Showing posts with label gchq. Show all posts
Showing posts with label gchq. Show all posts

20161023

PRIVATE EYES: The Little-Known Company That Enables Worldwide Mass Surveillance

IT WAS A POWERFUL piece of technology created for an important customer. The Medusa system, named after the mythical Greek monster with snakes instead of hair, had one main purpose: to vacuum up vast quantities of internet data at an astonishing speed.

The technology was designed by Endace, a little-known New Zealand company. And the important customer was the British electronic eavesdropping agency, Government Communications Headquarters, or GCHQ.

Dozens of internal documents and emails from Endace, obtained by The Intercept and reported in cooperation with Television New Zealand, reveal the firm’s key role helping governments across the world harvest vast amounts of information on people’s private emails, online chats, social media conversations, and internet browsing histories.

The leaked files, which were provided by a source through SecureDrop, show that Endace listed a Moroccan security agency implicated in torture as one of its customers. They also indicate that the company sold its surveillance gear to more than half a dozen other government agencies, including in the United States, Israel, Denmark, Australia, Canada, Spain, and India.

Some of Endace’s largest sales in recent years, however, were to the United Kingdom’s GCHQ, which purchased a variety of “data acquisition” systems and “probes” that it used to covertly monitor internet traffic.

Documents from the National Security Agency whistleblower Edward Snowden, previously disclosed by The Intercept, have shown how GCHQ dramatically expanded its online surveillance between 2009 and 2012. The newly obtained Endace documents add to those revelations, shining light for the first time on the vital role played by the private sector in enabling the spying.

Stuart Wilson, Endace’s CEO, declined to answer questions for this story. Wilson said in a statement that Endace’s technology “generates significant export revenue for New Zealand and builds important technical capability for our country.” He added: “Our commercial technology is used by customers worldwide … who rely on network recording to protect their critical infrastructure and data from cybercriminals, terrorists, and state-sponsored cybersecurity threats.”...

https://theintercept.com/2016/10/23/endace-mass-surveillance-gchq-governments/

20160421

How innocent people 'of no security interest' are mere keystrokes away in UK's spy databases


Classified mass-surveillance manuals for UK spies have been published today amid a legal battle against the British government.

The newly obtained documents set out Blighty's secret do's and don'ts for monitoring populations. The files acknowledge that chapter and verse on the lives of people "of no security interest" lie within the spooks' secret databases – and analysts and agents are simply told to avoid pulling up their information.

If you're the kind of person who thinks spies aren't interested in normal citizens, and thus they have nothing to worry about, guess again: your information is in the UK government's hands, and you are just a few keystrokes away. And, it appears, some Brit spies have no problem looking up their families, colleagues and even themselves for trivialities such as sending birthday cards.

As we've long known, for decades now GCHQ, MI5 and MI6 routinely extract people's personal information from files kept by private and public organizations, and plonk it all in highly classified searchable databases.

Now the rules and policies in place since 2001 overseeing this mining of data have been revealed. They include:

Advice urging agents to not search for themselves in the databases, especially for things like looking up where they've been traveling – presumably to remind themselves of their trips and how much to put down on their expenses:

An example of an inappropriate ‘self search’ would be to use the database to remind yourself where you have travelled so you can update your records. This is not a proportionate use of the system, as you could find this information by another means (i.e. check the stamps in your passport or keep a running record of your travel) that would avoid collateral intrusion into other people’s data...


http://www.theregister.co.uk/2016/04/21/bulk_personal_datasets/

20150926

From Radio to Porn, British Spies Track Web Users’ Online Identities

THERE WAS A SIMPLE AIM at the heart of the top-secret program: Record the website browsing habits of “every visible user on the Internet.”

Before long, billions of digital records about ordinary people’s online activities were being stored every day. Among them were details cataloging visits to porn, social media and news websites, search engines, chat forums, and blogs.

The mass surveillance operation — code-named KARMA POLICE — was launched by British spies about seven years ago without any public debate or scrutiny. It was just one part of a giant global Internet spying apparatus built by the United Kingdom’s electronic eavesdropping agency, Government Communications Headquarters, or GCHQ.

