Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Thursday, February 13, 2020

WhatsApp defends encryption as it tops 2 billion users


SAN FRANCISCO - The Facebook-owned messaging service WhatsApp said Wednesday it now has more than 2 billion users around the world as it reaffirmed its commitment to strong encryption to protect privacy.

WhatsApp, acquired by Facebook in 2014, has grown into one of the most widely used services in the Facebook "family" of apps, offering free messaging along with voice and video calls.

"Private conversations that once were only possible face-to-face can now take place across great distances through instant chats and video calling," a WhatsApp blog post said. 

"There are so many significant and special moments that take place over WhatsApp and we are humbled and honored to reach this milestone."

The statement said WhatsApp remained committed to its "strong encryption" that enables users to connect privately even amid calls by law enforcement in the United States and elsewhere to provide more access.

"Strong encryption is a necessity in modern life. We will not compromise on security because that would make people less safe," WhatsApp said.

"For even more protection, we work with top security experts, employ industry leading technology to stop misuse as well as provide controls and ways to report issues -- without sacrificing privacy."

Last week, child protection organizations called on Facebook to halt plans for strong encryption of all its platforms, saying that would allow predators to operate freely.

WhatsApp employs "end to end encryption" which can in many cases prevent law enforcement from accessing user data even with a court order.

The social network is working to extend end-to-end encryption across its messaging applications, including Facebook Messenger and Instagram.

BACK DOOR DILEMMA

Child protection groups have expressed fears that stronger encryption of online exchanges would facilitate the sharing of child pornography.

Backers of strong encryption argue that any special access or "backdoors" allowed for law enforcement would weaken security and could be exploited by criminals, hackers and authoritarian governments.

Officials from the US, Britain and Australia late last year called on Facebook to allow authorities to circumvent encryption to better fight extremism, child pornography and other crimes.

The heads of Facebook's WhatsApp and Messenger, Will Cathcart and Stan Chudnovsky, responded in a letter to officials from the three countries that allowing this kind of "backdoor" access "would be a gift to criminals, hackers and repressive regimes" while leaving users vulnerable.

Facebook's stance on encryption has been backed by more than 100 activist organizations, security experts and industry groups who warned against efforts to force tech companies to weaken encryption.

Despite its strong encryption, WhatsApp has seen flaws exploited in cyberspace.

Human rights activists have said that spyware hidden in WhatsApp messages, possible developed by Israel-based NSO Group, was used to track dissidents and others. 

Amazon chief Jeff Bezos's phone is also believed to have been infected by spyware hidden in a WhatsApp message from Saudi Crown Prince Mohammad bin Salman.

WhatsApp in October sued NSO Group, accusing it of using the messaging service to conduct cyberespionage on journalists, human rights activists and others.

BREAKUP? 

WhatsApp is one member of the Facebook app "family" that includes its core social network, Instagram and Messenger.

Facebook said recently some 2.89 billion people globally are daily users of at least one of these services.

But the growth has also attracted attention of regulators and activists concerned over the dominance of major tech platforms. Presidential hopeful Elizabeth Warren has been among those calling for the breakup of the big technology firms.

Facebook has argued against the idea of a breakup, saying the company is better able to keep its services safe and secure with a unified infrastructure.

Agence France-Presse

Wednesday, January 15, 2020

Encryption battle reignited as US govt at loggerheads with Apple


WASHINGTON — Apple and the US government are at loggerheads for the second time in 4 years over unlocking iPhones connected to a mass shooting, reviving debate over law enforcement access to encrypted devices.

Attorney General Bill Barr claimed Monday that Apple failed to provide "substantive assistance" in unlocking 2 iPhones in the investigation into the December shooting deaths of 3 US sailors at a Florida naval station, which he called an "act of terrorism."

Apple disputed Barr's claim, while arguing against the idea of "backdoors" for law enforcement to access its encrypted smartphones.

"We reject the characterization that Apple has not provided substantive assistance in the Pensacola investigation," the company said in a statement.

"Our responses to their many requests since the attack have been timely, thorough and are ongoing."

The standoff highlighted the debate between law enforcement and the tech sector about encryption -- a key way to protect the privacy of digital communications, but which can also make investigations difficult, even with a court order.

