Archive for NSA

Yikes! The NSA Was Able to Capture Live Data From Compromised iPhones [UPDATED]

Posted in Commentary with tags , , on December 31, 2013 by itnerd

Forbes Magazine is reporting that according to security researcher Jacob Appelbaum, the NSA  could install special software onto iPhones as part of a program called DROPOUTJEEP, that provides significant access to user data and other information:

DROPOUTJEEP is a software implant for the Apple iPhone that utilizes modular mission applications to provide specific SIGINT functionality. This functionality includes the ability to remotely push/pull files from the device. SMS retrieval, contact list retrieval, voicemail, geolocation, hot mic, camera capture, cell tower location, etc. Command, control and data exfiltration can occur over SMS messaging or a GPRS data connection. All communications with the implant will be covert and encrypted

The NSA according to leaked documents claims a 100% success rate. Here’s what Appelbaum thinks:

“Do you think Apple helped them build that?” Appelbaum asks at one point in his talk. “I don’t know. I hope Apple will clarify that… Here’s a problem: I don’t really believe that Apple didn’t help them. I can’t really prove it, but they [the NSA] literally claim that anytime they target an iOS device, that it will succeed for implantation. Either they have a huge collection of exploits that work against Apple products, meaning that they are hoarding information about critical systems that American companies produce and sabotaging them, or Apple sabotaged it themselves. Not sure which one it is. I’d like to believe that since Apple didn’t join the PRISM program until after Steve Jobs died, that maybe it’s just that they write shitty software.”

Ouch. That’s harsh.

There’s no comment yet from Apple. But they would be wise to comment on this and quickly.

UPDATE: All Things Digital has posted a comment from Apple denying any knowledge or participation in the above.

The NSA REALLY Likes The iPhone

Posted in Commentary with tags , , on September 9, 2013 by itnerd

Now I have to admit that I had an “oh crap” moment when I saw this news.com article about the reasons why the iPhone is loved by the NSA. But the more I read it, the (somewhat) better I felt. First, this is what got my attention:

The NSA can retrieve user data on iOS, Android, and BlackBerry devices, according to internal classified documents obtained by German news outlet Der Spiegel. Special task forces within the agency have reportedly studied the three mobile platforms with the goal of accessing the contacts, instant messaging traffic, and location data found on the devices.

The classified documents don’t point to any “large-scale” snooping of smartphone owners, but they do highlight the historic record of a few specific cases. And as detailed in a follow-up story published Monday by Der Spiegel, Apple’s iPhone has been a favorite among NSA agents for several reasons.

The article then goes on to explain how the NSA gets data from iPhones:

NSA programs called “scripts” can spy on 38 different features of the iPhone operating system, though the documents — at least one of which dates back to a 2010 NSA internal report — list just iOS 3 and 4 as the accessible versions. These features include mapping, voice mail, photos, and such apps as Facebook, Yahoo Messenger, and Google Earth.

The NSA also uses the iPhone’s backup files as another infiltration tool, according to Der Spiegel. These files contains such tidbits as contact lists, call logs, and drafts of text messages. And to grab this data, agents don’t even need to hit the iPhone itself — they can simply access the PC used to synchronize with the phone.

Now that’s the part that makes me feel somewhat better. The versions of iOS being referenced in the story are version 3 and 4 of iOS. Now that does not mean any later version such as iOS 6 has anything that the NSA can leverage. We just do not know if that’s the case. Another thing that makes me feel somewhat better. This isn’t, at least not according to story, is that there’s no large scale snooping going on that anyone knows about. Finally when it comes to the backup files, perhaps encrypting them will make them unreadable as you do have that option. Though there’s a report that the NSA can crack encryption so who knows?

Hmmm… Re-reading all of this, I don’t feel somewhat better actually. Does anyone else feel the same?

 

German Security Chief Says To Ditch American Services To Avoid NSA Spying…. #Fail

Posted in Commentary with tags , , on July 5, 2013 by itnerd

For the last few weeks, the planet has been watching the circus that has been created by Edward Snowden and his leaks about the NSA and their spying activities. For German Interior Minister Hans-Peter Friedrich, the fact that the NSA spies on Internet traffic has got his attention. Thus, he offers this advice:

“whoever fears their communication is being intercepted in any way should use services that don’t go through American servers.”

Good luck with that. When you do anything on the Internet, your traffic can go through any number of routes regardless of what service you’re using or where the service is hosted. So there is always a chance that your traffic can go through a place that the NSA monitors. Mr. Friedrich’s comments also don’t factor in the possibility that some other agency might be monitoring what you’re doing. So simply avoiding Facebook, Google, and Twitter will not get you very far. A more realistic response should be to assume that everything that you do online is being monitored. Thus you have to govern yourself accordingly.

In the meantime, perhaps Mr. Friedrich needs to rethink his comments.