Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, 1 September 2024

The FBI's Exaggerated Claims of Going Dark: A Closer Look


 The FBI has often claimed that its ability to fight crime is being hampered by "going dark"—a term used to describe the challenges law enforcement faces when encrypted communications prevent them from accessing crucial evidence. According to former FBI Director James Comey on page 5 of the House Homeland Security Committee report titled: "Going Dark, Going Forward: A Primer on the Encryption Debate", “Going Dark” refers to the phenomenon in which law enforcement personnel have the “legal authority to intercept and access communications and information pursuant to court order,” but “lack the technical ability to do so.”

While encryption is an important tool for protecting privacy, the FBI's assertions of going dark have been criticized as exaggerated.

The FBI argues that encryption impedes investigations into serious criminal activities, from terrorism to child exploitation. They suggest that tech companies' refusal to create backdoors for law enforcement is creating a significant barrier to solving these crimes. This stance has fueled public debates and legislative efforts to mandate decryption capabilities.

However, critics argue that the FBI's claims are overstated. For one, there's little evidence that encryption has directly prevented major investigations. Many successful cases have been solved without requiring direct access to encrypted communications. One of such cases is the recent indictment of Seth Herrera for transportation, receiving and possession of child pornography.

According to Nate Anderson who writes for Ars Technica:

“I've never seen anyone who, when arrested, had three Samsung Galaxy phones filled with "tens of thousands of videos and images" depicting CSAM (child sexual abuse material), all of it hidden behind a secrecy-focused, password-protected app called "Calculator Photo Vault." Nor have I seen anyone arrested for CSAM having used all of the following: Potato Chat ("Use the most advanced encryption technology to ensure information security.") Enigma ("The server only stores the encrypted message, and only the users client can decrypt it.") nandbox [presumably the Messenger app] ("Free Secured Calls & Messages.") Telegram ("To this day, we have disclosed 0 bytes of user data to third parties, including governments.") TOR ("Browse Privately. Explore Freely.") Mega NZ ("We use zero-knowledge encryption.") Web-based generative AI tools/chatbots”

The indictment did not state in details exactly how Seth’s criminal activities were discovered. However, according to the indictment, Seth’s criminal conduct was finally uncovered after he tried to access a link containing apparent CSAM.  This link described CSAM  depicting  prepubescent  minor  females  around  the  same  age  as  Seth’s young daughter.

Anderson also observed that: “Presumably, this "apparent" CSAM was a government honeypot file or web-based redirect that logged the IP address and any other relevant information of anyone who clicked on it. In the end, given that fatal click, none of the "I'll hide it behind an encrypted app that looks like a calculator!" technical sophistication accomplished much.”

Despite Seth’s use of encrypted messaging applications such as Potato Chat, Enigma, nandbox, and Telegram, he was still found out by law enforcements presumably using honeypot file or web-based redirect that logged the IP address and any other relevant information of Seth Herrera when he clicked on it.

Therefore, Seth’s indictment clearly shows that in spite of the use of encryption messaging applications by criminals, there are still many other ways of unearthing their criminal activities without breaking encryption, therefore the “going dark” claim by the FBI can be said to be an exaggeration of the true state of affairs.

Also, the prosecution being cagey in the indictment, about exactly how the alleged criminal acts of Seth were discovered, reminds me of the Nigerian Police Force who, when announcing the arrest of some notorious criminals, would simply say they acted on "credible intelligence". They would rarely disclose the details of how and what was done that led to the arrest with the use of credible intelligence.

The going dark debate highlights a broader tension between national security and individual privacy. While it's crucial to support law enforcement in their efforts to combat crime, it's equally important to consider the potential risks of compromising encryption standards. Balancing these needs requires careful consideration and a nuanced approach to both technology and security policy.

Friday, 10 September 2021

THE EFCC CHAIRMAN AND CRYPTO


Abdulrasheed Bawa, chairman of the Economic and Financial Crimes Commission (EFCC),
said that cryptocurrencies have become a preference for persons engaged in illegal financial transactions.

Meanwhile, El Salvador has become the first country to adopt Bitcoin as official currency. Also, Ukraine has legalized #bitcoin and #cryptocurrencies. Does it mean that Ecuador and Ukraine are accepting or encouraging illegal transactions by adopting and legalizing crypto currency?

