore good for Microsoft to recommend changing the hash function to SHA-256 if SHA-1 has the same potential problem as MD5 did back in 2008?"

An excellent question! Unfortunately, yes and no. Even if you, as a web site owner, change your SSL Web Site Certificate from one that is signed using SHA-1 to a new cert that is signed using SHA-2, you are still unsafe.

Why?

Because all it takes is for ONE Certificate Authority to use a "weak" hash algorithm, and someone who is up to no good can generate a forged CA Root Certificate. Once they have that, they can generate as many SSL Web Site Certs as they want - using any hashing algorithm they please - including a fake-yet-valid cert that they can use to impersonate your "secure" site!

In other words, the weakness in the hashing algorithm is just the tip of the iceberg. Due to the hierarchical "chain of authority" in the whole certificate system, if anyone manages to create a false CA Root Cert, they are more or less god in terms of creating false SSL Web Site Certs.

Thus, in order for Microsoft's words to have an effect, there must not be ANY Certificate Authority (Web Site Cert issuer) in the whole world that still uses SHA-1. In order for the "security" to actually be more secure, everyone must upgrade right now. But this isn't going to happen.

Now, if that isn't bad enough, think about all the NSA spying. Think about how many people said, "Naw, man, I just surf using HTTPS, and I'm totally safe!"

You think so?

I don't. You know why? Well, you should, by now... But there's more!

Guess who invented the SHA-1 hash algorithm in 1995?

The NSA.

Guess who invented SHA-2 in 2001?

The NSA.

So, why should all the Certificate Authorities switch from the NSA's SHA-1 to the NSA's SHA-2? Why, because the NSA created it the way they did for a reason!

SHA-1 already has been theoretically breached, and there are a few indications that SHA-2 isn't quite as super-duper-safe as everyone thinks.

Imagine you are the NSA. You want to spy on everyone, everyone's grandmother, the grandmothers' cats, and the mice that are currently being digested inside the cats. SSL is kind of a problem... It can use pretty annoying encryption. Well, hell! No problem. Just compromise the "certificate authority chain" by forging one little CA Root Certificate, and blammo! You can eavesdrop and man-in-the-middle anybody you darn well please, SSL or not!

Web sites over SSL? No problem.

E-mail over SSL? No problem.

I have said it before, and I'll say it again: There never was security or privacy on the internet, there is no security or privacy on the internet now, and most likely there never will be. Not unless some very big changes are made...

And do you know why all this (and much, much more) is possible?

Because just like you, I had no knowledge of the gaping holes in SSL. Awareness of this and many other issues - technological, political, psychological, social, etc. - is absolutely essential.

Otherwise, frankly, we're screwed.
Links:

Fake SSL certificates deployed across the internet


The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software

Read more...

Sunday, January 19, 2014

Is Bitcoin the Road to Financial Freedom?

On November 18, 2013, the first Congressional hearings on virtual currency --technology-based currency--took place before the Senate Homeland Security and Government Affairs Committee, chaired by Sen. Tom Carper.  According to the Washington Post, the hearings were lovefests, with it being stated that Bitcoin was a "legal means of exchange" and that "online payment systems, both centralized and decentralized, offer legitimate financial services".

The big questions should be: Why is Bitcoin so acceptable to the Feds? Why, all of a sudden, is it being promoted by mainstream media, and powerful 0.01% financial elites--Forbes, Fox Business, Time Magazine, MasterCard, Warren Buffet, Bill Gates, the CFR, DHS, etc? If that doesn't make you nervous, nothing will. So, is there a strategic plan for the replacement of the US dollar, and/or the debt-based fiat money system, with a global reserve currency? And will that currency be Bitcoin?

Bitcoin, to quickly explain, is a pseudo-anonymous protocol, a decentralized digital currency based on software by "Satoshi Nakamoto" (a pseudonym for the unknown person or people who designed the original Bitcoin protocol in 2008) where the transactions (entries on some type of global ledger) require a peer-to-peer network. The original amount of Bitcoins mined--involves solving complex mathematical problems that require a lot of computer power--is said to be 21 million, therefore limited, but that's easy to change with a few clicks of a mouse I would think, not to mention, the controllers do not have to account to anyone for any additional amount of Bitcoins created. Bitcoin can be subdivided into 100 million smaller units called satoshis and is also created by a process called mining. The difficulty of mining ranges depending on the systems being used, and that--the difficulty-- in addition to the market, decide it's worth, which is about $801.80 per bitcoin today at 12:54 AM EST. Now, the total crypto currency market--Litecoin, Peercoin, Quark, Namecoin, Primecoin, etc.--including Bitcoin is worth approximately $13 billion in total.

Now, keep in mind that DARPA created the Internet--which Bitcoin is totally dependent on--initially promoting it as an open, innovative information infrastructure. Fast forward to today and Verizon beat the FCC (Verizon v. FCC) where net neutrality regulations were vacated by all three DC Circuit judges. This marks the second time in four years the FCC had its net neutrality enforcement struck down.  Then there is the software that supposedly hides user identities on the Internet, the TOR Project, which was developed by the US Naval Research laboratory and endorsed by Senator Hillary Clinton. According to the Tor Project Annual Report 2010, the U.S. Government supplied over 80% of its funding.