The latest battle is similar to the dispute between Apple and the US Justice Department after the December 2015 mass shooting in San Bernardino, California, when the iPhone maker rejected a request to develop software to break into the shooter's iPhone.

That fight ended in 2016 when the government paid an outside party a reported $1 million for a tool that circumvented Apple's iPhone encryption.

Barr last year called on Facebook to allow authorities to circumvent encryption to fight extremism, child pornography and other crimes. The social network has said it would move ahead with strong encryption for its messaging applications.

OPENING WRONG DOORS? 

Digital rights activists argue that any privileged access for law enforcement would weaken security and make it easier for hackers and authoritarian governments to intercept messages.

"We have always maintained there is no such thing as a backdoor just for the good guys," Apple's statement said.

"Backdoors can also be exploited by those who threaten our national security and the data security of our customers."

Apple and others argue that digital "breadcrumbs" make it increasingly easy to track people, even without breaking into personal devices.

The government's latest demand "is dangerous and unconstitutional, and would weaken the security of millions of iPhones," Jennifer Granick of the American Civil Liberties Union said in a statement.

"Strong encryption enables religious minorities facing genocide, like the Uighurs in China, and journalists investigating powerful drug cartels in Mexico, to communicate safely."

Granick added that Apple cannot allow the FBI access to encrypted communications "without also providing it to authoritarian foreign governments and weakening our defenses against criminals and hackers."

Kurt Opsahl of the Electronic Frontier Foundation echoed that sentiment, saying Apple "is right to provide strong security" for its devices.

"The AG (attorney general) requesting Apple re-engineer its phones to break that security is a poor security trade-off, and imperils millions of innocent people around the globe," Opsahl tweeted.

James Lewis of the Center for Strategic and International Studies, a Washington think tank, said he believes it's possible to allow law enforcement access without sacrificing encryption.

"You're not weakening encryption, you're making it so it's not end-to-end," Lewis told AFP.

"It means that there's a third party who can look at it under appropriate authority."

But Lewis said he does not expect either side to come out a winner in the battle, and that US officials will likely find another outside party to crack the 2 iPhones belonging to the shooter, Royal Saudi Air Force 2nd Lt. Mohammed Saeed Alshamran, who died in the attack.

"It's a repeat of the movie we saw in San Bernardino," he said.

"It's going to be harder because Apple probably fixed the trick that worked in San Bernardino."

Agence France-Presse 

Tuesday, November 19, 2019

EXPLAINER: End-to-end encryption and chat privacy


SAN FRANCISCO — A Justice Department official hinted on Monday that a years-long fight over encrypted communications could become part of a sweeping investigation of big tech companies.

While a department spokesman declined to discuss specifics, a speech Monday by the deputy attorney general, Jeffrey A. Rosen, pointed toward heightened interest in technology called end-to-end encryption, which makes it nearly impossible for law enforcement and spy agencies to access people’s digital communications.

Law enforcement and technologists have been arguing over encryption controls for more than two decades. On one side are privacy advocates and tech bosses like Apple’s chief executive, Tim Cook, who believe people should be able to have online communications free of snooping. On the other side are law enforcement and some lawmakers, who believe tough encryption makes it impossible to track child predators, terrorists and other criminals.

Attorney General William P. Barr, joined by his British and Australian counterparts, recently pressed Facebook’s chief executive, Mark Zuckerberg, to abandon plans to embed end-to-end encryption in services like Messenger and Instagram. WhatsApp, which is owned by Facebook, already provides that tougher encryption.

“Companies should not deliberately design their systems to preclude any form of access to content even for preventing or investigating the most serious crimes,” Barr wrote in a letter last month.

Here is an explanation of the technology and the stakes.

HOW DOES THE ENCRYPTION WORK?

End-to-end encryption scrambles messages in such a way that they can be deciphered only by the sender and the intended recipient. As the label implies, end-to-end encryption takes place on either end of a communication. A message is encrypted on a sender’s device, sent to the recipient’s device in an unreadable format, then decoded for the recipient.

There are several ways to do this, but the most popular works like this: A program on your device mathematically generates two cryptographic keys — a public key and a private key.

The public key can be shared with anyone who wants to encrypt a message to you. The private key, or secret key, decrypts messages sent to you and never leaves your device. Think of it like a locked mailbox. Anyone with a public key can put something in your box and lock it, but only you have the private key to unlock it.

