Slashdot Mirror


NSA Can Spy On Data From Smart Phones, Including Blackberry

An anonymous reader writes with a report from Spiegel Online that the U.S. government "has the capability of tapping user data from the iPhone, [and] devices using Android as well as BlackBerry, a system previously believed to be highly secure. The United States' National Security Agency intelligence-gathering operation is capable of accessing user data from smart phones from all leading manufacturers. ... The documents state that it is possible for the NSA to tap most sensitive data held on these smart phones, including contact lists, SMS traffic, notes and location information about where a user has been." As a bonus, the same reader points out a Washington Post report according to which "The Obama administration secretly won permission from a surveillance court in 2011 to reverse restrictions on the National Security Agency's use of intercepted phone calls and e-mails, permitting the agency to search deliberately for Americans' communications in its massive databases ... In addition, the court extended the length of time that the NSA is allowed to retain intercepted U.S. communications from five years to six years — and more under special circumstances, according to the documents, which include a recently released 2011 opinion by U.S. District Judge John D. Bates, then chief judge of the Foreign Intelligence Surveillance Court."

54 of 298 comments (clear)

  1. Let me guess, BIS by Ferzerp · · Score: 3, Informative

    BES in theory can only be intercepted and cracked with a massive amount of computation time, limiting the functional use of any dragnet attempts.

    Journalists never understand the difference between BIS and BES though.

    1. Re:Let me guess, BIS by Gr8Apes · · Score: 2

      Unless, of course, they cracked the private master key(s). If BB did something as stupidly asinine as RSA and use a single master key to auth all other keys, well, you're in a pickle as soon as the master gets out or cracked. It wouldn't surprise me if that's exactly what has happened.

      --
      The cesspool just got a check and balance.
    2. Re:Let me guess, BIS by edman007 · · Score: 5, Insightful

      Or BES just has an NSA backdoor.

  2. Secret oversight by Anonymous Coward · · Score: 5, Insightful

    Secret oversight can't be trusted, and anyone who thought it could be trusted was a moron.

    1. Re:Secret oversight by Anonymous Coward · · Score: 5, Insightful

      The Nazi hunters had to dig thru millions of paper documents. I think it would be the right thing to do to start keeping track of all the people who have thrown our country away. A centralized site where people can upload pictures of the agents and any information they may have on them.

      Whether it is federal agents 'only doing their job' or federal judges making it possible all the way down to the DHS agents at airports acting as thugs.

      We need a single place where all this information can be consolidated for the future so they can all be held accountable for the damage they contributed to.

    2. Re:Secret oversight by Jawnn · · Score: 3, Insightful

      And yet the sheeple just keep bending over and taking it.

    3. Re:Secret oversight by gmuslera · · Score: 5, Insightful

      The worst part of the no trust is that they can't even know if the data they are collecting from is being misused. Not just they are lowering on pourpose your security (weakening crypto, planting backdoors, etc), and syphoning everyone's private information, but is already proved (to the public, with Snowden) that they don't know who access their information and how is or will be using it.

      So if tomorrow your bank account shows a pretty rounded zero because the backdoors NSA planted on you was used by one of the employees of one of the companies the NSA hires (he just sold in the black market that backdoor information and someone else did it), don't be sad, the country must be defended from the terrorists.

    4. Re:Secret oversight by Anonymous Coward · · Score: 2, Insightful

      Would you lose the idiotic term "sheeple"? It's smug and condescending, and is the sort of expression used by conspiracy nutjobs to distinguish themselves from the unwashed masses who don't understand the Truth as revealed on some guy's blog. In short, it makes you sound like a complete twat.

    5. Re:Secret oversight by noh8rz10 · · Score: 3, Insightful

      I think it would be the right thing to do to start keeping track of all the people who have thrown our country away.

      You mean a list of all voters and nonvoters too?

    6. Re:Secret oversight by mcgrew · · Score: 5, Interesting

      Secret oversight can't be trusted

      Of course not, but posting anonymously won't keep them from knowing who you are.