Gavin Andresen, the Lead Core Bitcoin Developer and founder of The Bitcoin Foundation is slated to address the Council on Foreign Relations (CFR) on Thursday, February 16, 2014, as he did the C.I.A. a couple of years ago when Bitcoin wasn't as big as it is now. This, in and of itself, may not be a big deal, but it's apparent to anyone with eyes to see that this foundation is seeking government acceptance to insure  a seat of power in what might become the new highly globalized Bitcoin economy.



And then there is the potential Bitcoin Greenlist that will determine the people who are allowed to conduct trade online.  While the Greenlist predates Bitcoin, this patent filing incorporates Bitcoin into its features. Think about it. If the U.S. government acquires access to the owners of even ten percent of Bitcoin addresses, they'll gain a large amount of financial data about the entire world!

Links:

Obama Initiative Spawns Identity Based Bitcoin Greenlist

“In April 2011, President Obama signed (PDF) the NSTIC or the National Strategy For Trusted Identities In Cyberspace where public and private players are collaborating on the creation of an “Identity Ecosystem” to address “(1) the insecurity and inconvenience of static passwords and (2) the cost of transactional risks that arise from the inability of individuals to prove their true identity online.”
BitLegal is the easiest way to explore the evolving legal and regulatory status of Bitcoin and virtual currencies around the globe.

MasterCard tracks global 'cashless journey'
“The study focuses on the value of all consumer payments ($63 trillion in total spend), including those that happen beyond retail point-of-sale. In 2011, 34 percent ($21 trillion) of total global consumer spend was done with cash, with cashless payments accounting for 66 percent ($42 trillion)[...]Countries such as the United States (where an estimated 80% of the value of consumer spend was cashless) and Singapore (69%) are approaching the "tipping point" to becoming nearly cashless, and remaining cash use is largely a product of consumer habit.
HOW TO MAKE A MINT: THE CRYPTOGRAPHY OF ANONYMOUS ELECTRONIC CASH by Laurie Law, Susan Sabett, Jerry Solinas, National Security Agency Office of Information Security Research and Technology, Cryptology Division, 18 June 1996

Read more...

Thursday, August 15, 2013

Project Meshnet: Building a Way to Protect Internet Freedom.

Every time an Internet censorship bill like SOPA, CISPA, PIPA, ACTA, is shot down by public protest, another one pops up. To be sure, one day when we're all distracted by something else, an Internet censorship bill will pass.  That's where Project Meshnet comes in.

Whereas the network routing system Tor uses peers to connect and send information through the infrastructure that is already in place for the Internet Project Meshnet is proposing an entirely new internet with different routing protocols. Multiple computers are connected to each other via a wireless connection spanning a large area and all information, messages, documents, music, images, etc., passes from computer to computer until it reaches its destination. If a computer or node is down than an alternative route is found. In other words, the architecture of the meshnet is owned by countless individuals instead of a handful of corporate providers, which makes the oppression of free speech practically impossible.

“Our objective is to create a versatile, decentralized network built on secure protocols for routing traffic over private mesh or public internetworks independent of a central supporting infrastructure."



Links:

MeshWiki

reddit DarkNetPlan This subreddit is dedicated to organizing a decentralized alternative to traditional ISP's.

Internet Relay Chat

Read more...

Friday, July 19, 2013

2045 and the Global Future Agenda to Counterfeit Humanity.

So, is the end of human civilization as we know it going to be extinct in less than 32 years? Most of us will still be alive, hopefully, in 2045; therefore, this transformation,  known as the Singularity--the moment when technological change becomes so rapid and profound, it represents a rupture in the fabric of human history, a post-human existence, if you will--should concern the general public about what it implies about our human future while we still have brains in our heads.

The idea that you can upload yourself, your brain, into a computer and become digitally immortal sounds a little batshit, right?  But Ray Kurzweil, director of engineering at Google, stated that's what's going to happen during his conference speech at the Global Futures 2045 International Congress recently. He also claims that the biological parts of our body will be replaced with mechanical parts and this could happen as early as 2100. I guess the idea is to kill oneself the moment our brain uploads.  Heaven's Gate, anyone? 

That's right. The director of engineering at Google is planning to put all of our brains into robot avatars and all of his pals--most of the global elite--think that's the best idea since sliced bread.  Of course, they do. Think of all the money they'll save when  corporations can replace human beings with robot avatars (see video below).  What they don't understand--or maybe they do, they just hope that we don't--is they can't transfer our souls into these robots.

We are certainly being conditioned to this Orwellian end. I know I spend far too much time on the Internet, in this virtual world that often displaces the real one.  The illusion of freedom lures me in and makes me feel I can go anywhere I want, explore anything I want.   I'm sorry but, often times, the real world kind of pales in comparison. The sad thing is, I'm aware of this dangerous illusion, yet I still capitulate, whereas children raised in the virtual world--television, video games, iPhones, Internet, etc--since birth will embrace this Orwellian technology without question, and with open arms as adults. They will know nothing else.

