Friday, 14 August 2015

EFF’s Privacy Badger: Another Tool in Your Privacy Toolkit

You have your VPN, your web proxy and your secure messenger. What else should you keep in your privacy toolkit?

EFF, Electronic Frontier Foundation, Privacy Badger, web tracking, third party
EFF's Privacy Badger blocks advertiser & third party tracking.

The Electronic Frontier Foundation (EFF) recently released Privacy Badger 1.0, a browser extension for Firefox and Chrome that blocks advertisers and third parties from tracking activity online.

EFF Staff Technologist and Privacy Badger Lead Developer Cooper Quintin explained, "It's likely you are being tracked by advertisers and other third parties online. You can see some of it when it's happening, such as ads that follow you around the Web that seem to reflect your past browsing history. Those echoes from your past mean you are being tracked, and the records of your online activity are distributed to other third parties--all without your knowledge, control, or consent. But Privacy Badger 1.0 will spot many of the trackers following you without your permission, and will block them or screen out the cookies that do their dirty work."

Why we like Privacy Badger:
  • Privacy Badger shows users who was tracking them
  • Privacy Badger automatically initiates a "Do Not Track" browser setting
  • Committed digital privacy advocate EFF works for user privacy, not advertisers

What Privacy Badger won't do:
  • Block tracking by websites users actively visit (first party websites)
  • Block mobile web tracking
  • Block Internet Explorer, Opera or Safari web tracking 

Privacy Badger, in a nutshell: 
Privacy Badger 1.0 is an attempt to enforce what its corresponding Do Not Track policy cannot. Do Not Track empowers users to emerge from their shadows in order to assert their belief in a right to opt-out of tracking, but without legislative support, has found limited success in motivating first and third party trackers to voluntarily respect users' requests for privacy. Privacy Badger enables users to take matters into their own hands.

Neither Privacy Badger 1.0 nor the Do Not Track policy anonymizes identity or blocks all web tracking, but together they are powerful tools in the digital privacy toolkit. Be informed, surf secure and stay Rando!

Wednesday, 12 August 2015

Death of Bangladeshi Blogger Strengthens Argument for Legislative Reform

Niloy Neel, Bangladesh, Bangladeshi blogger, Section 57, digital privacy, ICT Act, 2013 Amendment
Niloy Neel concealed his true identity on Facebook. [Source: bdnews24.com]
Friday’s murder of Niloy Neel confirms that a list is a dangerous place to find oneself in the digital age.

Four of the 84 individuals on a list of Bangladeshi “atheist bloggers”—Neel, along with Avijit Roy, Oyasiqur Rahman Babu and Ananta Bijoy Das—have been brutally murdered in 2015.

The list dates back to 2013, the year the Bangladeshi government amended the Information and Communication Technology (ICT) Act to legalize warrantless arrests and increase maximum prison sentences to 14 years. Given the Act's Section 57, which called for punishment for information that "causes to deteriorate or creates possibility to deteriorate law and order, prejudice the image of the State or person or causes to hurt or may hurt religious belief or instigate against any person or organization," the amendment invited free expression to be countered with stiff consequences.

At the time, established Islamic groups collected and submitted the 84 names to the Bangladeshi government, asking for the bloggers’ arrests. The list, ignored by the government, instead fell into the hands of Islamic fundamentalists, who on Friday exhibited their growing willingness to take matters into their own hands.

Neel had suspected himself to be a target and asked the police for protection, who only told him to leave the country. He stayed in Bangladesh and took what precautions he could: in addition to using a penname, he removed photos and changed his location on Facebook. Regardless, the blogger was attacked in his own home, proving just how little protection or privacy he had.

The international community has responded with an outpouring of criticism for Bangladesh’s lack of responsibility in protecting its citizens’ rights to expression and to life:

United Nations Special Rapporteurs on freedom of expression, David Kaye, and on extrajudicial executions, Christof Heyns, condemned the murder: "The violent killing of another critical voice in Bangladesh shows that serious threats to freedom of expression persist in the country. The organized targeting of critical voices aims at promoting a culture of silence and fear, and affects the society as a whole. The Bangladeshi authorities must not only continue to strongly condemn these horrendous acts against freedom of expression, but should also ensure that their words are followed by more effective efforts to ensure greater accountability and prevent this kind of violence."