      I just upgraded to an Android phone from my old feature phone and find it annoying when a pre-installed app wants me to turn GPS and Location Services on. Those are supposed to be for my benefit, not doubleclick and the NSA's.

    7. Re:Secret oversight by AlphaWoIf_HK · · Score: 2

      It's smug and condescending

      That's probably intentional. It's not hard to feel superior to people who support this nonsense because they believe it will keep them safe, or people who simply don't care in the least.

      --
      Da derp dee derp da teedly derpee derpee dum. Rated PG-13.
    8. Re:Secret oversight by davester666 · · Score: 2

      To be fair, Google Mail does need it to be able to properly fill in the 'from' header field.

      --
      Sleep your way to a whiter smile...date a dentist!
    9. Re:Secret oversight by fustakrakich · · Score: 2
      --
      “He’s not deformed, he’s just drunk!”
    10. Re:Secret oversight by AlphaWoIf_HK · · Score: 2

      Which is exactly why they shouldn't have such sweeping powers to begin with. Even your beloved court admitted it can't even provide oversight.

      --
      Da derp dee derp da teedly derpee derpee dum. Rated PG-13.
    11. Re:Secret oversight by centipedes.in.my.vag · · Score: 3, Insightful

      You're implying that the voting function changed any outcomes; and that is arguably not true. Further, being so aggressively victim-blaming is a pretty horrid view - and amazingly ironic given your username.

      --
      Only on /. can I lose karma with 2x "5, Funny" posts.
  3. And the saga continues.... by xystren · · Score: 5, Insightful

    Yet again, the extent of government overreaching continues. Lie about what really is really being done, and with a subtle move along, nothing to see here... "Ohh, look over there,Kim Kardashian."

    Simply amazing that what is being assured is not being done, is in reality being done.

    1. Re:And the saga continues.... by ifiwereasculptor · · Score: 5, Interesting

      What amazes me is that there have been no reprisals so far. Not by the US citizens, by US courts nor by other countries. Folks who actually live in the US, please tell me: are people really just shrugging it off or am I just not seeing the repercussions from here?

    2. Re:And the saga continues.... by cdp0 · · Score: 4, Insightful

      Please tell me what you think I should do to stop it. As an average citizen, I have no power over anything this government does. I am just a victim.

      Protest.

      Not protesting means you agree with what happens. You can't be neutral on a moving train.

    3. Re:And the saga continues.... by Anonymous Coward · · Score: 5, Insightful

      The authorities' response would be:

      A. "Smithers, release the drones!"
      B. Abundant supply of tasers and riot gear for law enforcement agents
      C. Look! Another sport event on cable!
      D. Market yet another manufactured crisis, giving politicians yet another opportunity to divide public opinion
      E. All of the above

    4. Re:And the saga continues.... by BitZtream · · Score: 4, Interesting

      Stop voting for these fucking politicians.

      It's not difficult, change the people who make the laws.

      Learn what you potential future politicians actually have done in the past and stop listening to the bullshit that spews from their mouths and campaigns.

      Vote out these life time politicians.

      Stop sitting on your lazy ass and make an actual effort instead of whining that it doesn't matter.

      Apathy changes nothing.

      The president DOES NOT MAKE LAWS, so stop giving him all your attention and vote for specific people in congress. Next time around, vote them out when the lie to you.

      --
      Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
    5. Re:And the saga continues.... by DarkOx · · Score: 4, Insightful

      Yes you do. Keep spreading the word that Government can't be trusted and that you and your fellow citizens should NOT cooperate with agents of government. They ask for info tell them to get a warrant. You see something, say NOTHING. They want to "contribute" to your project attend your conference etc, you respond get lost FED. Start excluding people who work for three letters from social events, etc.

      If all of us citizens stand up and just say no; it will make these programs way less effective. If we treat these Constitution shredding collaborators like the criminals they are and black ball them; it will be increasingly hard for government to find people to do this stuff.