So yes, I'm fully aware that I'm using a Google platform to bash Google, that I'm using the technology that's enslaving us to preach about our technological enslavement, that everything I post can be traced back to me. I feel like one of those self-righteous evangelicals who preach on the evils of sex, drugs and rock 'n roll, at the same time they're banging the drugged out rock 'n roller down the hall. However, I justify it by telling myself I'm taking advantage of this technology while I still can, before they either shut if off or make it so the only thing that's accessible is intelligence collecting social network sites. I tell myself that this is where I discovered I was not educated, but indoctrinated, rationalizing that I'd rather use their technology to educate myself and the occasional other who might accidentally land here.  That's what I tell myself.

Back to the Singularity.  It is being sold as this ulta-cool utopia, as part of our inevitable evolutionary path that will one day make gods out of men. What they don't tell you is that this only applies to the technocratic elite. They don't tell you that the world will be divided between the super-human "gods" and the poor pitiful slaves who can't afford to transform themselves into Nietzsche's Übermensch (overman).  They conveniently leave that part out.

Without question, we've been heading in the direction of the soul-killing commoditization of human-beings for a very long time as we've been led to embrace scientism through materialistic reductionism as the only avenue to truth.  It's just now that we have the technology to make this Orwellian agenda real.  Sold as "cool", but in reality, creepy, here are a few tidbits that will no doubt effect our future as human beings: Biometrics at a distance (sense your heartbeat through a wall); algorithms that predict your next move;  brain-link, controlling your brain through the Internet; autonomous humanoid robots, and/or, robots with real brains;  Pentagon's Project Avatar, robotic soldiers; Narrative Networks, high-tech, chemically enhanced propaganda; the embryonic LifeLog program; and electronic tattoos and ingested pills that make you a walking password.

Former DARPA (gave birth to the Internet) head, Regina Dugan, now the leader for special projects for Motorola, a Google subsidiary, came out with her electronic tattoo, an RFID bar code,  that can be used to authenticate oneself, not to mention a pill that can be ingested and then battery-powered by digestive acids to make one's whole body a password.  As she said, “your entire body becomes your authentication token.” Mark of the beast, anyone?

And let's not forget smart dust and/or neural dust. These nano-particles embed themselves in your brain, functioning as an MRI inside your brain. In other words, "tiny implantable sensors could function like an MRI inside the brain, recording data on nearby neurons and transmitting it back out." Tinfoil hats, anyone?

Will we willfully choose such an evolutionary direction? Will self-aware machines evolve before humans become self-aware?  Oh, we are already self-aware?  Sorry, my bad.



Links:

Intelligent neural dust embedded in the brain could be the ultimate brain-computer interface

IARPA (Intelligence Advanced Research Projects Activity)   , a little-known U.S. government organization, is developing analytic programs for the National Security Agency that could make recent revelations about the NSA’s activities look antiquated by comparison. Rather than reviewing archival data, it may use current data to predict the future.

We'll be uploading our entire MINDS to computers by 2045 and our bodies will be replaced by machines within 90 years, Google expert claims

Read more...

Wednesday, June 05, 2013

TPP: The Biggest Threat to the Internet You've Never Heard Of.

The Trans-Pacific Partnership Agreement (TPP) is being negotiated in secret between more than 12 countries around the Pacific region. Find out why it poses a huge threat to your digital freedoms.

“The first concern about the TPP is its Article 4, on “Copyright and Related Rights”.

It extends the terms of protection of these rights to the life of the author, plus 70 years. Although this is already part of Australia’s law since 2006, it goes beyond the life plus 50 years from the Berne Convention and will bring all the signatory countries in line with US law.

Copyright extensions have been criticised as being “bad for innovation, bad for the economy and bad for our culture”. This is because extending copyright protection delays creative material going into the public domain and restricts the re-use and remix of older material into something new and innovative.

It also benefits established artists and corporate rightsholders who have bought the rights from the original innovators, at the expense of emerging creators.

Article 4 also prohibits the circumvention of technical measures which are used to protect copyrights. These measures include the restrictions on music files which prohibit the user making copies, on DVDs which prevent the DVD being played in a different region, and on e-books which stop them being read aloud by the computer.

There are some very limited exceptions to this rule, such as for researchers who are trying to ensure the interoperability of computer programs and to investigate security flaws.

Although technical protection measures can protect against copyright infringements, they can also stop plenty of perfectly legal uses of protected material. The circumvention of technical protection measures can be done for legitimate reasons, such as for promoting competition and facilitating innovation.

Yet this is not included in the TPP’s text, and currently the breaking of a technical protection measure will be prohibited, even if it does not constitute a copyright infringement.


Read more...

Tuesday, April 23, 2013

Boston Bombing: A Great Big Diversion?

So, what's going on while everyone is distracted by bombs, explosions, poisoned letters, "martial law", etc?

The Cyber Intelligence Sharing and Protection Act (CISPA), which Aaron Swartz called "the Patriot Act of the Internet", a bill that is currently moving through Congress passed the House of Representatives on April 18th. At the last moment, an alteration to protect user's social media passwords from employers was defeated in a Congress vote.

President Obama gutted the Stock Act when he signed S. 716 which basically gutted the stock act which was created to make it harder for the legislature and the executive branch to engage in insider trading.

Israel and John Kerry are escalating the war in Syria, claiming Syria has chemical weapons.

Billionaire, New York Mayor Michael Bloomberg claims that the Constitution must change to give government more power, after the Boston Marathon Bombings to allow for greater security to stave off future attacks.

Speaking of diversions:









Read more...