The battle between privacy and security is an age-old battle. Law enforcement and intelligence agencies around the world are always looking for opportunities to do away with privacy or technologies that enhance privacy. See the FBI–Apple encryption dispute. They argue that privacy enhancing technologies, such as encryption, impede or make their work of securing lives and property difficult or impossible. So does it mean that the death of privacy will make us more secure?

In the US, the FBI has severally claimed that they are "going dark", that is to say that crime busting and investigation is being hampered by the increasing use or adoption of encryption by tech consumers. In other words, the FBI and other law enforcement and intelligence agencies have been claiming for years that the increased use of encryption by consumers is making surveillance and lawful interception much more difficult and impeding investigations.

However, recent events have shown that the claim of going dark is over exaggerated. On May 22, 2018, the Washington Post reported that the FBI repeatedly cited inflated statistics about the number of cellphones whose data it could not access because of encryption.

Also in June, 2021, it was reported that for three years, the Federal Bureau of Investigation and the Australian Federal Police owned and operated a commercial encrypted phone app, called AN0M, that was used by organized crime around the world. In other words, instead of the FBI trying to break encryption or hack into devices, they created an encrypted phone app and put it out there and some criminals felt the phone app was secure and their communications were end to end encrypted, whereas, law enforcement agents had access to all their communications which were supposed to be encrypted and unreadable or inaccessible to third parties. With this, can you say the law enforcement and intelligence agencies are really going dark? See: The FBI's Anom Stunt Rattles the Encryption Debate.

In view of the above, the Chairman's claim might just be another ploy by a law enforcement agency to try chirp away at privacy and anonymity as law enforcements are wont to do, while hiding under the guise of fighting crime.

Further reading:

(1) Going Dark, Going Forward: A Primer On The Encryption Debate 

(2) US: FBI’s Encryption Statistics Inflated

(3) Rethinking Encryption

(4) Harvard Study Questions ‘Going Dark’ Cryptoproblem-

Friday, 30 September 2016

HISTORICAL CELL SITE LOCATION INFORMATION AND TELCOS IN NIGERIA


According to Wikipedia.com, a telco i.e. telephone company, telephone service provider or telecommunications operator:
is a kind of communications service provider (CSP) (more precisely a telecommunications service provider or TSP) that provides telecommunications services such as telephony and data communications access…With the advent of mobile telephony, telephone companies now include wireless carriers, or mobile network operators. Most telephone companies now also function as internet service providers (ISPs), and the distinction between a telephone company and an ISP may disappear completely over time, as the current trend for supplier convergence in the industry continues.

Historical cell site location information or mobile/cell phone location data is a collection of past connections between a mobile phone and cell towers or telecommunications masts. A cell site is mobile phone base station or antenna where radio signals are sent and received. In  the United States case of State v. Earls, it was stated that “Cell or (mobile) phones register or identify themselves with nearby cell towers every seven seconds. Cell providers (like MTN, Glo, Etisalat and Airtel in Nigeria) collect data from those contacts, which allow carriers to locate cell phones on a real-time basis and to reconstruct a phone’s movement from recorded data.”

Most times when you call the call centre of your GSM network provider or telco in Nigeria such MTN, Glo, Etisalat or Airtel, to make a complaint or inquiry, the customer care representative will ask you what town or city and local government you are calling from. I am usually taken aback by this question because they (telcos) already know or at least can approximate my location so why bother to ask me.