HOW IS IT DIFFERENT FROM OTHER FORMS OF ENCRYPTION?

A more common form of encryption, known as transport layer encryption, relies on a third party, like a tech company, to encrypt messages as they move across the web.

With this type of encryption, law enforcement and intelligence agencies can get access to encrypted messages by presenting technology companies with a warrant or national security letter. The sender and recipient would not have to know about it.

End-to-end encryption ensures that no one can eavesdrop on the contents of a message while it is in transit. It forces spies or snoops to go directly to the sender or recipient to read the content of the encrypted message. Or they must hack directly into the sender’s or recipient’s device, something that can be harder to do “at scale” and makes mass surveillance much more difficult.

Privacy activists, libertarians, security experts and human rights activists argue that end-to-end encryption steers governments away from mass surveillance and toward a more targeted, constitutional form of intelligence gathering. But intelligence and law enforcement agencies argue that end-to-end encryption makes it much harder to track terrorists, pedophiles and human traffickers.

When Zuckerberg announced in March that Facebook would move all three of its messaging services to end-to-end encryption, he acknowledged the risk it presented for “truly terrible things like child exploitation.”

“Encryption is a powerful tool for privacy, but that includes the privacy of people doing bad things,” he said.

HASN'T THIS DEBATE BEEN AROUND FOR DECADES?

The debate over end-to-end encryption has had several iterations, beginning in the 1990s with the spread of Pretty Good Privacy, or PGP, software, an end-to-end encryption scheme designed by a programmer named Phil Zimmermann. As a result, the Clinton administration proposed a “Clipper Chip,” a back door for law enforcement and security agencies.

But the Clipper Chip provoked a backlash from a coalition of unlikely bedfellows, including the American Civil Liberties Union; televangelist Pat Robertson; and Sens. John Kerry, (Democrat, Massachusetts), and John Ashcroft, (Republican, Montana). The White House backed down in 1996.

End-to-end encryption gained more traction in 2013, after data leaked by former National Security Agency contractor Edward J. Snowden appeared to show the extent to which the NSA and other intelligence and law enforcement agencies were gaining access to users’ communications through companies like Yahoo, Microsoft, Google and Facebook without their knowledge.

Encrypted messaging apps like Signal and Wicker gained in popularity, and tech giants like Apple and Facebook started wrapping user data in end-to-end encryption.

Google, which pledged to add an end-to-end encryption option for Gmail users several years ago, has not made this the default option for email. But the company does offer a video-calling app, Duo, that is end-to-end encrypted.

As more communications moved to these end-to-end encrypted services, law enforcement and intelligence services around the world started to complain about data’s “going dark.”

WHAT ARE GOVERNMENTS DOING?

Government agencies have tried to force technology companies to roll back end-to-end encryption, or build back doors, like the Clipper Chip of the 1990s, into their encrypted products to facilitate government surveillance.

In the most aggressive of these efforts, the FBI tried in 2016 to compel Apple in federal court to unlock the iPhone of one of the attackers in the 2015 mass shooting in San Bernardino, California.

Cook of Apple called the FBI’s effort “the software equivalent of cancer.” He said complying with the request would open the door to more invasive government interception down the road.

“Maybe it’s an operating system for surveillance, maybe the ability for the law enforcement to turn on the camera,” Cook told ABC News. “I don’t know where it stops.”

Privacy activists and security experts noted that any back door created for US law enforcement agencies would inevitably become a target for foreign adversaries, cybercriminals and terrorists.

Alex Stamos, chief security officer of Yahoo at the time, likened the creation of an encryption back door to “drilling a hole in the windshield.” By trying to provide an entry point for one government, you end up cracking the structural integrity of the entire encryption shield.

The FBI eventually backed down. Instead of forcing Apple to create a back door, the agency said it had paid an outside party to hack into the phone of the San Bernardino gunman.

SO WHAT NOW?

Governments have stepped up their calls for an encryption back door.

Last year, Australian lawmakers passed a bill requiring technology companies to provide law enforcement and security agencies with access to encrypted communications. The bill gave the government the ability to get a court order allowing it to secretly order technology companies and technologists to re-engineer software and hardware so that it can be used to spy on users.