Monday, February 18, 2013

Resubmitting CISPA Under the Guise of National Security

Imagine, if you will, an Internet surveillance grid of the future that includes an Internet ID system, Internet licenses, Internet blacklists, an Internet taxation system, giant firewalls used as a blockade to information, etc. Imagine biometric gate-keeping sensors that control and watch everything you do on the Internet. Imagine being accountable and responsible to the Big Brother Internet. This might sound far out, but that's what DARPA had in mind when they created the Internet. Now, they just need the legislation in place to make it happen. What's more is that the same tech corporations that claim they believe in an open Internet and online freedom--Facebook (who overtly supports CISPA) Google, Yahoo, etc.-- will aid and abet the government when it comes time to install these restrictions. However, the powers that be, know that in order to accomplish this goal, they must gradually increase the heat on the proverbial pot of water, rather than switch it to boil right away.

Which brings us to the latest State of the Union address, where President Obama said he signed an executive order to strengthen the nation's cyber defenses by increasing information sharing and by developing standards to protect our national security, our jobs and our privacy. Sure, on the surface, that sounds good, because, of course, our national security infrastructure should be protected. But, guess what? It already is. I mean, do you really think our national security infrastructure is available online...on the same Internet, we the people, surf? Hell no! So what is this CISPA (Cyber Intelligence Sharing Protection Act) legislation the Obama administration claims must be passed to secure our networks and prevent attacks? Well, it basically provides a framework of legal authority to, for example, give the "trustworthy" corporations, immunity from their actions. In fact, the text of this legislation states that private information may be shared "notwithstanding any other provision of law."
You know, provisions of law like the the Fourth amendment.

Anyway, the very next day, after the State of the Union address, Mike Rogers, chairman of the House Intelligence Committee, along with other members of Congress resubmitted CISPA--a rehashed version that has not been released yet. Yes, the one that failed to reach the Senate during the last Capitol Hill session. The problem is that the language of this bill is so vague and so broad that once this framework is put in place, the potential to destroy our civil liberties--yes, even more than they've already been destroyed--is boundless, possibly resulting--at some time in the future-- in the aforementioned scenario.

As President Obama told us, he has already signed the executive order to lay the groundwork for the cooperation between the private and the public sectors, which like I said before, gives full immunity to the private sector, so if the private sector uses your information for whatever reason, you cannot sue them. And it's not just the government that has an interest in eliminating what's left of "freedom" on the Internet. The large corporations want to control what information is allowed to flow on the internet as well. They too don't want disgruntled consumers, dissenting opinions, whistle blowers, and fact checkers alerting the public of their nefarious activities. The bottom line is this bill is not about security, this is all about the wealthy and powerful struggling to maintain the status quo, to maintain their place of privilege and authority in a world that, given enough freedom, could severely threaten and/or undermine their sense of entitlement and position of great advantage.

"Shall the throne of iniquity have fellowship with thee which frameth mischief by a law." -- Psalm 94:20

From CISPA is Back:



Read more...

Tuesday, January 22, 2013

Hollywood, the Pentagon, and Sock Puppets and Operation Earnest Voice.

As our world grows increasingly complex, our need for simple, sound-byte explanations of complicated issues becomes greater. Why? Mostly because we're trying to manage and navigate what's become not only a more complex world, but also a more oppressive and often times unjust world. This, of course, makes us vulnerable to the manipulators, and their never ending programs of propaganda that saturate every walk of life.

Take the military’s "sock puppet" software that creates fake online identities in order to spread pro-American propaganda. It's called Online Persona Management Services. This Centcom contract allows for the creation of up to 10 sock puppet accounts for every U.S. serviceman working on the program. The stipulations are that every fake persona must have a convincing background history, including friend networks so that it will remain undetectable to even the most "sophisticated adversaries”. This way the U.S. military can create a false consensus in online conversations, crowd out unwelcome opinions, and smother commentaries or reports that do not correspond with their objectives.  T"his multiple fake persona contract was thought to have commenced as a part of  Operation Earnest Voice (OEV) --how Orwellian of them--which was first developed in Iraq as a psychological warfare weapon against the online presence of al-Qaida supporters and others ranged against coalition forces.

It gets even more Orwellian.  General David Petraeus has said American efforts to infiltrate online discussion are aimed at "countering extremist ideology and propaganda and ensuring credible voices are heard". He said the US military’s objective was to be “first with the truth”.

Then there is the NDAA that not only  codifies indefinite military detention without charge or trial into law for the first time in American history, it legalizes propaganda on the American public. That's right, the U.S. government can carry out legal misinformation campaigns against the citizens of this country. The Pentagon already spends $4 billion to influence public opinion. Moreover, the CIA has been infiltrating the largest press institutions since the 1950s with Operation Mockingbird, a secret CIA campaign to spread disinformation and false stories during the cold war, by paying off editors at most mainstream news outlets.

And last, but certainly not least is Operation Hollywood, propaganda on steroids. At At least since the WWII, the interests of Hollywood and the agenda of Washington and corporate America have consistently coincided, sometimes artfully, sometimes blatantly. Has Hollywood had any positive influence? Undoubtedly, however, the positive influence is much more obvious than the often concealed negative influence.

Empire: Hollywood and the War Machine:

Empire examines the symbiotic relationship between the movie industry and the military-industrial complex.

