|
Written by BYte69
|
|
Monday, 01 May 2006 |
This article is to lay out what I don't think many people in the EU or US know. I am going to point out information, news reports, and laws that are active or pending. I will also touch on large ISP and Internet companies that are enabling the erosion of our rights. I will split it into sections with supporting links for each for those of you interested. I hope also that after you see what is going on that it will make all of us more active in trying to defend our rights. It is everyones responsiblity to keep track of what there goverment is doing. We the people must ensure that we the right to privacy. Without privacy all the other rights will go with it slowly. To me privacy is the corner stone.
***ISP/Telecoms and NSA monitoring***
So who to pick on first???? Well I feel we should start at the local point and work out so. Here we go. Do you realize that major ISP's (Internet service providers) and backbone network companies (ATT, MCI, Sprint, Level 3 and others) are supplying the NSA and other organizations with data. So as your browsing the Internet or chatting that data can be filtered and captured. You may say I don't do anything to worry about. That may be true but the fact your reading this and its posted on a security/hacking community site could be grounds. I admit I am reaching a bit but I will point out some proposed laws that will surprise you. Now how are the spy agencies doing this. Well something you need to realize is that all Internet traffic at some point probably goes through the US. You say not possible. I say DNS. So how are they tracking and gathering data? Well conveniently NSA and the ISP's/telco backbone providers co locate. What is co locate? That means that the NSA and ISP/Telco companies have buildings near or at the same location as each other. Here is a map of Internet exchange points. Follow some of the links in the paper below.
http://uk.geocities.com/osin1776/
Now if you looked you would see the major backbone providers I pointed out before. I am going to highlight AT&T because that is the most data available about how they help the NSA. What they do is provide a secured room for NSA to put there equipment. That equipment has some very good capability that I will also point out to you. But first here is some information from an AT&T tech about the NSA setup:
http://www.wired.com/news/technology/0,70619-0.html?tw=wn_index_1
Here is map of what NSA has done.
http://www.nsawatch.org/nsa_octopus.jpg
Now mind you the above info is just for ATT. Other telcos/ISP's are involved. Now the equipment they are using is top of the line. For dedicated data taps they use things like this Finsar tap:
http://www.finisar.com/nt/taps2.php
Which you have NO way to know anything about. It pulls data in real time.
Then there is the shotgun approach using this software.
http://www.narus.com/products/index.html
This is used in conjunction with CDR and other data all telcos keep. Your bill comes from the CDR data. NSA has access to the network via the software and other equipment taps I have pointed out. So all this in collected and in theory if you do not fit the 48 criteria set out by the NSA for a terrorist your data is clear. Well at least for now.
Next step is this. There is now in the EU and US laws or pending law to keep records of all the locations you go when you use the Internet. That is that the ISP/telco keeps logs for a period of time of source and destination IP addresses etc. This is pending in the US and EU. So they can track everything you look at. What also may make you think twice is there is yet another law coming up in the US call DCMA II. I will tackle that one all by itself later.
So here are the laws I am talking about for the EU and pending one in the US.
http://www.computerworld.com/managementtopics/outsourcing/isptelecom/story/0,10801,106537,00.html (EU)
Pending in the US but patterned after the EU law. Here is the pending US version.
http://www.cdt.org/security/nsa/20060315dewine.pdf (Called the Terrorist Surveillance Act of 2006)
Now as an added bit of information for you here is more information about narus the company and what the software can do. Now keep in mind that this is a private company. So they can kind of call there own shots. I would also like you to look at how much data it can process in REAL TIME. " OC-192 carries about 10 gigabits of data per second. Ten billion bits per second, monitored in real-time. That is stunning." Keep in mind its dealing with the standard OSI model of network traffic. Which means this is a high powered and amazing system. Here is another go quote from the article below. " NarusInsight focuses on two layers: number four, the transport layer, built on standards like TCP and UDP, the physical building blocks of internet data traffic, and number seven, the application layer, built on standards like HTTP and FTP, which are dependent on the application using them, i.e. Internet Explorer, Kazaa, Skype, etc. It monitors 10 billion bits per second at level four and 2500 million bits per second at level seven. For reference, the 256K DSL line I am using equals .25 million bits per second. So one NarusInsight machine can look at about 39,000 DSL lines at once in great detail."
http://www.dailykos.com/storyonly/2006/4/8/14724/28476
Now if your not worried about your civil liberties okay. But some of us are and so is the EFF and ACLU. You can find a a history and running update on what is happening in the NSA/ATT federal court case and keep up to date at the following sites:
http://www.eff.org/legal/cases/att/
http://www.aclu.org/safefree/nsaspying/index.html
Recently the Government has set up a very effective roadblock to this law suit by filing a "State Secrets" filing. Apparently the "DOJ Will Assert Military and State Secrets Privilege and Request Dismissal of Lawsuit" which means that the suit will stop with NO further action. This is yet another example of what the US government is willing to do to kill dissent. Here is a story and the filing by the government.
http://www.eff.org/news/archives/2006_04.php
http://blog.wired.com/27BStroke6/
***Major Internet companies cooperating with governments.******
Okay to the next stop on the walk. Large Internet companies like google and yahoo turn over data. This is something else that flys in the face of privacy. The US has sued google to obtain a block of data for a period of time of search data. Now google is fighting it here. But who did provide data to the Department of Justice?? I give you a few guesses. MSN, Yahoo, AOL, and others. Now google is fighting it but we will see where that goes later. Now I understand China is a large country and has many Internet users. They are all watched. But why would an American company turn over data to the government??? Yahoo turned over data that has place at least one person in prison. They turned over email etc. So how is that being a good company?? Here is the story about Yahoo.
http://news.com.com/2100-1028_3-6060667.html
Now are all American companies doing this? Yes. Why? Money plain and simple. Now I am going to take google to task a bit. The company claims its motto is "do not evil". Well if that is true how and why are you in China?? Do we forget the bloody Tiananmen Square, 1989 ? Google claims it want open access to all the world information. Well doing business in China does not help it. Here is googles reasoning:
http://googleblog.blogspot.com/2006/01/google-in-china.html
Now who enables all this filtering??? American and EU technology companies. Cisco, Microsoft, Bull, Siemens etc. They also help the Chinese government use the technology. All for the mighty dollar.