Australia’s law is based on Britain’s 2016 Investigatory Powers Act, which compels British companies to hand over the keys to unscramble encrypted data to law enforcement agencies. The Australian law could apply to overseas companies like Facebook and Apple.

Australia’s new law applies to network administrators, developers and other tech employees, forcing them to comply with secret government demands without notifying their employers.

Other governments are also considering new encryption laws. In India, Facebook’s biggest market, officials told the country’s Supreme Court in October that Indian law requires Facebook to decrypt messages and supply them to law enforcement upon request.

“They can’t come into the country and say, ‘We will establish a non-decryptable system,’” India’s attorney general, K.K. Venugopal, told the court, referring to Facebook and other big tech platforms. India’s Supreme Court has said it will reconvene on the issue in January.


2019 The New York Times Company

source: news.abs-cbn.com

Wednesday, November 6, 2019

Facebook to widen access to encryption feature, test safety measures


LISBON - Facebook will outline on Wednesday an expanded test of encryption on its Messenger platform, moving ahead with a controversial plan for enhanced security that regulators and government officials warn will aid criminals.

Executives told Reuters they would also detail safety measures, including stepped-up advisories for recipients of unwanted content.

The moves, which will be more fully described by company executives at a Lisbon tech conference, follow complaints by top law enforcement officials in the United States, United Kingdom and Australia that Facebook's intention to encrypt messaging on all its platforms would put child sex predators and pornographers beyond detection.

Facebook messaging privacy chief Jay Sullivan and other executives said the company, supported by civil rights groups and many technology experts, would continue to work toward the changeover, while more carefully scrutinizing the data that it does collect.

Sullivan plans to call attention to a little-publicized option for end-to-end encryption that already exists on Messenger, hoping that increased usage will give the company more data to craft additional safety measures before it makes private chats the default setting.

“This is a good test bed for us,” Sullivan said. “It’s part of the overarching direction.”

Around the same time as the talk on Wednesday, the company will post more on its pages for users about how Secret Conversations function. The feature has been available since 2016 but is not easily discoverable by users and takes extra clicks to activate.

The company is also considering banning the use of Messenger accounts not linked to regular Facebook profiles. The vast majority of Messenger accounts are associated with Facebook profiles, but a greater proportion of stand-alone accounts are used for crime and unwelcome communications, executives said.

Requiring a link to Facebook would reduce the privacy protections of those Messenger users but give the company more information it could use to warn or block troublesome accounts or report suspected crimes to police.

The enhanced safety measures the company plans include sending reminders to users to report unwanted contacts and inviting recipients of unwanted content to send plain-text versions of the chats to Facebook to ban senders or potentially report them to police.

Facebook might also send more prompts to users reached by people with no shared friends or who have had many messages or friend requests rejected.

Facebook had previously said it wanted to ease user reporting of misconduct as it gradually moves toward more encryption, but it has given few details.

source: news.abs-cbn.com

Saturday, October 5, 2019

US pressures tech giants over encrypted messages


WASHINGTON - The US government on Friday urged tech giants to allow police to read encrypted messages, saying access was essential to prevent serious crime despite privacy concerns.

After Facebook rejected giving access to law enforcement agencies, US Attorney General William Barr upped the pressure by issuing an industry-wide call.

"Making our virtual world more secure should not come at the expense of making us more vulnerable in the real world," Barr said in a speech in Washington.

Barr dismissed accusations that the government was seeking a "backdoor" to everyone's private social media messages.

"We are seeking a front door. We would be happy if the companies providing the encryption keep the keys," he said.

Tech giants must abandon "the indefensible posture" that a technical solution was not possible and should develop products to balance cybersecurity with public safety, Barr said.

Facebook already encrypts WhatsApp messages from end-to-end -- meaning only the sender and recipient can read them -- and is working to extend the technology to other apps in its group, including Messenger and Instagram.

Facebook said it was intent on introducing the feature without granting oversight to law enforcement agencies.

"We hope that industry will be an ally, not an adversary," Barr said.

source: news.abs-cbn.com

Friday, October 4, 2019

Facebook's Zuckerberg defends encryption, despite child safety concerns


SAN FRANCISCO, United States - The United States, Britain and Australia signed an open letter earlier in the day calling for Facebook to suspend its encryption plan, saying it would hinder the fight against child abuse and terrorism.