War is hell, but for Hollywood it provides the perfect dramatic setting against which courageous heroes win the hearts and minds of the public. The Pentagon recognises the power of these celluloid dreams and encourages Hollywood to create heroic myths; to rewrite history and provide willing young patriots for its wars. In return, Hollywood receives access to billions of dollars worth of military kit, from helicopters to aircraft carriers. So is it a case of art imitating life, or a sinister force using art to influence life and death and the public perception of both?


Read more...

Tuesday, January 15, 2013

The Nationally Directed Effort to Take Down Aaron Swartz

The death of Aaron Swartz, co-founder of Reddit, co-author of the specifications for the Web feed format RSS 1.0 (Rich Site Summary), pioneer of open-source, and  Internet activist against the monopoly of information, was sadly, a death that was coerced. Yes, he apparently killed himself, but it's the government--with the assistance of MIT who over-zealously persecuted through prosecution, and pushed him to that point.  Not the first time, I might add.

The issue here is the abusive treatment of citizens, in particular, one citizen who courageously spoke truth to power, Aaron Swartz, by a government bureaucracy intent on intimidating activists. In this case, prosecuting a person accused of a victimless "crime," if it was a crime at all, and threatening a severe sentence--35-years in jail-- in retaliation for, in this case, advocating on behalf of the free flow of information on the Internet.

What was Aaron Swartz's crime? Attempting to liberate taxpayer paid research journals--that already belonged to the public--to the public for free, journals that the "owner" of the records, JSTOR, declined to press charges. Swartz did not seek to profit from the information he liberated, and the writers/researchers had already been compensated for the work, unlike all of corrupt banksters, CEOs, and politicians, who not only go free but are rewarded for intentionally bringing down the global economy.
“..he used an open network connection at MIT, which explicitly allowed free guest access, to download academic research papers that were available for free for any user on that particular network."
According to a good friend of his, Aaron Swartz had a "much broader agenda than the information freedom fights for which he had become known." He was also a "political activist interested in health care, financial corruption, and the drug war."  To sum it up, Aaron's goal was making "life a little less unfair." And for that, he paid the ultimate price.

Here are some of the more unusual aspects in this case:

Two days before Aaron Swartz was arrested, the Secret Service took over the investigation.
"On the morning of January 4, 2011, at approximately 8:00 am, MIT personnel located the netbook being used for the downloads and decided to leave it in place and institute a packet capture of the network traffic to and from the netbook.4 Timeline at 6. This was accomplished using the laptop of Dave Newman, MIT Senior Network Engineer, which was connected to the netbook and intercepted the communications coming to and from it. Id. Later that day, beginning at 11:00 am, the Secret Service assumed control of the investigation."

The top federal prosecutor, U.S. Attorney Carmen Ortiz and her assistant Stephen Heymann rejected any deal that did not involve a prison sentence.

Aaron Swartz prosecutor 'drove another hacker to suicide in 2008 after he named him in a cyber crime case'
“In his suicide note, James said he had no faith in the justice system, which he believed were trying to tie him to a crime he did not commit.

'I have no faith in the "justice" system. Perhaps my actions today, and this letter, will send a stronger message to the public.

'Either way, I have lost control over this situation, and this is my only way to regain control.

'Remember, it's not whether you win or lose, it's whether I win or lose, and sitting in jail for 20, ten, or even five years for a crime I didn't commit is not me winning. I die free.'

James was the first juvenile put into confinement for a federal cyber crime case.

And last, but certainly not least, from emptywheel, who seems to be breaking most of the news regarding the death of Aaron Swartz, the Department of Justice invoked Aaron Swartz’ manifesto to justify investigative methods.
“And look at the passage from the Manifesto they quote in the brief, which appears in this larger passage.
“There is no justice in following unjust laws. It’s time to come into the light and, in the grand tradition of civil disobedience, declare our opposition to this private theft of public culture.

We need to take information, wherever it is stored, make our copies and share them with the world. We need to take stuff that’s out of copyright and add it to the archive. We need to buy secret databases and put them on the Web. We need to download scientific journals and upload them to file sharing networks.
In context, much of the manifesto advocates for things that are perfectly legal: sharing documents under Fair Use. Taking information that is out of copyright and making it accessible. Purchasing databases and putting them on the web.

Aside from sharing passwords, about the only thing that might be illegal here (depending on copyright!) is downloading scientific journals and uploading them to file sharing networks.

Precisely what the government accused Swartz of.

But they don’t cite that passage. Rather, they cite the “making copies” passage–something not inherently illegal. As if that justified the investigative tactics they used.

Used as it is in this page-limited brief arguing why their tactics were legal, the citation is really bizarre. But it does seem to admit that the government considers Swartz’ role in the Open Access movement to be as much proof he was a criminal as that he chose to download the documents at MIT and not Harvard.
This is just one more example of how distorted the whole US justice system has become in order to please the elite few who want to retain their power and wealth at any cost.
“For remember, we live in a world where the architects of the financial crisis regularly dine at the White House — and where even those brought to “justice” never even have to admit any wrongdoing, let alone be labeled “felons.” Harvard Law Professor Lawrence Lessig,

Read more...

Sunday, July 29, 2012

The Internet: A Walled World Under Constant Surveillance?