Whenever a mobile telephone makes a call, the call is routed through a cell site located at a fixed geographic location. Mobile telephone companies keep records of which cell site processes a call, and through this information law enforcement agents can locate the position of the SIM card, and therefore infer the location of the telephone user. This was used by the Nigerian Police to obtain the location of Timothy Dung, an armed robbery suspect in the case of The State v. Timothy Dung. On page three of the judgement it was stated thus:
According to the PW2 on the 20/8/2010 a case of armed robbery was transferred from the ‘E’ Division Police Station to the State Criminal Investigation Department (CID). PW1 volunteered a statement before the police.
According to the PW2 they swung into action by applying their detective mechanism to arrest the person because the line snatched was still going. Police applied to court to obtain a court order to serve Airtel/Zain who was the service provider of the line (Zain) snatched from the PW1. Airtel/Zain complied with the court order and released the coordinate to the Police. The coordinate enabled the Police to set a security trapping system that showed them the exact direction and position where the accused (that) was using that particular line at that time was standing. The system gave the latitude and longitude on google earth. lt shows(sic) that the accused person who was with the stolen line was at Abuja and the call history of the line after the robbery was within Abuja town and a town in Plateau State.  However, about three' days back, the line was showing that it, was in Abuja. The Police went to Abuja and the system directed them to Federal Fire Service in Abuja town and they went there. When the PW2 and his team called the number/line, it rang and the accused received the call. The PW2 then arrested the accused and interviewed him.
The case of United States v. Allums, also shows that telcos know or can estimate the location of their subscribers or customers at any given time using historical cell site location information (CSLI) or cell site analysis. James Edward Allums on 30th November, 2007, robbed a bank in Salt Lake City, Utah, United States. A bank employee dropped a chair from the second floor balcony onto Allums’ head as he stood brandishing a knife at a teller on the first floor.  In anger Allums removed his ski mask to look up and curse at the chair-dropper and in the process glowered directly into the surveillance camera. Allums had a mobile phone on him on 30th November.

Prosecutors introduced evidence that cell site tracking records showed that Allums’ phone, and presumably Allums, was located in close proximity to the bank and to two other locations also robbed by Allums. Thus, Allums was convicted on three counts of armed robbery.

Apart from historical CSLI mobile phone location can also be determined through GPS and mobile phone triangulation. At this juncture it is appropriate to state how mobile phone communications work as captured or explained in Re: Application for Telephone Information Needed for a Criminal Investigation:
Cell (mobile) phones operate through the use of radio waves.  To facilitate cell phone use, cellular service providers maintain a network of radio base stations—also known as cell towers (popularly referred to in Nigeria as mast)—throughout their coverage areas.
Whenever a cell phone makes or receives a call, sends or receives a text message, or otherwise sends or receives data, the phone connects via radio waves to an antenna on the closest cell tower, generating cell site location information (CSLI).  The resulting CSLI includes the precise location of the cell tower and cell site serving the subject cell phone during each voice call, text message, or data connection.  If a cell phone moves away from the cell tower with which it started a call and closer to another cell tower, the phone connects seamlessly to that next tower.
CSLI may be generated in the absence of user interaction with the cell phone. For example, CSLI may still be generated during an incoming phone call that is not answered.  Additionally, most modern smartphones have applications that continually run in the background, sending and receiving data without a user having to interact with the cell phone.
Indeed, cell phones, when turned on and not in airplane mode, are always scanning their network’s cellular environment. In so doing, cell phones periodically identify themselves to the closest cell tower—i.e., the one with the strongest radio signal—as they move throughout their network’s coverage area.  This process, known as “registration” or “pinging,” facilitates the making and receiving of calls, the sending and receiving of text messages, and the sending and receiving of cell phone data. Pinging is automatic and occurs whenever the phone is on, without the user’s input or control. A cell phone that is switched on will ping the nearest tower every seven to nine minutes. (Emphasis mine)
From the above it is crystal clear that CSLI can be used to estimate the location of an individual by identifying the nearest cell tower or mast and sector used when a call is made. It therefore presents circumstantial evidence of a person’s location.  This ability to locate a cell phone presents obvious benefits to law enforcement and intelligence authorities  as seen in the two cases referred to above. CSLI also poses a significant threat to privacy. Thus in State v. Earls (supra) the court observed that:
Advances in technology offer great benefits to society in many areas. At the same time, they can pose significant risks to individual privacy rights. This case highlights both principles as we consider recent strides in cell-phone technology. New improvements not only expand our ability to communicate with one another and access the Internet, but the cell phones we carry can also serve as powerful tracking devices able to pinpoint our movements with remarkable precision and accuracy.

Tuesday, 28 June 2016

WILL THE DEATH OF PRIVACY GUARANTEE BETTER SECURITY OF LIVES AND PROPERTY FOR ALL OF US?


With every terrorist attack in the West legislators and law enforcement authorities call for laws (or amendment of extant laws) for increased surveillance of citizens. This they argue will enhance the capabilities of law enforcement authorities to prevent and where they occur, investigate terrorist attacks.