The United States, Britain and Australia signed an open letter earlier in the day calling for Facebook to suspend its encryption plan, saying it would hinder the fight against child abuse and terrorism.

Zuckerberg, speaking in a livestream of the company's weekly internal Q&A session, said he had been aware of child exploitation risks before announcing his encryption plan and acknowledged that it would reduce tools to fight the problem.

"When we were deciding whether to go to end-to-end encryption across the different apps, this was one of the things that just weighed the most heavily on me," he said.

Addressing an employee question about online child abuse, Zuckerberg acknowledged that losing access to the content of messages would mean "you're fighting that battle with at least a hand tied behind your back."

But he said he was "optimistic" that Facebook would be able to identify predators even in encrypted systems using the same tools it used to fight election interference, like patterns of activity and links between accounts on different platforms.

He also suggested the company might further limit the ways adults can interact with minors on Facebook's platforms.

Zuckerberg announced his plan to pivot the company toward more private forms of communication in March, capping months of internal debate over the merits of encryption, three sources familiar with the discussions told Reuters.

Inside the company, privacy engineers and others eager to shed the legacy of the Cambridge Analytica scandal saw the move as a win, as did product managers watching the steady uptick of growth at Facebook's encrypted messaging service WhatsApp.

But members of Facebook's safety team familiar with the child exploitation risks argued against the plan, raising deep concerns through the group's leaders and in large company meetings with senior executives, the sources said.

The United States, Britain and Australia said in their joint letter that they had engaged with Facebook on the issue, but that the company had not committed to addressing their "serious concerns" about the impact of its proposals.

The National Center for Missing and Exploited Children also met with Zuckerberg and other senior leaders of Facebook, who offered assurances that child safety was important to them.

source: news.abs-cbn.com

Thursday, March 9, 2017

CIA blasts WikiLeaks for publishing secret documents


The Central Intelligence Agency on Wednesday accused WikiLeaks of endangering Americans, helping US rivals and hampering the fight against terror threats by releasing what the anti-secrecy site claimed was a trove of CIA hacking tools.

A CIA spokeswoman would not confirm the authenticity of the materials published by WikiLeaks, which said they were leaked from the spy agency's hacking operations.

Nevertheless, said spokeswoman Heather Fritz Horniak, "The American public should be deeply troubled by any WikiLeaks disclosure designed to damage the intelligence community's ability to protect America against terrorists and other adversaries."

"Such disclosures not only jeopardize US personnel and operations, but also equip our adversaries with tools and information to do us harm," she said.

Horniak defended the CIA's cyber operations, which the WikiLeaks materials showed focused heavily on breaking into personal electronics using a wide range of malware systems.

"It is CIA's job to be innovative, cutting-edge, and the first line of defense in protecting this country from enemies abroad," she said.

- Massive leak -

On Tuesday, WikiLeaks published nearly 9,000 documents it said were part of a huge trove leaked from the CIA, describing it as the largest-ever publication of secret intelligence materials.

"This extraordinary collection, which amounts to more than several hundred million lines of code, gives its possessor the entire hacking capacity of the CIA," it said.

The documents showed that CIA hackers can turn a TV into a listening device, bypass popular encryption apps, and possibly control one's car.

Most experts believe the materials to be genuine, and US media said Wednesday that the Federal Bureau of Investigation is opening a criminal probe into the leak.

The source of the materials remained unclear. The investigation could focus on whether the CIA was sloppy in its controls, or, as The Washington Post reported, it could be "a major mole hunt" for a malicious leaker or turncoat inside the agency.

WikiLeaks itself said the documents, hacking tools and code came from an archive that had circulated among US government hackers and private contractors.

An investigation would come as the CIA is already enmeshed in a politically-charged probe into Russia's alleged interference in the US election last year in support of President Donald Trump's campaign.

WikiLeaks, which has stunned the US government with a series of publications of top secret political, diplomatic and intelligence materials, said the publication Tuesday was only the first of a series of releases of CIA hacking materials.

That raised concerns that the site could release the actual hacking tools it obtained along with the documents. Experts worry those could fall into the hands of anyone, including US enemies and criminals.