What happens when the physical and virtual worlds converge?  After all, the digital age is only in its infancy, and already, the boundaries between the two are becoming increasingly blurred. 

Will this dual reality "move toward more networked individualism based on continued technological progress and trust in computer and human networks—including the withering of boundaries"? Or, will it move toward walled surveillance, and corporate ownership of everyone and everything?

"The Individual in a Networked World: Two Scenarios". suggests two scenarios. One, "Collaborative Agents In Augmented Reality", and two, "A Walled and Surveilled World".

I'm betting on #2.

Read more...

Monday, May 21, 2012

The Knowledge Graph: Google's Ministry of Truth.

If you remember, Orwell's "Ministry of Truth" concerned itself with spreading lies in order to manipulate public opinion; film and radio carried this process even further. The Ministry of Truth coined phrases like "War is Peace", Freedom is Slavery" and "Ignorance is Power". In other words, fiction became truth. So, what does this have to do with Google?

Well, anyone with an IQ of a bat - a baseball bat, that is -  knows Google has a monopoly on information distribution. It's hard to come up with anything on the net that Google hasn't, at the very least, tried to take over. Take YouTube, for example. Prior to Google's takeover, censorship was not an issue on YouTube. Today, it most certainly is. "Copyright School", anyone?

So, now, under the guise of of trying to produce semantically meaningful results, I suppose, Google will replace the old strategy of matching keywords to webpages, and employ Metaweb algorithms to generate search results in the form of a new search tool,  "The Knowledge Graph". This tool will return answers or “facts” from pre-selected sources  such as the CIA Factbook, Wikipedia, the World Bank, and Freebase, an open database generated by Metaweb, which Google acquired in 2010.

In addition to providing traditional search results, the Knowledge Graph results will offer a wide range of answers to search queries directly on the results page. In other words, instead of finding the correct Wikipedia article that has the answer, the information will appear in a type of Googlepedia display.

Instead of using the typical search strength of a particular answer, this new feature will draw "facts" from places like Wikipedia for historical information, CIA World Factbook for geopolitical answers, the World Bank for economic facts, Freebase for information about people and other predetermined
But, do we really want to abdicate the role of "decider" to Google, who plans to supply lowest common denominator search results, considering the aforementioned underlying sources that will embed meaning into the content?  Not me. Personally, I prefer unstructured ambiguity. It assures better access to unbiased information.

Read more...

Tuesday, May 15, 2012

Another Effort to Take the Internet Away From the People.

Behind closed doors, in Dallas Texas, trade representatives of big corporations are secretly negotiating a massive trade agreement called the Trans-Pacific Partnership (TPP), which includes regulations for the Internet – including intellectual property provisions that could potentially "harm online expression, privacy and innovation on the Internet".

This Agreement may be even worse than ACTA as it could tie the hands legislators and create new, international standards for intellectual property enforcement. Internet users and free expression advocates like EFF aren’t allowed in the room and are forbidden from seeing the text, even though U.S. Trade Representatives claim  they have made “extraordinary efforts” to include public stakeholders in negotiations. This couldn’t be further from the truth. Like ACTA, negotiations exclude the public, while welcoming private industry representatives with open arms.
Last week, 32 legal scholars sent a letter to the office of the USTR demanding transparency in the process. Including the release of the text and demand for real participation from civil society, they demanded the immediate release of “reports on US positions and proposals on intellectual property matters that are currently given only to Industry Trade Advisory Committee members under confidentiality agreements.” This is key because there is nothing that could justify the withholding of such reports that simply outline the U.S. position on intellectual property from the public. This is especially true given the fact that the U.S. government’s proposals could impede Congress from engaging in domestic legal reform of legislation regulating IP.
US Congressman Darrell Issa just released the Trans Pacific Partnership Intellectual Property Rights Chapter on KeepTheWebOPEN.com. Only problem is, it's the old 15-month old version. How stupid do they think we are?

Via Public Citizen:
The Trans-Pacific Partnership (TPP) is being negotiated in secret and the stakes for the 99% couldn't be higher...The Trans-Pacific Partnership (TPP) "free trade" agreement is a stealthy policy being pressed by corporate America, a dream of the 1 percent, that in one blow could:

• offshore millions of jobs,

• free Wall Street and its banksters from oversight,

• reduce Internet freedom,

• ban policies needed to create green jobs and rebuild local economies,

• decrease access to medicine by extending drug company monopolies,

• empower corporations to attack our environmental and health safeguards, such as tobacco control and clean air and water regulations.

Closed-door talks are on-going between the U.S. and Australia, Brunei, Chile, New Zealand, Peru, Singapore, Malaysia and Vietnam; with countries like Japan and China potentially joining later.

600 corporate advisors have access to the text, while the public, Members of Congress, journalists, and civil society are excluded. And so far what we know about what's in there is very scary!

But there's still time to organize to shine a light on the horrors of the TPP and convince our governments to instead pursue policies that benefit the 99% in our countries. Watch this video (you may want to mute) and then take action by signing our petition calling for an end to secrecy in the TPP negotiations.

TPP: Spreading NAFTA to Asia and Chile...Guaranteed to screw you and me.

Read more...