It has been reported here that: 
The federal government is taking another step it says would make the US homeland safer from terrorism. US border authorities are proposing that millions of tourists entering the country each year reveal their social media identities.
The proposal from US Customs and Border Protection, announced last week in the Federal Register, would add a line to the online or paper form that US-bound visitors must fill out if they don't have a visa and plan on staying for up to 90 days for vacation, business, or other affairs. The agency says travelers coming to the US under the Visa Waiver Program won't be forced to disclose their social media handles, but leaving it blank obviously could raise red flags.
Here's what will be asked: "Please enter information associated with your online presence—Provider/Platform—Social media identifier." 
It has also been reported that "Federal agents (in the US) are planting microphones to secretly record conversations."

Arstechnica also reported that:
Russia's lower house of parliament, the State Duma, has approved a series of new online surveillance measures as part of a wide-ranging anti-terrorism lawAs well as being able to demand access to encrypted services, the authorities will require Russia's telecom companies to store not just metadata, but the actual content of messages too, for a period of six months. Metadata alone must then be held for a total of three years, according to a summary of the new law on the Meduza site. Authorities will be able to access the stored content and metadata information on demand…the legislation still needs to be approved by Russia's upper house, the Federation Council, and signed by President Putin.”
Slowly and gradually our right to privacy is being be eroded. Nigerians may think this is only happening in the US but it is happening at home here in Nigeria too, for e.g. compelling mobile phone users to register their GSM lines and submit biometric data etc. before activation of the lines for use.


See also the Facebook post by one James S. Gbudu claiming to monitor the internet with the hope of riding it of fake social media accounts being used to abuse Nigerians!

It may not be out of place to conclude that the future for privacy looks bleak! I therefore foresee a situation whereby little by little the right to privacy(online and possibly offline) will be gradually eroded until there is no more right to privacy most especially in the name of fighting terrorism and other crimes. This erosion of privacy will be further aided by the coming Internet of Things (IoT).

The question then is; will the DEATH of privacy guarantee better security of lives and property for all of us?


Saturday, 19 March 2016

The Dangers of the Internet of Things (IoT)



Are you ready for a future where not just your smartphone,  desktop, laptop computer or tablet is connected to the Internet but also your cars, electronic appliances(home theatre, TV etc.), lights in household and commercial environments, alarm clocks, speaker systems, washing machines, microwaves, sandwich makers/toasters, blenders etc. are connected to the Internet? 

In the near future, you may no longer need to remember to turn the oven off when the cake is done or switch on lights when you enter a room. Your home will do it for you. These products are part of the Internet of Things (IoT), aimed at automating our lives by connecting mobile devices to appliances, lights, and just about everything.

The Internet of Things (IoT) refers to the ever-growing network of physical objects that feature an IP address for internet connectivity, and the communication that occurs between these objects and other Internet-enabled devices and systems. IoT extends internet connectivity beyond traditional devices like desktop and laptop computers, smartphones and tablets to a diverse range of devices and everyday things that utilize embedded technology to communicate and interact with the external environment, all via the Internet.

Simply put, IoT is a computing concept that describes a future where every day physical objects will be connected to the Internet and be able to identify themselves to other devices. Most of us think about being connected in terms of computers, tablets and smartphones. IoT describes a world where just about anything can be connected and communicate in an intelligent fashion. In other words, with the IoT, the physical world will become one big information system.

It describes a situation where everything in our surrounding environment is made capable of automatically communicating with each other without any inter-human or human-to-machine interaction. Apart from the fact that it is a path-breaking discovery, it can also prove to be extremely beneficial in facilitating our lives to manifolds.

Despite the enormous benefits, IoT might raise some privacy and security concerns. The risks inherent in our Internet-connected lives and IoT are brought into sharp focus by the movie: Ratter. Ratter is an acronym for a type of malware known as a Remote Access Trojan, an unwittingly downloaded program that provides a hacker with undetected access to a user’s Internet-enabled devices. The ratter can then manipulate programs and files, as well as operate camera and microphone functions, enabling video and audio access to the victim’s activities.

In the movie; Ratter, Emma is determined to make a fresh start as she moves from the Midwest of America to rent a spacious apartment in Brooklyn, New York and begin grad school, Emma never suspects that everything she does within view of her laptop, phone or webcam is being watched and recorded by an unknown stalker who has electronically hijacked her devices. Whether she’s prepping meals in her kitchen, settling into bed at night or showering with her laptop playing music in the background, Emma’s always-online lifestyle is fully revealed to the ratter.