Okay so enough about the Internet companies.
***Government surveillance.****
Now this surveillance is suppose to be secret. But for some reason whistle blowers keep coming out and telling how (insert favorite three letter government agency here) they are over stepping the constitution etc. Well maybe that should be a wake up call the the people effected. Well at least here in the US there was a quick bit of reaction but when the networks moved away from the story so did the peoples mines. I also am amazed at Americans that are willing to forgive or not care that your rights are slowly being taken. Here is a few words to live by:
"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." - Benjamin Franklin.
I have been picking on the NSA admittedly. Because they are the latest one in the news but this problem is systemic of our government. The FBI had carnivore, NSA has this latest, and the CIA has the rendition flights to torture friendly locations. So far almost no body has really done anything about it. Our elected officials seem to want to sweep this under the rug. Here is a story about the NSA whistle blower that was relieved of duty due to "mental issues" . What that he has a brain that knows right from wrong.
http://www.wired.com/news/technology/0,70619-0.html?tw=wn_index_1
Now those of you in the EU don't think that the same things do not happen there. There is a higher amount of surveillance in the EU of its people then in the US. Can you say cameras. They also are the one that helped the US get the idea of data retention laws for your Internet/call data. Now we know its an open secret that GCHQ in Britain is part of the Echelon network. Yes it does exist and its being upgraded. Here is a bit more info on Echelon:
http://news.bbc.co.uk/1/hi/world/europe/1357264.stm
Here is the EU report on Echelon:
http://www2.europarl.eu.int/omk/OM-Europarl?PROG=REPORT&L=EN&PUBREF=-//EP//TEXT+REPORT+A5-2001-0264+0+NOT+SGML+V0//EN&LEVEL=2
Here is a new report of DHS and CDC sharing data. Including EU passenger data.
http://www.aclu.org/privacy/spying/25335prs20060425.html
***Ways to protect yourself and fight the laws.***
The best way to protect yourself is to pay attention to what your government at all levels is doing. I would concentrate your attention at the state and federal levels or the equivalent in your area. They can and do effect you. So support organizations like EFF (Electronic Frontier Foundation), ACLU (American Civil Liberties Union), and others. Those are just the better known. Amnesty also does a lot of work on this. If everyone thinks someone else is going to protect your rights your wrong. Citizens of the world must pay attention to what there government does. If not they will take more power and your rights will evaporate over time.
Now I am going to touch on ways to keep them from easily gathering your network information. The best way currently I believe is using a live CD. What a live CD does is this. You put the CD in a system you want to connect to the Internet on. You boot off the CD and it will boot an OS (usually Linux or BSD). Then you use it to surf the Internet etc. Now there are layers of protection provided by using the live CD. One is that it will not leave trace info on the hard disk. Your not using it nor touching it so when you shutdown the system all traces of where you went are gone. Now most live CD do not have proxies setup. But you can change that by loading diff rent modules etc. Now mind you not all proxies are good. Some leak a lot of information. So what do you do when you want a very good way to protect your self. You download and use this live CD. Its called Anonym.OS and its one of the better ones. Some of the features it has is MAC address spoofing at bootup. Random password creation and TOR proxies right away. So you don't have to think about finding good proxies. Now I will tell you that it will be slower do to the proxies. But it will protect your identity fairly well. The link to that CD is here:
http://sourceforge.net/projects/anonym-os/
You can also use TOR proxies on your own system. TOR is a volunteer network of computers to protect your privacy. There currently is about 400 TOR proxies. If you like it you can also configure your system and donate bandwidth and be a proxy in the chain. It is help full. Also do not use TOR proxies to download a lot of crap. Its a shared resource. Here is the web page to the project:
http://tor.eff.org/
Note who is hosting it. EFF.
So now you have some tools to fight for your rights and protect your identity.
***Conclusion.***
I have tried to point out some of the things spotted over the last year or so. But this is by no means a complete list of spying on people. The EU and US are based on individual freedoms yet they monitor everything we do to build us data on us. If you don't agree with the current powers then you could be monitored even more. Also note that there are laws being proposed in the US like DCMA II that will make sharing info a crime. So if I or someone passed info via NewOrder on how to uninstall the Sony rootkit which is considered DRM technology it would be a crime punishable by longer jail sentences, etc. Then in conjunction with a proposed new law to protect the MPAA and RIAA and give them more tools including wire taps etc to find file traders. It will only get worse if people don't wake up. So in short WAKE UP or you will be a lemming and lead off the cliff and have no freedom.
Add as favourites (97)
|
- Please keep the topic of messages relevant to the subject of the article.
- Personal verbal attacks will be deleted.
- Please don't use comments to plug your web site. Such material will be removed.
- Just ensure to *Refresh* your browser for a new security code to be displayed prior to clicking on the 'Send' button.
- Keep in mind that the above process only applies if you simply entered the wrong security code.
| |