New documents show how the NSA infers relationships based on mobile location data (Washington Post, 10 Dec 2013) – Everyone who carries a cellphone generates a trail of electronic breadcrumbs that records everywhere they go. Those breadcrumbs reveal a wealth of information about who we are, where we live, who our friends are and much more. And as we reported last week, the National Security Agency is collecting location information in bulk — 5 billion records per day worldwide — and using sophisticated algorithms to assist with U.S. intelligence-gathering operations. How do they do it? And what can they learn from location data? The latest documents show the extent of the location-tracking program we first reported last week. Read on to learn more about what the documents show. The NSA doesn’t just have the technical capabilities to collect location-based data in bulk. A 24-page NSA white paper shows that the agency has a powerful suite of algorithms, or data sorting tools, that allow it to learn a great deal about how people live their lives. Those tools allow the agency to perform analytics on a global scale, examining data collected about potentially everyone’s movements in order to flag new surveillance targets. For example, one NSA program, code-named Fast Follower, was developed to allow the NSA to identify who might have been assigned to tail American case officers at stations overseas. By correlating an officer’s cellphone signals to those of foreign nationals in the same city, the NSA is able to figure out whether anyone is moving in tandem with the U.S. officer.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/Arvind Balaraman.

Google catches French govt spoofing its domain certificates (ZDnet, 9 Dec 2013) – France’s cyberdefence division, Agence nationale de la sécurité des systèmes d’information (ANSSI), has been detected creating unauthorised digital certificates for several Google domains. Google states on its own security blog that an intermediate certificate authority (CA) issued the certificate, which links back to ANSSI. “Intermediate CA certificates carry the full authority of the CA, so anyone who has one can use it to create a certificate for any website they wish to impersonate,” Google wrote. In a statement by ANSSI, the cyberdefence organisation revealed that this intermediate CA is actually its own infrastructure management trust administration, or “L’infrastructure de gestion de la confiance de l’administration” (IGC/A). ANSSI itself is the cyber response and detection division of the French republic. ANSSI states that the fraudulent certificates were a result of “human error, which was made during a process aimed at strengthening overall IT security”. Google states that the certificate was used in a commercial device, on a private network, to inspect encrypted traffic. According to the web giant, users on that network were aware that this was occurring, but the practice was in violation of ANSSI’s procedures. Google used the incident to highlight the need for its Certificate Transparency project, aimed at fixing flaws in the SSL certificate system that could result in man-in-the-middle attacks and website spoofing. Google’s answer to these flaws is for CAs to adopt a framework that monitors and audits these certificates, thus outing rogue CAs or when certificates are illegitimately issued. This is not the first time that the flaws of SSL certificates have been exposed. The US National Security Agency is alleged to have used man-in-the-middle attacks through unauthorised certificates against Google in the past. Additionally, in August 2011, abreach at DigiNotar, another CA, found that an Iranian hacker had created rogue certificates for Google domains, intercepting user passwords for Gmail.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/Vichaya.

 

URL shortening in legal briefs, and now legal opinions (Volokh Conspiracy, 2 Dec 2013) – Most readers will be familiar with URL shortening services — redirection services that give users a short web address that points to a longer one. I’ve come across URL shortening in legal briefs more and more, and I have used such links in briefs myself. The shortening avoids an unsightly excessively-long URL when you are linking to content on the web, and it’s also easier for the reader who might hand-type the URL into a browser. In the opening brief in United States v. Auernheimer, for example, I linked tohttp://goo.gl/dVQ4k instead of to the ugly https://chrome.google.com/webstore/detail/scraper/mbigbapnjcgaffohmbkdlecaccepngjd?hl=en. In the last two years, federal court decisions have started to use URL shortening links, too. Judge Kozinski uses them extensively in today’s dissent in Minority Television Project v. FCC, a case on the First Amendment implications on banning certain kinds of ads on public TV. A quick Westlaw search finds 9 judicial opinions before today’s decision that use Google’s URL shortener, goo.gl. Several of them use the service for maps. It’s an interesting development, and I suspect it’s one that we will see more of rather than less of in the future.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/renjith krishnan.