      We can change this thing but voting in the horse race won't do it. Its gotta be done from the ground. Make working for the NSA something to be embarrassed about.

      As long as these methods the military/security complex are working right or wrong the power hungry will use and abuse them. We need to make them no longer work. Make the price tag of this type of signals intelligence the loss of all good human intelligence and being subject to disdainful stairs and "we don't serve your kind here" everytime a badge comes out; things would start to change.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    6. Re:And the saga continues.... by Jeremiah+Cornelius · · Score: 3, Interesting

      If voting could change anything, it would be outlawed.

      As it is, they just want the numbers to look good enough, to get away with what they want.

      That's why they keep so many in jail - and out of the polls.

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    7. Re:And the saga continues.... by gmuslera · · Score: 4, Insightful

      What about supporting the ones trying to do something about it? Raising awareness on the clueless majority of US population (and correcting the one with the wrong clues, like i.e. the ones that buys the shoot the messenger mantra) could help too, you have a voice, use it.

    8. Re:And the saga continues.... by currently_awake · · Score: 2

      The NSA spends all its time looking for ways to spy on us. That accumulated man-hours is far greater than what we are dedicating to the counter-attack. If we start spending our time looking for ways to protect our privacy (to counter their efforts) then our accumulated man-hours will be far greater, and we will push them back. This method does not require a united counter attack, only that many of us work at the problem.

    9. Re:And the saga continues.... by moteyalpha · · Score: 2

      Those who do not study history are doomed to repeat it.
      It was a good tactic in the American revolution against the British and seems to work just as well now.
      --sheeple analogy--
      Sheeple dog guards the sheeple, wolves put on sheeple suits and attack the dog, dog gets frienzied and starts attacking the sheeple, dog runs crazy until it is worn out, Wolves finish off the half dead dog and it is dinner time.
      1. Incite madness
      2. Wait for them to get tired
      3. Profit!
      If you watch a nature show about wolves hunting herbivores, even the stupidest wolf knows this.

    10. Re:And the saga continues.... by Anonymous Coward · · Score: 4, Insightful

      The only possible outcome of your strategy is to ensure that any remaining well-adjusted people working in government will leave and that there will be new laws making your countermeasures illegal. Both of those outcomes are horrible and directly opposite of what you want. Other than, obviously, voting for third parties, what you need to do is to make genuine connections with people in government and influence them to change their ways - which is the opposite of what you are advocating.

      Yelling at people generally doesn't make them see things your way. In fact, I imagine that it is precisely people with your personality in government that are making these horrible decisions - they are looking for a fight and taking whatever measures they feel is necessary to help them win that fight. Did that kind of behavior from them make you more or less likely to work with them in peace? That works the other way too.

    11. Re:And the saga continues.... by OldSport · · Score: 5, Interesting

      That's the entire problem with this NSA crap. Anyone who bucked the system and made it far along enough in the process would have tons of dirt on him/her already automatically unearthed by the NSA's data centers. The info would be leaked to a complicit media, who would drool over the chance to run another political scandal, and the good politician's career would be over before it even began.

      It's sad, but knowing about the extent of the abuse has actually made me *more* worried about protesting the abuse. Panopticon and all that -- we know they can be watching any of us now, with access to basically all our information online (even stuff that's encrypted, like this data, which is being sent over a VPN but who even knows if it's secure?), as well as all the metadata from our phones, which tell them exactly where we have gone. I doubt they are interested in me per se, but say I ran for office under a platform the established powers didn't like -- they might get interested then, and I would be fucked.

      This shit is really scary.

    12. Re:And the saga continues.... by OldSport · · Score: 2

      Do the words "self-fulfilling prophecy" mean anything to you?

    13. Re:And the saga continues.... by doubletalk · · Score: 2

      Problem is that I'm too impatient, I want things change NOW. Starting a revolution is too long, I want things change at least at 25mbps.