At the same time, she begins receiving random blocked calls and text messages, which her friend Nicole dismisses as typical misdialed numbers and tech glitches. When her laptop starts acting up, Emma takes it to a repair shop but apparently there’s nothing amiss, although she does change her passwords as a precaution. An unexpected call from a blocked number turns out to be her jilted, bitter ex-boyfriend Alex, leading Emma to wonder if he’s the one who’s been anonymously harassing her.

She dismisses the thought however, since things are going so well with Michael, the new guy she’s been dating, until an online chat session becomes way too creepy and Emma breaks things off, concerned that even he might be targeting her. It’s all part of the ratter’s escalating plan to isolate her from friends and family, even as he becomes more aggressive, breaking into her apartment and observing her while she sleeps. As his threatening behavior escalates and Emma’s stress level spikes, her parents urge her to move to a new apartment, but with the ratter monitoring her every move, message and phone call, a change of location isn’t likely to provide much respite or increased security.

In a selfie-obsessed culture motivated by the urge to document everything and perhaps even achieve fleeting viral celebrity, the unpleasant possibilities articulated by the movie, Ratter, are alarmingly immediate and unnervingly reinforced by news accounts of hijacked webcams and hacked cellphones betraying unsuspecting users.



Monday, 6 January 2014

Nigeria and Data Protection

“We live in an age of “big data.” Data has become the raw material of production, a new source of immense economic and social value. Advances in data mining  and  analytics  and  the  massive  increase  in  computing  power  and  data storage capacity have expanded, by orders of magnitude, the scope of information available to businesses, government, and individuals. In addition, the increasing  number  of  people,  devices,  and  sensors  that  are  now  connected  by digital networks has revolutionized the ability to generate, communicate, share, and access data. Data create enormous value for the global economy, driving innovation, productivity, efficiency, and growth.  At the same time, the “data deluge” presents privacy concerns that could stir a regulatory backlash, dampening the data economy and stifling innovation."

It is therefore clear from the above that data, especially personal data(any data or information in connection with a specific individual, which can be used, separately or in combination with other data, to identify an individual) has acquired an immense value in the age we are living(the digital age) and serious steps ought to be taken to protect the personal data of citizens but Nigeria seems to be lagging behind as the best we have at the moment is the guidelines on personal data issued by National Information Technology Development Agency(NITDA) which is good gut not enough(what we need is a law) and there is also a draft bill on Personal Information and Data Protection which is pending before the federal lawmakers.

This does not augur well for the citizens whose personal data is scattered all over the place (banks, the Federal Road Safety Commission (FRSC), the National Identity Management Commission (NIMC), the Nigeria Communications Commission (NCC), GSM service providers and online retailers like Jumia and Konga who are currently making waves in the Nigeria internet sphere as online shopping is becoming increasingly popular among Nigerians).

In China they have taken serious steps to guard and protect the personal data of their citizens with the passage of such laws as the Peoples’ Republic of China Law on the Protection of Consumer Rights and Interests and persons who flout the law are been arrested and prosecuted. For instance the Police in China, apprehended a 10-member gang in Beijing and Shanghai for illegally obtaining and selling nearly one million...You can find the rest of the story here

Monday, 18 November 2013

Barr. Timothy Tion discusses the NCC directive to cybercafe owners and cybercrime Part 1


Recently I was on “ICT WORLD”, a radio Benue program to discuss the Nigeria Communication Commission (NCC) directive to cybercafé operators which came into effect on the 1st of November, 2013 directing all cybercafé licencees and operators in the country to maintain an up to date data base of its subscribers/users detailing information such as; full names, names of corporate body (in the case of a corporate establishment), traceable physical address, full faced passport photograph, telephone numbers, permanent residential address(not P. O. Box), evidence of registration with Corporate Affairs Commission(CAC)(applicable to corporate bodies only) and other forms of identification including international passport, driver’s licence, national identity card, etc.
According to the NCC, this database is to aid law enforcement authorities in fighting the increasing rate of cybercrime committed through cybercafés across the country.
Here is the link to download the discussion. To download; click the "download" icon in green. Listen and let me get your feedback. Thank you.

UPDATE 22 DECEMBER 2020
The above link to the discussion is dead. Here is a new link to the discussion which is divided into parts 1 and 2. Listen to part 1 here and part 2 here