 - Tech sector scrambles for fixes -

The WikiLeaks documents detailed the CIA's practice of exploiting vulnerabilities in hardware and software, without ever informing producers of them.

The CIA allegedly found ways to hack into personal electronics from leading companies like Apple and Samsung, Android phones, popular Microsoft software, and crucial routers from major manufacturers.

The documents suggest it can also infiltrate smartphones in a way that allows it to get around popular messaging encryption apps.

The tech sector was scrambling to understand how their products were at risk.

"While our initial analysis indicates that many of the issues leaked today were already patched in the latest iOS, we will continue work to rapidly address any identified vulnerabilities," Apple said in an emailed statement.

"We're confident that security updates and protections in both Chrome and Android already shield users from many of these alleged vulnerabilities," Google director of information security and privacy Heather Adkins said in a released statement.

"Our analysis is ongoing and we will implement any further necessary protections."

Samsung and Microsoft both said they were "looking into" what WikiLeaks revealed.

 - Encryption apps safe-


Joseph Hall, a technologist with the Center for Democracy and Technology, a digital rights organization, said the documents raise questions about the US government's pledge last year to disclose vulnerabilities to technology firms.

That pledge means "security flaws should get back to the companies so they can get fixed, and not languish for years," he said.

The American Civil Liberties Union commented in a tweet: "When the govt finds software security holes, it should help fix them, not hoard them and leave everyone vulnerable."

Companies that make encryption programs and apps targeted by the CIA said the revelations show the agency has not been able to break their software.

Open Whisper Systems, which developed the technology for the Signal encryption app, said the CIA documents showed that Signal works.

"None of the exploits are in Signal or break Signal Protocol encryption," the group said in a tweet.

"The existence of these hacking tools is a testimonial to the strength of the encryption," said Steve Bellovin, a Columbia University computer science researcher, in a blog post.

source: news.abs-cbn.com

Tuesday, March 15, 2016

Chinese hackers behind U.S. ransomware attacks - security firms


Hackers using tactics and tools previously associated with Chinese government-supported computer network intrusions have joined the booming cyber crime industry of ransomware, four security firms that investigated attacks on U.S. companies said.

Ransomware, which involves encrypting a target's computer files and then demanding payment to unlock them, has generally been considered the domain of run-of-the-mill cyber criminals.

But executives of the security firms have seen a level of sophistication in at least a half dozen cases over the last three months akin to those used in state-sponsored attacks, including techniques to gain entry and move around the networks, as well as the software used to manage intrusions.

"It is obviously a group of skilled of operators that have some amount of experience conducting intrusions," said Phil Burdette, who heads an incident response team at Dell SecureWorks.

Burdette said his team was called in on three cases in as many months where hackers spread ransomware after exploiting known vulnerabilities in application servers. From there, the hackers tricked more than 100 computers in each of the companies into installing the malicious programs.

The victims included a transportation company and a technology firm that had 30 percent of its machines captured.

Security firms Attack Research, InGuardians and G-C Partners, said they had separately investigated three other similar ransomware attacks since December.

Although they cannot be positive, the companies concluded that all were the work of a known advanced threat group from China, Attack Research Chief Executive Val Smith told Reuters.

The ransomware attacks have not previously been reported. None of the companies that were victims of the hackers agreed to be identified publicly.

The security companies investigating the advanced ransomware intrusions have various theories about what is behind them, but they do not have proof and they have not come to any firm conclusions.

Most of the theories flow from the possibility that the Chinese government has reduced its support for economic espionage, which it pledged to oppose in an agreement with the United States late last year. Some U.S. companies have reported a decline in Chinese hacking since the agreement.

Smith said some government hackers or contractors could be out of work or with reduced work and looking to supplement their income via ransomware.

It is also possible, Burdette said, that companies which had been penetrated for trade secrets or other reasons in the past were now being abandoned as China backs away, and that spies or their associates were taking as much as they could on the way out. In one of Dell's cases, the means of access by the team spreading ransomware was established in 2013.

The cyber security experts could not completely rule out more prosaic explanations, such as the possibility that ordinary criminals had improved their skills and bought tools previously used only by governments.

Dell said that some of the malicious software had been associated by other security firms with a group dubbed Codoso, which has a record of years of attacks of interest to the Chinese government, including those on U.S. defense companies and sites that draw Chinese minorities.