    14. Re:And the saga continues.... by Anonymous Coward · · Score: 2, Interesting

      And: The temperature in FtMeade is already quite high, believe me on this. They read the comment boards like we do. Actually, they do it 8 hours a day.

      So, don't be Chicken Little: Insult them as much as you can. Don't call for violence, just call them traitors. Call them Peeping Toms. Call them Pervers. In plaintext without TOR. Sure as hell they will tally up the "called NSA-traitor list" and when they see the water level rises each day, quite a few of them will simply quit or spill the beans.

      The top brass will be finally discussing with people who Sit In in FtMeade. Even Erich Mielke tried to "explain" himself one day. He said "Ich liebe Euch Doch Alle !". Before he had ordered some people to be shot, of course.

      Make those guys sweat. The nice thing is, the first sweat level can start right from your comfy chair.

    15. Re:And the saga continues.... by OldSport · · Score: 2

      I was replying to the "better to run for office" part of your post, and what I said relates directly to the "if you want to change the people who make the laws, you gotta step up and volunteer to be one of them." Relax a bit, would you?

      The fact of the matter is that at this point, virtually *anything* you do online is no longer private. If you sift through enough email, browsing history, etc. etc. etc. for any given individual you will likely find something, somewhere that could at least be used to intimidate that person.

  4. Open Source Android by Oysterville · · Score: 3, Interesting

    Are there any projects within the Android realm that can combat this? Given the open nature of the OS, it'd be nice if we could somehow adequately firewall such things.

    1. Re:Open Source Android by zidium · · Score: 4, Insightful

      The exploits and backdoors on Android devices are put in there by the manufacturers themselves, usually for monetary compensation and / or risk of harm from the agencies doing the threatening. There's no way around them.

      --
      Slashdot Valentines Beta Massacre: iT WORKED! The boycotts killed Beta!!
    2. Re:Open Source Android by pashdown · · Score: 3, Informative

      Gibbertbot offers OTR XMPP chat for Android, as does ChatSecure for iOS. The DuckDuckGo app for Androind/iOS offers untracked search over HTTPS. There are a number of PGP/GPG email readers/writers for Android and iOS.

      All of this can be precluded by the NSA having a backdoor at the graces of the manufacturer, but we still don't know the extent of that. The article states that their iPhone surveillance required them to hack into the host iTunes computer, which can be prevented with a good firewall.

    3. Re:Open Source Android by Anonymous Coward · · Score: 2, Informative

      No, because mobile phone hardware is specifically designed to make sure that user replaceable software like Android is kept inside a sandbox and only a government approved proprietary operating system can directly use the radio hardware.

  5. Well really... by santosh.k83 · · Score: 2

    Not surprising given that the smartphone hardware and software are very much propreitary in nature, and allow for easier exploitation since third party auditing is practically impossible for the entire ecosystem.

    At this point nothing except a ground-up freshly designed and built system and either written from scratch software or highly trusted ones like OpenBSD (without installing anything except base system) can be regarded as tentatively safe, and even this security is gone once such system connects to the Internet since once data is beyond the system, NSA can still intercept and crack it.

    We need clean engineered hardware, and software, and that's not going to happen anytime soon, so we have to make do with open source software and best security practices and air-gapping sensitive stuff, or not storing it in digital systems in the first place

  6. And now Act II and Act III by ehack · · Score: 4, Interesting

    And now comes Act II where intercepted data can be shown in secret to a judge to obtain convictions without the defense being able to review same.
    Then in Act III trials will be held in secret chambers with no defense.

    --
    This is not a signature.
  7. Re:Happy now? by Anonymous Coward · · Score: 2, Insightful

    Hey Obanaistas, ready to admit your guy is even worse than Bushitler?

    No, we'll just accuse you of being a racist. Hope you understand.

  8. Re:Happy now? by Narcocide · · Score: 4, Insightful

    NOPE but I'm willing to admit I'll probably never vote Democrat or Republican again.