Sunday, May 13, 2012

FBI Pushing Plan to Force Surveillance Backdoors on Social Networks, Web Email Providers and VOIP



The FBI wants Internet companies to support a proposal that would require firms like Microsoft, Facebook, Yahoo, and Google, to build in backdoors for government surveillance. If passed, these ompanies would have to provide the bureau with decryption tools to make sense of the information that it captures.

The Communications Assistance for Law Enforcement Act (CALEA) already provides assistance to law enforcement by requiring that they cooperate with police in order to conduct lawfully-authorized electronic surveillance.  The FCC extended CALEA in 2004 to apply to broadband providers, but web companies are not covered under this law.  

Of course, once again, it's all in the name of national security and public safety.

Read more...

Tuesday, May 08, 2012

Pedophilia on Facebook Increasing?

It's interesting how Facebook has no problem censoring certain types of comments, articles, pictures and messages.  It's interesting how easily Facebook bans people for adding too many friends or chatting too much,  yet somehow, stopping thousands of child predators to interact and trade photos is beyond their capability. In fact, the social networking giant, ordered a mother to take down pictures of her 7-year old son, competing at a local Special Olympics event just because he has Down Syndrome .  

"When she next logged on, she received messages from Facebook's monitoring team, saying that pictures violated its user agreement.

To keep your account active, please remove any photos that contain hate speech, support for violent organizations, or threats to harm others,' the message read.

Ms Cornwell's account was disabled for three days until she took down the photos.

'Every photo was of my son at the Special Olympics Event,' she said.
Nevertheless, pedophiles on Facebook, if anything, are on the increase.  In August of 2010, a Vancouver B.C. high school teacher was amongst eleven people arrested on child pornography charges linked to an alleged international child porn ring that was operating on popular social networking site Facebook.

Currently, Chelsea Schilling is doing a four part series on the dark side of Facebook. Part one deals with pedophilia.
"During the investigation, entire Facebook predator communities were easily spotted. Child pornographers use groups as meet-up points to find others with similar interests. Many of the offenders would list similar interests on their profile pages, including terms such as “Thirteen,” “Lolita,” “Justin Bieber,” “incest” and “PTHC (preteen hard-core pornography).” Their activities might include “Receiving nude pics,” and they subscribe to explicit Facebook fan pages posted in plain sight.

Send a flood of 1st-class mailed postcards to Facebook’s Mark Zuckerberg, members of Facebook’s board and top-level management and staff telling them you want this criminal activity to stop.

In most cases, child-pornography traders and pedophiles have two kinds of friends: 1) sexual deviants who have similar interests and 2) unsuspecting children they’ve found and “friended” on Facebook. Many predators will establish a virtual relationship with a child, convince him or her to send provocative photos and even persuade the child to meet with them in person.
Now, Facebook does have a place where you can report these pages; however, from what people have told me, and reports I've read, Facebook ignores those reports.

Meanwhile, a very wealthy Mark Zuckerberg kicks off Facebook IPO  road show.

Links:

Sign petition to stop child porn on Facebook


Stop Child Porn on Facebook


“The Berlin Turnpike: A True Story of Human Trafficking in America”

“Social networking sites like Facebook, MySpace and Twitter have completely changed the game. Enormously popular – and growing every day – these free sites offer very powerful tools for men who are buying sex, pimps who are selling it, and pedophiles trading child pornography. In a brilliantly devious marketing ploy, pimps have used these sites in such a way that men no longer need to look for girls on the street corner or the Internet. Using social networking, the girls will come to them."

Read more...

Saturday, March 24, 2012

Avoid Big Brother: File Sharing Anonymously

Did U.S. authorities overstep their jurisdiction when they pulled the plug on cyberlocker service Megaupload? Of course. Don't they always? But it appears that the Fed's takedown of Megaupload - note, without SOPA, PIPA, ACTA, or any other special legislation - has only encouraged more sophisticated methods of file-sharing/storing, free from the prying eyes of governments, corporations and advertisers. 

Thwarting the state:

RetroShare is a Open Source cross-platform, private and secure decentralised communication platform.
It lets you to securely chat and share files with your friends and family, using a web-of-trust to authenticate peers and OpenSSL to encrypt all communication.

HFS HTTP File Server

... it's file sharing... it's webserver... it's open source... it's free... it's guaranteed to contain no malware
DiskCryptor

PeeJe -Share is an absolutely free file-hosting service for providing webspace on our servers without the need to sign-up.

Links:

Cloud computing is a trap, warns GNU founder Richard Stallman

Control Your Computing Before It Controls You

Read more...

Monday, February 27, 2012

How to Remove Your Google Search History Before New Privacy Policy Takes Effect

On March 1st, Google will implement its new, unified privacy policy, which will affect data Google has collected on you prior to March 1st as well as data it collects on you in the future. Until now, your Google Web History (your Google searches and sites visited) was cordoned off from Google's other products. This protection was especially important because search data can reveal particularly sensitive information about you, including facts about your location, interests, age, sexual orientation, religion, health concerns, and more. If you want to keep Google from combining your Web History with the data they have gathered about you in their other products, such as YouTube or Google Plus, you may want to remove all items from your Web History and stop your Web History from being recorded in the future.

Click here to see how you can do that.

Read more...

Sunday, February 19, 2012

Big Brother Legislation Under the Guise of Protecting Children: .