The revelations about the scope of the British agency’s surveillance are contained in documents obtained by The Intercept from National Security Agency whistleblower Edward Snowden. Previous reports based on the leaked files have exposed how GCHQ taps into Internet cables to monitor communications on a vast scale, but many details about what happens to the data after it has been vacuumed up have remained unclear.

Amid a renewed push from the U.K. government for more surveillance powers, more than two dozen documents being disclosed today by The Interceptreveal for the first time several major strands of GCHQ’s existing electronic eavesdropping capabilities.

One system builds profiles showing people’s web browsing histories. Another analyzes instant messenger communications, emails, Skype calls, text messages, cell phone locations, and social media interactions. Separate programs were built to keep tabs on “suspicious” Google searches and usage of Google Maps.

The surveillance is underpinned by an opaque legal regime that has authorized GCHQ to sift through huge archives of metadata about the private phone calls, emails and Internet browsing logs of Brits, Americans, and any other citizens — all without a court order or judicial warrant...

https://theintercept.com/2015/09/25/gchq-radio-porn-spies-track-web-users-online-identities/

20150906

The Way GCHQ Obliterated The Guardian’s Laptops May Have Revealed More Than It Intended


In July 2013, GCHQ, Britain’s equivalent of the U.S. National Security Agency, forced journalists at the London headquarters of The Guardian to completely obliterate the memory of the computers on which they kept copies of top-secret documents provided to them by former NSA contractor and whistleblower Edward Snowden.

However, in its attempt to destroy information, GCHQ also revealed intriguing details about what it did and why.

Two technologists, Mustafa Al-Bassam and Richard Tynan, visited Guardianheadquarters last year to examine the remnants of the devices. Al-Bassam is an ex-hacker who two years ago pleaded guilty to joining attacks on Sony, Nintendo, and other companies, and now studies computer science at King’s College; Tynan is a technologist at Privacy International with a PhD in computer science. The pair concluded, first, that GCHQ wanted The Guardian to completely destroy every possible bit of information the news outlet might retain; and second, that GCHQ’s instructions may have inadvertently revealed all the locations in your computer where information may be covertly stored...

https://theintercept.com/2015/08/26/way-gchq-obliterated-guardians-laptops-revealed-intended/

20150905

Clinton secrets hacked by spy in bag

THE MI6 spy found dead in a holdall had illegally hacked into secret data on Bill Clinton, The Sun on Sunday can reveal.

Gareth Williams, 31, dug out the guestlist for an event the former American president was going to as a favour for a pal.

The codebreaker — who had breached his security clearance — handed the list to the friend, who was also to be a guest.

MI6 bosses raged over the data breach amid growing tensions with US security services over Mr Williams’s transatlantic work.

Today, just over five years since his body was found inside a padlocked bag, his death remains one of Britain’s most mysterious unsolved cases.

The Sun on Sunday can reveal that voicemail messages Mr Williams left for family and pals were deleted in the days after his death. And a rival agent may also have broken into the flat to destroy or remove evidence.

The inquest was barred from discussing Mr Williams’s work in public. But sources say he was helping on the joint monitoring network Echelon, which uses sophisticated programs to eavesdrop on terrorists and criminal gangs, particularly those in Russia...

http://www.thesun.co.uk/sol/homepage/features/6613428/Secrets-of-MI6-spy-found-dead-in-bag-revealed.html

20150804

GCHQ AND ME: My Life Unmasking British Eavesdroppers


I STEPPED FROM the warmth of our source’s London flat. That February night in 1977, the air was damp and cool, the buzz of traffic muted in this leafy North London suburb, in the shadow of the iconic Alexandra Palace. A fellow journalist and I had just spent three hours inside, drinking Chianti and talking about secret surveillance with our source, and now we stood on the doorstep discussing how to get back to the south coast town where I lived.

Events were about to take me on a different journey. Behind me, sharp footfalls broke the stillness. A squad was running, hard, toward the porch of the house we had left. Suited men surrounded us. A burly middle-aged cop held up his police ID. We had broken “Section 2″ of Britain’s secrecy law, he claimed. These were “Special Branch,” then the elite security division of the British police.

For a split second, I thought this was a hustle. I knew that a parliamentary commission had released a report five years earlier that concluded that the secrecy law, first enacted a century ago, should be changed. I pulled out my journalist identification card, ready to ask them to respect the press.

