'Babar' Malware Attributed To France
sarahnaomi writes: The NSA, GCHQ, and their allies in the Five Eyes are not the only government agencies using malware for surveillance. French intelligence is almost certainly hacking its targets too — and now security researchers believe they have proof. On Wednesday, the researchers will reveal new details about a powerful piece of malware known as "Babar," which is capable of eavesdropping on online conversations held via Skype, MSN and Yahoo messenger, as well as logging keystrokes and monitoring which websites an infected user has visited. The researchers are publishing two separate but complementary reports that analyze samples of the malware, and all but confirm that France's spying agency the General Directorate for External Security (DGSE) was responsible for its creation.
This proves that all the whining about the NSA has little to do with actual worries (as if anyone in the government actually cares about their porn viewing habits), and more to do with overwrought anti-Americanism.
No, it doesn't.
We are more concerned about the NSA doing it because it has a bigger budget and because, for a lot of slashdotters, it's our government that's doing it. It's still a subject for humor, but nevertheless a real social policy concern. I've met a lot of great guys who work in law enforcement whom I would generally trust not to abuse the powers created by massive surveillance, but the problem arises when too much trust is given and there isn't enough oversight of how it is used. As it is, the public is not given any believable claim to even the existence of meaningful oversight.
That means bad actors within the system can use it to spy on people they know, on their own ex-wives, for example. And while they might get severely disciplined if they're caught, the public hasn't been told how likely it is that they're caught.
It also means the system can be used to blackmail VIPs, power-brokers, reporters, and legislators. While most of the people involved would not use it for that, it only takes one or two people to be willing to do that and a lack of *perfect* oversight and reporting for a system like this to utterly threaten and destroy any notion of representative government.
Imagine you have a database of every Congressman's phone calls, or even every third or fourth phone call that happens to be to someone within a three-hop warrant of a terrorist.