  9. Belief In Law by b4upoo · · Score: 3, Interesting

    Obviously if phone traffic is intercepted most of the crimes mentioned in conversations would not relate to terrorism. One wonders how many criminal prosecutions could take place if all crimes detected were subject to prosecution. Murder plots, cases of fraud and tax cheating, drug sales and smuggling and prostitution would all certainly be found with ease. It would quickly become obvious that our local and national government have little interest if stopping most crime.
                    If you don't believe this or do not want to believe it think about this one simple situation. People leaving bars in the wee hours are often drunks driving home. A smart cop would not want to stop people at closing time as he would be pulling over bar staff leaving work. But almost everyone leaving a bar 3o minutes before closing is legally drunk. So simply sitting at an advantageous spot and pulling over cars leaving the bar would yield a huge amount of good arrests. Yet town discourage cops from using this tactic as it disrupts business. Think about that a bit. Wouldn't we want to catch every drunk driver every time they drive drunk?

    1. Re:Belief In Law by Anonymous Coward · · Score: 3, Interesting

      My wife and I were "ambushed" by two police cars after leaving a bar after closing. We only lived about 1000 feet from the bar, but they had to detain us for 30 minutes anyway. At the end of the ordeal they drove us home (yes 1000 feet) and told us that "the next time we get "sloshed' that we should have a way to get home. We weren't even "sloshed". Cops in the US are real bastards.

  10. White hat or black hat, they're paid hackers by Overzeetop · · Score: 2

    Yeah, the guys who jailbreak iPhones and root Android devices. How about the crackers - all those pirated programs on the internet, or DeCSS and the bluray keys that are published. The ones who hack new features into Canon cameras with third party firmware. You know these guys, right?

    Great - now go pick the ones who have trained for this and have PhDs in cryptography. Give them a $80-120,000/yr salary and benefits. Tell them they are responsible for keeping the USA safe by ferreting out every plot that gets communicated over any device in the world.

    Congratulations, you now know who works for the NSA. And yet, somehow, we're surprised that they've managed to crack (for surveillance) the same devices we crack for entertainment and features.

    --
    Is it just my observation, or are there way too many stupid people in the world?
  11. Re:Happy now? by Anonymous Coward · · Score: 2, Insightful

    In fact, I don't. How about explaining it to me?

    It's all we have left.

  12. Thank you Edward Snowden by rvw · · Score: 5, Insightful

    I cannot thank you enough for making all this information public, and for giving up your normal life to inform us. I hope that one time you will be recognized by the UN, EU and most hopefully for you the US, so you can return to your own country without being prosecuted.

    1. Re:Thank you Edward Snowden by wjcofkc · · Score: 4, Informative

      It's easy to look at this post as redundant at a glance. The truth is, we cannot say this enough. Here, have my last mod point.

      --
      Brought to you by Carl's Junior.
    2. Re:Thank you Edward Snowden by Oysterville · · Score: 5, Informative

      You're in luck! By posting to the thread after moderating it, you get your mod point back!

    3. Re:Thank you Edward Snowden by Qzukk · · Score: 4, Interesting

      Actually, he doesn't get the mod point back, it just disappears.

      Also if you mod then post AC from the same IP, it just disappears too, only without the "you're about to undo your moderations" warning.

      --
      If I have been able to see further than others, it is because I bought a pair of binoculars.
  13. Re:And now Act II and Act III by NettiWelho · · Score: 2

    What is the sentence in the Soviet Union for being convicted of insanity??

    Varies depending on who you pissed off.

    http://en.wikipedia.org/wiki/Political_abuse_of_psychiatry_in_the_Soviet_Union

  14. Things people can do by Okian+Warrior · · Score: 5, Informative

    From a previous post, here's the collected list of suggested actions people can take to help change the situation.

    Have more ideas? Please post below.