PAYMENT IN BITCOIN

Ransomware has been around for years, spread by some of the same people that previously installed fake antivirus programs on home computers and badgered the victims into paying to remove imaginary threats.

In the past two years, better encryption techniques have often made it impossible for victims to regain access to their files without cooperation from the hackers. Many ransomware payments are made in the virtual currency Bitcoin and remain secret, but institutions including a Los Angeles hospital have gone public about ransomware attacks.

Ransomware operators generally set modest prices that many victims are willing to pay, and they usually do decrypt the files, which ensures that victims will post positively online about the transaction, making the next victims who research their predicament more willing to pay.

Security software companies have warned that because the aggregate payoffs for ransomware gangs are increasing, more criminals will shift to it from credit card theft and other complicated scams.

The involvement of more sophisticated hackers also promises to intensify the threat.

InGuardians CEO Jimmy Alderson said one of the cases his company investigated appeared to have been launched with online credentials stolen six months earlier in a suspected espionage hack of the sort typically called an Advanced Persistent Threat, or APT.

"The tactics of getting access to these networks are APT tactics, but instead of going further in to sit and listen stealthily, they are used for smash-and-grab," Alderson said.

source: www.abs-cbnnews.com

Tuesday, February 23, 2016

Apple urges US gov't to form panel on encryption issues amid dispute


Apple is not backing down on its stance to protect customers' data.

In a statement posted on its website, the tech giant called on the US government to create a panel on encryption and data privacy issues.

Apple added it would gladly take part on that effort.

The tech giant has been opposing a court order to help the FBI unlock the iPhone used by one of the shooters in the San Bernardino terror attack.

The company wants that demand withdrawn, saying it sets a dangerous precedent that threatens civil liberties and makes the data on all other iPhones vulnerable to hacks and cyberattacks.

Still, Apple's stand does not sit well with the families of the San Bernardino attack victims as they intend to file court papers to support government's position.

-ANC's News Now, February 23, 2016

source: www.abs-cbnnews.com

Saturday, February 20, 2016

Apple v FBI, is my iPhone safe?


NEW YORK — On Wednesday, a federal judge ordered Apple Inc. to help the FBI hack into an encrypted iPhone used by Syed Farook, who along with his wife, Tashfeen Malik, killed 14 people in December. Specifically, the government wants Apple to bypass a self-destruct feature that erases the phone's data after too many unsuccessful attempts to guess the passcode. Apple has helped the government before in this and previous cases, but this time Apple CEO Tim Cook said no and Apple is appealing the order.

What's the big deal? Why isn't Apple cooperating, and what does this mean for ordinary iPhone users? AP explains:

WHY ALL THE FUSS?

The clash brings to a head a long-simmering debate between technology companies whose business relies on protecting digital privacy (except, ahem, where advertising is concerned) and law enforcement agencies who say they need the ability to recover evidence or eavesdrop on the communications of terrorists or criminals to do their job. This is the first major case that requires the two sides to present their arguments in court, so it could ultimately affect millions of smartphone users.

IT'S JUST ONE IPHONE. AND THIS COULD HELP CATCH TERRORISTS. SO WHAT'S THE BIG DEAL?
While the judge on the case says the government is only asking for help unlocking one, single iPhone, Apple says the case is much bigger than that and sets a dangerous precedent. Cook says the company doesn't have a system to bypass the self-destruct one. And if it creates one, the technology it creates could eventually be used to work against other iPhones. Then everyone's iPhone would potentially be less secure. As Apple CEO Cook said, "Once created, the technique could be used over and over again, on any number of devices. In the physical world, it would be the equivalent of a master key, capable of opening hundreds of millions of locks — from restaurants and banks to stores and homes."


IS MY IPHONE STILL SECURE?

Yes. The technology being debated doesn't even exist yet. So what does this mean for your iPhone? In the short term, nothing. The case is likely to drag on for months — even years, if it works its way through appeals to the Supreme Court. But ultimately, the case could set the standard for just who has access to private data — the private message, photos and other data you store on your phone — and could cause millions of smartphones users to rethink what they store on their phones.

WILL MY DISGRUNTLED EX OR FORMER BOSS BE ABLE TO HACK INTO MY PHONE?