The Committee to Protect Journalists’ Sumit Galhotra asked, “How many more bloggers must be murdered before the government of Prime Minister Sheikh Hasina acts decisively to stem violence and impunity?” 

Official Bangladeshi rhetoric, however, has done little to address this question. Inspector General of Police AKM Shahidul Hoque recently defended the law: “We need to remember that hurting religious sentiments is a crime according to our law. Those who are free thinkers and writers, I will request them, please make sure that we don’t cross the line. Anything that may hurt anyone’s religious sentiments or beliefs should not be written.”

With four men dead in six months, Hoque needs to ask the law to change, not the bloggers to silence themselves. It is 2013’s amendment to the ICT Act that created the notion that individuals should be punished harshly for their ideas, and in turn manifested a list of people to target. It is time for the Bangladeshi government to take responsibility for the toxic environment it has created.

In June, there were reported plans to amend the ICT Act by the end of 2015. Bangladesh cannot wait that long.

Tuesday, 11 August 2015

Freedom House Evaluates Internet Freedom Worldwide

Independent Watchdog Freedom House has categorized 65 countries as Free, Partly Free or Not Free in terms of their Freedom on the Net:

Freedom House, Freedom on the Net, Internet Freedom

Freedom House's interactive map and reports provide detailed explanations of where each country stands in terms of obstacles to internet access, limits on content and violations of user rights. For example:
  • Brazil: Free. 2014's Marco Civil Bill protects digital privacy and net neutrality, but cyberattacks remain an issue.
  • Nigeria: Partly Free. Cybercafes are required to maintain a database of registered users and individuals have been arrested for social media posts.
  • Iran: Not Free. Internet speeds are slow; Twitter and Facebook are blocked; and censorship and arrests for online activities are common.
The study acknowledges a trend towards increased government surveillance, censorship of free speech and pressure on independent news outlets.

Take a look; know your freedoms; and surf secure and stay Rando!

Thursday, 6 August 2015

Just Say No to Civil Liability for Encryption Providers

Last Thursday, Lawfare posted an article so controversial that Edward Snowden was among the digital privacy advocates to speak out in opposition.

Lawfare, Apple, Encryption, Civil Liability, Edward Snowden
In “Civil Liability for End-to-End Encryption: Threat or Fantasy?” legal experts Benjamin Wittes and Zoe Bedell attempted to objectively determine whether a company such as Apple could be held liable if its encrypted communications were utilized in carrying out a terrorist attack or crime.

The conclusion of their two-part article was murky at best: “The irony is that the logical consequence of this analysis is not necessarily that Apple should design its systems so as to facilitate law enforcement access to encrypted communications when presented with a warrant. It may well be, rather, that it should deny service to individuals once it has been put on notice that the government has probable cause that those individuals are engaged in criminal or terrorist activity. That presents a weird kind of due process issue, of course. Those individuals have not yet been charged with any crime. Some may be innocent. And from the Bureau’s point of view, cutting off service may be the last thing investigators want, as it would tip off the suspect that his activity had been noticed. 

“All that said, it’s a bit of a puzzle how a company that knowingly provides encrypted communications services to a specific person identified to it as engaged in terrorist activity escapes liability if and when that person then kills an American in a terrorist incident that relies on that encryption.”

The article was met immediately with harsh criticism from the privacy community, whose tweets accused the authors of everything from “expressly threatening Apple w/terrorism prosecution” to continuing a “braindead jihad against encryption.” Wittes and Bedell posted a second article later that day, insisting that as an encryption agnostic and a backdoor skeptic, respectively, their point had been missed.