    Links worthy of attention:

    http://anticorruptionact.org/ [anticorruptionact.org]

    http://www.ted.com/talks/lawrence_lessig_we_the_people_and_the_republic_we_must_reclaim.html [ted.com]

    http://action.fairelectionsnow.org/fairelections [fairelectionsnow.org]

    http://represent.us/ [represent.us]

    http://www.protectourdemocracy.com/ [protectourdemocracy.com]

    http://www.wolf-pac.com/ [wolf-pac.com]

    https://www.unpac.org/ [unpac.org]

    http://www.thirty-thousand.org/ [thirty-thousand.org]

    Join the class action suit that Rand Paul is bringing against the NSA.

    Suggestion #1:

    (My idea): If people could band together and agree to vote out the incumbent (senator, representative, president) whenever one of these incidents crop up, there would be incentive for politicians to better serve the people in order to continue in office. This would mean giving up party loyalty and the idea of "lessor of two evils", which a lot of people won't do. Some congressional elections are quite close, so 2,000 or so petitioners might be enough to swing a future election.

    Let your house and senate rep know how you feel about this issue / patriot act and encourage those you know to do the same.

    If enough people let their representivies know how they feel obviously those officials who want to be reelected will tend to take notice. We have seen what happens when wikipedia and google go "dark", congressional switchboards melt and the 180's start to pile up.

    Fax is considered the best way to contact a congressperson,especially if it is on corporate letterhead.

    Suggestion #2:

    Tor, I2dP and the likes. Let's build a new common internet over the internet. Full strong anonymity and integrity. Transform what an
    eavesdropper would see in a huge cypherpunk clusterfuck.

    Taking back what's ours through technology and educated practices.

    Let's go back to the 90' where the internet was a place for knowledgeable and cooperative people.

    Someone Added: Let's go full scale by deploying small wireless routers across the globe creating a real mesh network as internet was designed to be!

    Suggestion #3:

    A first step might be understanding the extent towards which the government actually disagrees with the people. Are we talking about a situation where the government is enacting unpopular policies that people oppose? Or are we talking about a situation where people support the policies? Because the solutions to those two situations are very different.

    In many cases involving "national security", I think the situation is closer to the second one. "Tough on X" policies are quite popular, and politicians often pander to people by enacting them. The USA Patriot Act, for example, was hugely popular when it was passed. And in general, politicians get voted out of office more often for being not "tough" on crime and terrorism and whatever else, than for being too over-the-top in pursuing those policies.

    Suggestion #4:

    What I feel is needed is a true 3rd party, not 3rd, 4th, 5th, and 6th parties, such as Green, Tea Party, Libertarian; we need an agreeable third party that can compete against the two majors without a lot of interference from small parties. We need a consensus third party.

    Suggestion #5:

    Replace the voting system. Plurality voting will always lead [wikipedia.org] to the mess we have now. The only contribution towards politics I've made in years

  15. FISA court should be impeached by whoever57 · · Score: 4, Insightful

    The Obama administration secretly won permission from a surveillance court in 2011 to reverse restrictions on the National Security Agency's use of intercepted phone calls and e-mails, permitting the agency to search deliberately for Americans' communications in its massive databases,

    That is so obviously unconstitutional that the FISA court is clearly in violation of its oath to uphold the constitution.

    --
    The real "Libtards" are the Libertarians!
    1. Re:FISA court should be impeached by fustakrakich · · Score: 2

      It's a secret court, with a secret oath, to the government and its masters. You won't find a copy of the constitution anywhere in the room, well maybe in the bathroom, on a roll, by the toilet...

      --
      “He’s not deformed, he’s just drunk!”
  16. Re:Where'd all the "BOOOOSH!" wackos go? by Sponge+Bath · · Score: 2

    Are you that blinded by your partisanship or are you just a retard?

    The two often go hand in hand.

  17. DUH... by Lumpy · · Score: 2

    Blackberry gave up all security years ago... Nobody remembers that UAE demanded access and they rolled over nearly instantly.. They probably handed everything over to the NSA without them even asking.

    --
    Do not look at laser with remaining good eye.
  18. Re: Happy now? by Anonymous Coward · · Score: 2, Insightful

    How has voting for the major parties worked out for you would be a better question.