Not likely. Even if the technology is ultimately built and ruled legal, it would only be used by governments, or maybe cybercriminal masterminds. But probably not the average Joe next door — though you might want to watch out for his brilliant, disaffected hacker kid. (Also, all bets are off if you're talking about a phone provided by your employer, who already has the right to any information stored there.)

source: philstar.com

Thursday, February 18, 2016

Apple likely to invoke free-speech rights in encryption fight


NEW YORK/SAN FRANCISCO - Apple Inc. will likely seek to invoke the United States' protections of free speech as one of its key legal arguments in trying to block an order to help unlock the encrypted iPhone of one of the San Bernardino shooters, lawyers with expertise in the subject said this week.

The tech giant and the Obama administration are on track for a major collision over computer security and encryption after a federal magistrate judge in Los Angeles handed down an order on Tuesday requiring Apple to provide specific software and technical assistance to investigators.

Apple Chief Executive Officer Tim Cook called the request from the Federal Bureau of Investigation unprecedented. Other tech giants such as Facebook Inc., Twitter Inc. and Alphabet Inc.'s Google have rallied to support Apple.

Apple has retained two prominent, free-speech lawyers to do battle with the government, according to court papers: Theodore Olson, who won the political-speech case Citizens United v. Federal Election Commission in 2010, and Theodore Boutrous, who frequently represents media organizations.

Government lawyers from the U.S. Justice Department have defended their request in court papers by citing various authorities, such as a 1977 U.S. Supreme Court ruling that upheld an order compelling a telephone company to provide assistance with setting up a device to record telephone numbers.

The high court said then that the All Writs Act, a law from 1789, authorized the order, and the scope of that ruling is expected to be a main target of Apple when it files a response in court by early next week.

But Apple will likely also broaden its challenge to include the First Amendment's guarantee of speech rights, according to lawyers who are not involved in the dispute but who are following it.

Compared with other countries, the United States has a strong guarantee of speech rights even for corporations, and at least one court has ruled that computer code is a form of speech, although that ruling was later voided.

Apple could argue that being required to create and provide specific computer code amounts to unlawful compelled speech, said Riana Pfefferkorn, a cryptography fellow at Stanford University's Center for Internet and Society.

The order against Apple is novel because it compels the company to create a new forensic tool to use, not just turn over information in Apple's possession, Pfefferkorn said. "I think there is a significant First Amendment concern," she said.

A spokesman for the U.S. Attorney's Office in Los Angeles declined to comment on the possible free-speech questions on Thursday.

A speech-rights argument from Apple, though, could be met with skepticism by the courts because computer code has become ubiquitous and underpins much of the U.S. economy.

"That is an argument of enormous breadth," said Stuart Benjamin, a Duke University law professor who writes about the First Amendment. He said Apple would need to show that the computer code conveyed a "substantive message."

In a case brought by a mathematician against U.S. export controls, a three-judge panel of the 9th U.S. Circuit Court of Appeals, which covers California, found in 1999 that the source code behind encryption software is protected speech. The opinion was later withdrawn so the full court could rehear the case, but that rehearing was canceled and the appeal declared moot after the government revised its export controls.

The FBI and prosecutors are seeking Apple's assistance to read the data on an iPhone 5C that had been used by Rizwan Farook, who along with his wife, Tashfeen Malik, carried out the San Bernardino shootings that killed 14 people and wounded 22 others at a holiday party.

U.S. prosecutors were smart to pick the mass shooting as a test case for an encryption fight with tech companies, said Michael Froomkin, a University of Miami law professor. That is because the shooting had a large emotional impact while also demonstrating the danger posed by armed militants, he said.

In addition, the iPhone in dispute was owned not by Farook but by his employer, a local government, which has consented to the search of the iPhone. The federal magistrate who issued the order, Sheri Pym, is also a former federal prosecutor.

"This is one of the worst set of facts possible for Apple. That's why the government picked this case," Froomkin said.

Froomkin added, though, that the fight was enormously important for the company because of the possibility that a new forensic tool could be easily used on other phones and the damage that could be done to Apple's global brand if it cannot withstand government demands on privacy. "All these demands make their phones less attractive to users," he said.

source: www.abs-cbnnews.com