If Wittes and Bedell were surprised by the pushback, they shouldn’t have been. The Electronic Frontier Foundation recently declared the Crypto Wars a global phenomenon, citing proposed and passed legislation in the United States, United Kingdom, Netherlands and Australia as evidence. The privacy community recognizes that the world is engaged in a real, immediately impactful debate about the necessity of government backdoors; rather than let an arbitrary inquiry into a hypothetical situation be interpreted as a reason to compromise Apple’s—and everyone’s—encryption, they spoke out.

The concern about the implications of the article was so great that the Intercept even reached out to Edward Snowden for a response. Snowden took advantage of the opportunity to remind Wittes and Bedell that encryption cannot be reduced to a domestic issue:

“The central problem with insecurity mandates has never been addressed by its proponents: if one government can demand access to private communications, all governments can. No matter how good the reason, if the U.S. sets the precedent that Apple has to compromise the security of a customer in response to a piece of government paper, what can they do when the government is China and the customer is the Dalai Lama?”

In solidarity with privacy advocates everywhere, SumRando's founder concurred that “encryption—integral to the security SumRando users rely on—is currently our strongest tool in the fight against unwarranted surveillance and in support of a right to privacy. It is impossible to ignore that people from all walks of life, from around the globe, knowingly or passively, depend on this technology to maintain their online safety."

In Part One of their article, Wittes and Bedell wisely concluded that Apple’s hypothetical liability could simply come down to the “zeitgeist of the moment.” As such, the privacy community has reminded the authors that majority opinion finds no rational, logical or objective argument for holding Apple liable for a crime committed using its encrypted communications.

Sunday, 2 August 2015

It’s a Vulnerable World: July 2015

Oh, the wonderful things hackers can do, especially when we let them. July 2015 has been a month of vulnerabilities, insecurities and computer malfunctions:

PandaLabs, malware strains, ransomware, Africa, security vulnerabilities
[Image: Yuri Samoilov]
July kicked off with the announcement that PandaLabs had detected more than 225,000 new malware strains every day from January to March 2015, a 40% increase over 2014’s Q1. The multinational security lab did not have specific numbers regarding Africa, but reported “It is safe to say that Africa has a high rate of infection, but a low targeted rate of attacks. One of the most common forms of malware currently being distributed is ransomware…Unfortunately the number of victims paying the ransom is growing and this is primarily due to the lack of backups and efficient backup procedures in Africa.”

July 8 proved to be a day of glitches in which separate computer malfunctions brought the New York Stock Exchange to a halt and grounded United Airlines flights. In both incidents, computers—not hackers—have been held accountable.

Security researchers Charlie Miller and Chris Valasek successfully hacked the controls of a Jeep Cherokee in motion, and estimated another 471,000 vehicles are similarly vulnerable to such an attack. Fiat Chrysler initially responded with a software update, but followed up in late July with a recall of 1.4 million vehicles. WIRED’s report on the hackable Jeep later snowballed into similar reports of vulnerabilities with GeneralMotors’ OnStar system, satellites and even sniper rifles.

The United States Federal Trade Commission filed a complaint on July 21 against Lifelock and accused the company of “continuing to make deceptive claims about its identity theft protection services” and “failing to take steps required to protect its users’ data.” The claim is especially worrisome given that Lifelock collects sensitive personal data including social security, credit card and bank account numbers.

In-flight Wi-Fi, Dell, public Wi-Fi, insecurity
[Image: Anthony Quintano]
Flyer beware: Dell reminded travelers that in-flight Wi-Fi is as insecure as any other public Wi-Fi.

HP Fortify released a study that revealed ten top smartwatches have significant security vulnerabilities, including insufficient authentication; lack of encryption; insecure interfaces, software and firmware; and privacy concerns. The study asked “whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built.”

Elastica Cloud Threat Labs discovered phishing web pages on Google Drive and suggested Google’s Single Sign On (SSO) procedures for multiple services make it attractive to hackers. The report concludes, “While the cloud offers unprecedented benefits to its users, it is challenging the traditional security model, and necessitating a modern, flexible security stack designed to account for its borderless perimeter.”

If we've missed any July vulnerabilities, let us know in the comments below. Surf secure and stay Rando!