But they already knew that my companion that evening, Time Out reporter Crispin Aubrey, and I were journalists. And they had been outside, watching our entire meeting with former British Army signals intelligence (Sigint) operator ≈, who at the time was a social worker.

Aubrey and I were arrested on suspicion of possessing unauthorized information. They said we’d be taken to the local police station. But after being forced into cars, we were driven in the wrong direction, toward the center of London. I became uneasy...

https://firstlook.org/theintercept/2015/08/03/life-unmasking-british-eavesdroppers/

20140816

NSA/GCHQ: The HACIENDA Program for Internet Colonization

Since the early days of TCP, port scanning has been used by computer saboteurs to locate vulnerable systems. In a new set of top secret documents seen by Heise, it is revealed that in 2009, the British spy agency GCHQ made port scans a "standard tool" to be applied against entire nations (Figure 1, see the picture gallery). Twenty-seven countries are listed as targets of the HACIENDA program in the presentation (Figure 2), which comes with a promotional offer: readers desiring to do reconnaissance against another country need simply send an e-mail (Figure 3).

The HACIENDA Program
The documents do not spell out details for a review process or the need to justify such an action. It should also be noted that the ability to port-scan an entire country is hardly wild fantasy; in 2013, a port scanner called Zmap was implemented that can scan the entire IPv4 address space in less than one hour using a single PC. [3] The massive use of this technology can thus make any server anywhere, large or small, a target for criminal state computer saboteurs...

20140524

What does GCHQ know about our devices that we don't?

While the initial disclosures by Edward Snowden revealed how US authorities are conducting mass surveillance on the world's communications, further reporting by the Guardian newspaper uncovered that UK intelligence services were just as involved in this global spying apparatus. Faced with the prospect of further public scrutiny and accountability, the UK Government gave the Guardian newspaper an ultimatum: hand over the classified documents or destroy them.

The Guardian decided that having the documents destroyed was the best option. By getting rid of only the documents stored on computers in the UK, it would allow Guardian journalists to continue their work from other locations while acquiescing to the Government's demand. However, rather than trust that the Guardian would destroy the information on their computers to the Government's satisfaction, GCHQ sent two representatives to supervise the operation. Typically, reliable destruction of such hardware in the circumstances would be to shred or melt all electronic components using a much larger version of the common paper shredder and leaving only the dust of the original devices. Indeed, some devices such as external USB sticks were turned to dust.

Alternatively, it might have been expected that GCHQ would solely target the hard drives of the devices in question. The hard drives, after all, are one of the few components of a computer where user data is supposed to be retained after the power to the device is removed.

Surprisingly, however, GCHQ were not just interested in hard drives nor did they destroy whole devices. An examination of the targeted hardware by Privacy International, with cooperation from the Guardian, has found the whole episode to be more troubling and puzzling than previously believed... 1

https://www.privacyinternational.org/blog/what-does-gchq-know-about-our-devices-that-we-dont

20130616

GCHQ intercepted foreign politicians' communications at G20 summits

Foreign politicians and officials who took part in two G20 summit meetings in London in 2009 had their computers monitored and their phone calls intercepted on the instructions of their British government hosts, according to documents seen by the Guardian. Some delegates were tricked into using internet cafes which had been set up by British intelligence agencies to read their email traffic.

The revelation comes as Britain prepares to host another summit on Monday – for the G8 nations, all of whom attended the 2009 meetings which were the object of the systematic spying. It is likely to lead to some tension among visiting delegates who will want the prime minister to explain whether they were targets in 2009 and whether the exercise is to be repeated this week.

The disclosure raises new questions about the boundaries ofsurveillance by GCHQ and its American sister organisation, the National Security Agency, whose access to phone records and internet data has been defended as necessary in the fight against terrorism and serious crime. The G20 spying appears to have been organised for the more mundane purpose of securing an advantage in meetings. Named targets include long-standing allies such as South Africa and Turkey...

http://www.guardian.co.uk/uk/2013/jun/16/gchq-intercepted-communications-g20-summits

20130614

An Old Mystery Solved: Project C-43 and Public Key Encryption

For most of history, it was believed that the only way a message could be encrypted was if the sender and the receiver shared the secret of srambling and unscrambling the text. That view changed sharply in 1976, when Stanford computer scientists Martin E. Hellman and Whitfield Diffie published a paper called ““New Directions in Cryptography” that described what is now known as public key encryption (PKE). Two years later, Ron Rivest, Adi Shamir, and Len Adelman of MIT described a simpler method. When the web came along, the Diffie-Hellman and RSA algorithms became the bedrock of secure communications.