If you haven't noticed there is a significant effort to not only severely restrict the internet, but to spy and collect our personal information while doing so. This time, it's under the guise of protecting children from Internet pornography: H.R.1981 - Protecting Children From Internet Pornographers Act of 2011 A bill which Rep. Lamar Smith (R-TX) has fast-tracked.

However, this bill does not protect children from anything at all - because criminals use encryption and other devious methods to avert authorities, whereas ordinary citizens do not - rather, this bill would require Internet service providers to capture credit card data, bank statements, IP information and search history from every user and keep it on hand for 18 months. Moreover, the government would not need a warrant to look at all your data. And once all of this personal information about innocent Americans is collected, it would be available to law enforcement for any purpose.

So, once again,  in this ever expanding Orwellian house of mirrors, the innocent are targeted, while the truly guilty go free.

Read more...

Thursday, February 16, 2012

DOJ Wants $5 Million to Act as Hollywood's Private Police Force

Apparently, copyright infringement is big threat to national security, because despite the protest of many public interest groups begging President Obama to stop filling his administration with RIAA lawyers, in April 2009, he appointed the 5th RIAA attorney into the Department of Justice (DOJ). And, now, the DOJ wants $5 million to hire 14 new employees, nine of them - you guessed it - attorneys!

As Congress struggles to resolve the "debt crisis", subsidizing the rich and powerful, not the poor and unempowered, seems to be the only solution to this massive "problem". After all, if they don't continue to increase the burden on the less fortunate, the less fortunate might gather the strength to rise up and break the backbone of their power, and we wouldn't want that, would we?

Read more...

Wednesday, February 15, 2012

Cool and Useful Websites.

BirdFeeder - Open, decentralized micropublishing. Think Twitter.

Blurb - Make your own book.

Call the Future calls the specified number with the given return name.Please understand that this is a demo only and the limit is often maxed out. If so, please try later.

Citebite - Paste a chunk of text and the URL of the page containing the text and in return get a link that opens directly to your selection and highlights it.

Currency Converter

CurveCP: Usable security for the Internet

Deterministic Password Generator  - This javascript program runs in your browser and uses the Skein-512 secure hash to deterministically generate passwords based on a single master password. This page DOES NOT send your master password or derived passwords to any server or store them. Different secure passwords are generated for each site so only the master password need be remembered. Site specific passwords can be regenerated at any time from anywhere in the world. The generated passwords can be saved locally by your browser for your convenience (or not).

Dirty Share - PureJavascript Peer to Peer Filesharing. 

File Destructor - Basically provides an excuse if you can't meet your deadline.

FileTea - Low friction, one-click anonymous file sharing. FileTea allows instantaneous file sharing using only a browser and standard HTTP. Users just drag-n-drop their files into a webpage and an URL is generated for each one. These URLs are then sent to recipients or just published somewhere, and allow direct download of the corresponding file.

Fluid - Turn Your Favorite Web Apps into Real Mac Apps.

Freecode: Open Transactions   is a solid, easy-to-use, financial crypto and digital cash library, including an API, server, and test client. It features anonymous numbered accounts, untraceable digital cash, triple-signed receipts, basket currencies, and signed XML contracts. It also supports cheques, invoices, payment plans, markets with trades, and other instruments. It uses OpenSSL and Lucre blinded tokens.

Friendika
- Interconnects social websites, and is also the most technically advanced and feature-rich decentralised Facebook alternative currently available for the indie web.

Gazhoo - Upload and sell documents

GoodReader
- pdf reader for iPad

Hackety Hack - teaches you the absolute basics of programming from the ground up. No previous programming experience is needed!

Lulu - Personal book publishing

Map-O-Net  - shows where you lie in the structure of IP addresses.

Readdle - PDF converter for the iPad.

RoboHash - Generate unique images from any text.  It's an easy web service that makes it easy to provide unique, robot/alien/monster images for any text. Put in any text, such as IP address, email, filename, userid, or whatever else you like, and get back an image.

Vector Magic Automatically convert bitmap images like JPEGs, GIFs and PNGs to the crisp, clean, scalable vector art of EPS, SVG, and PDF with the world's best auto-tracing software.

WebSDR
- Software Defined Radio Online. Internet and radio.

Related Links:

Darknet Rising: A Private, Secure and Anonymous Meshnet Is Emerging

Read more...

Monday, January 23, 2012

If You Thought SOPA Was Bad, Watch Out For ACTA

If You Thought SOPA Was Bad, Just Wait Until You Meet ACTA

Few people have heard of ACTA, or the Anti-Counterfeiting Trade Agreement, but the provisions in the agreement are just as pernicious as anything we saw in SOPA. Worse, the agreement spans virtually all of the countries in the developed world, including all of the EU, the United States, Switzerland and Japan.

Many of these countries have already signed or ratified it, and the cogs are still turning. The treaty has been secretly negotiated behind the scenes, with unelected bureaucrats working closely with entertainment industry lobbyists to craft the provisions in the treaty. The Bush administration started the process, but the Obama administration has aggressively pursued it.

Indeed, we’ve already signed on to the treaty. All it needs now is Senate ratification. The time to stop the treaty is now, and we may need a second global internet blackout to call attention to it.



Read more...
Iraq Deaths Estimator
Petitions by Change.org|Start a Petition »

  © Blogger templates The Professional Template by Ourblogtemplates.com 2008

Back to TOP