But PKE had an unknown pre-history. As early as the 1960s, John H. Ellis of GCHQ/CESG, the British equivalent of the National Security Agency’s Central Security Service, was experimenting with ideas about “non-secret encryption.” He described his work in a 1970 paper entitled “The Possibility of Non-Secret Digital Encryption,” but it remained classified until 1997. In the 1970s, CESG researchers Clifford Cocks and Malcolm Williamson found ways to implement PKE, but this work, too, stayed secret for more than two decades. A 2004 Wired story by Steven Levy gives a detailed account of the British efforts. In his account, The History of Non-Secret Encryption,” Ellis drops a fascinating hint of earlier work. Reflecting on the “obvious” impossibility of secret communications without a shared secret, he wrote...

http://techpinions.com/an-old-mystery-solved-project-c-43-and-public-key-encryption/18205

20120502

British spy in bag was poisoned or suffocated, coroner rules - CNN.com

London (CNN) -- A British spy found dead at his home in 2010 -- his naked body padlocked inside a large red carrying bag stowed in the bathtub -- was either suffocated or poisoned, but it is unlikely his death will ever be satisfactorily explained, coroner Fiona Wilcox said Wednesday.

Gareth Williams' death was "unnatural and likely to have been criminally mediated," she ruled.

He probably entered the bag alive, Wilcox said, reading her ruling to a court around the corner from the home of the world's most famous fictional detective, Sherlock Holmes....

http://edition.cnn.com/2012/05/02/world/europe/uk-spy-mystery-death/index.htm...

20120420

BBC News - Alan Turing papers on code breaking released by GCHQ

Two 70-year-old papers by Alan Turing on the theory of code breaking have been released by the government's communications headquarters, GCHQ.

It is believed Turing wrote the papers while at Bletchley Park working on breaking German Enigma codes.

A GCHQ mathematician said the fact that the contents had been restricted "shows what a tremendous importance it has in the foundations of our subject".

It comes amid celebrations to mark the centenary of Turing's birth...

http://www.bbc.com/news/technology-17771962

20111119

Why America's NSA and Britain's GCHQ Had Gareth Williams Assassinated

The National Security Agency's new Director in 1999, Air Force General Michael Hayden, had a long career in its surveillance operations but his primary qualification for office was his adherence to the Catholic Charismatic Renewal movement - one which sought direct religious experience with Christ through pentacostal and evangelical experience. It was a millinarian type of religious group, reminiscent of the crusading orders of the Middle Ages, and best exemplified in the modern world by the Knights of Malta, the great recruiting agency of many of today's New World Order people. Its capacity to find essential professionals, and fit them into key government positions goes far beyond what Yale University's Skull and Bones Society can accomplish. While Hayden was attending Pittsburgh's Duquesne University, he studied American history - getting an M.A. on the impact of the Marshall Plan upon Europe, the first step in the West's renewal after the catastrophic collapse in WWII. "Like many of his religious and conservative classmates," James Bamford wrote, "Hayden rejected the antiwar movement and the social revolution and instead would embrace the military." (1)

CIA Director George Tenet became interested in Hayden's potential to ignite NSA in an fightback against the continuing stalemate over Palestine, and growing Muslim hostility toward America. "The CIA chief liked what he heard and Hayden flew back to Korea virtually assured that he had the job as director of the NSA." (2) It recalled Henry Kissinger's hiring of lowly Major Alexander Haig as his military aide as the Nixon administration was gearing up to pull off a surprising victory in the Vietnam War despite the apparent hopelessness of the struggle, and all the campaign rhetoric about negotiating peace with the North Vietnamese and the Vietcong. Despite appearances, both military men were well versed in the operation of America's covert government, whatever was required at a given moment. It looked like new Tonkin Gulf incidents were required if any new initiative was to be established.