Showing posts with label Canada. Show all posts
Showing posts with label Canada. Show all posts

Canada's WiFi Surveillance and CSEC's Non-Denial Denials

Saturday, 1 February 2014

On Thursday, a report I worked on with Glenn Greenwald and Greg Weston was published in Canada, revealing how the country's spy agency CSEC secretly developed a program to monitor WiFi users in a major Canadian airport.

The piece, based on documents leaked by the former US National Security Agency contractor Edward Snowden, has led to CSEC being accused of acting unlawfully and has triggered calls for better oversight of the agency.

But one of the most intriguing aspects of the fallout from the story has been the Canadian government's response — which merits some scrutiny and analysis.

First, some context.

Back in November, Greenwald, Weston and I reported separate revelations about Canada's role in an NSA operation to spy at the G8 and G20 summits in Canada in 2010. In response, CSEC's chief John Forster claimed in response to reporters' questions:

What I can tell you is that CSEC, under its legislation, cannot target Canadians anywhere in the world or anyone in Canada, including visitors to Canada.

During a speech in October, Forster had made a similar statement:

I can tell you that we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada. In fact, it's prohibited by law. Protecting the privacy of Canadians is our most important principle.

And again, in January, he repeated this assertion in a letter to a Canadian newspaper:

Under the law, CSE’s foreign intelligence mandate specifically dictates that our activities be directed only at foreign entities, and not at Canadians or anyone in Canada. That is the law and we fully respect that.

Having analysed Canadian documents in the Snowden material, these statements struck me as quite astonishing.

Why? Because one of the top-secret Snowden documents revealed that, in 2012, CSEC had set up a program that involved monitoring WiFi usage at a large Canadian airport. The secret files showed how CSEC was able to use a huge amount of data about the WiFi connections to follow users "backward and forward in recent time" — identifying visits to hotels, other airports, Internet cafes, coffee shops, and a library.

The tactic is described by CSEC in the files as "IP profiling" — a surveillance method that can be used to track users' movements over time. In one case, as we reported at CBC on Thursday, the spy agency says that it performed a sweep of an entire "modest-sized" city and identified 300,000 user IDs:

The "mission impact" of the tactic, according to the document, is that it can alert spies to "target country location changes" and "webmail logins with time-limited cookies":

The full document [pdf] speaks for itself. It illustrates a secret surveillance operation was conducted on Canadian soil — sweeping up metadata on the WiFi usage of thousands of people not suspected of any crime. Equally significant, the revelation contradicts CSEC chief Forster's repeated assertion that "we do not target Canadians at home or abroad in our foreign intelligence activities, nor do we target anyone in Canada."

After we reported the airports story, it got more interesting.

CSEC issued a statement that was notable for three reasons. First, the agency did not repeat its previous mantra claiming not to "target anyone in Canada." Second, it appeared to make an admission that it is sweeping up metadata within Canada, saying that it was "legally authorized" to "collect and analyze" this information. And third, it issued a fresh denial, saying that "no Canadian or foreign travellers were tracked. No Canadian communications were, or are, targeted, collected or used."

Shortly afterwards, on Friday, a similar denial was made by the Canadian prime minister's parliamentary secretary, who launched a bizarre personal attack on Greenwald while claiming that the "facts" were that "nothing in the stolen documents showed that Canadians' communications were targeted, collected, or used, nor that travellers' movements were tracked."

But these denials are hollow.

It's a straw man to claim that the revelations were about communications being "targeted, collected, or used." That is not what our story was about. The issue at hand is how CSEC initiated a program to sweep up information showing when people are connecting to WiFi networks and using this information to build "profiles" of their movements back and forward in time.

And that brings us to the more important point. CSEC and the prime minister's secretary claimed that "no Canadian or foreign travellers were tracked." However, what they did not say was how they were defining the word "tracked."

The documents quite clearly show how the agency used user "IP profiles" to monitor WiFi users' movements over time, with this capability enabling it to generate "alerts" when a person relocates to another country.

The dictionary definition of "tracking" says that it means "the act or process of following something or someone." CSEC's IP profiling is exactly that — monitoring users' location and keeping tabs on where they are. Indeed, the document says as much, outlining how CSEC uses this tactic to "follow IDs backward and forward in recent time." The documents also mention how CSEC used tools called "Quova" and "Atlas database" — which are technologies used to pinpoint the geolocation of an IP address.

CSEC's denial that it "tracked" Canadians or foreign travellers, I think, hinges upon a narrowly defined interpretation of the word. The US Department of Defence, for instance, uses "tracking" as a specific technical term meaning the "precise and continuous position-finding of targets by radar, optical, or other means." CSEC's IP profiling definitely fits the dictionary definition of "tracking" as it is understood by most people — but does it fit the narrower military definition? Perhaps CSEC believes that IP profiling does not constitute "precise and continuous" tracking. But if so, it should be explaining this — as otherwise its denial is highly misleading.

Spy agencies are professionals in the art of deception, and sometimes that seems to be reflected in their public relations strategy. Afterall, we have seen misleading denials issued repeatedly by the National Security Agency and its Five Eyes counterparts about various surveillance revelations in recent months. Again and again, officials have used narrowly defined words or jargon terms in a carefully crafted way in order to issue non-denial denials in which they appear to refute an allegation but on closer reading do not really refute it at all.

The ultimate point here is that the tactics being used by CSEC and the Canadian government to deflect criticism of their secret surveillance programs merit as much attention as the revelations themselves. That is especially clear when, in response to disclosures about their secret programs, senior government officials launch childish character assassination attempts against the journalists who reported the information. In a democratic society, surely a higher standard is required. It is not enough for governments and spy agencies to spit out a few indignant statements and denials with the expectation that people should just blindly trust that they are telling the truth.

Also, no matter how "tracking" is being defined, what is clear is that CSEC was (and our sources say still is) running a large-scale surveillance operation on domestic soil, seriously calling into question spy chief Forster's previous statements that "our activities" are not directed "at Canadians or anyone in Canada." The CSEC boss is due to appear before a Senate committee hearing on Monday. Hopefully Canada's lawmakers will take the opportunity to ask some probing questions.


UPDATE, 7 February 2014: Since the story was published last week, there have been several developments. There have been more calls for an independent review of CSEC's activities, while spy chief Forster was forced to publicly defend the surveillance in Monday's Senate hearing.

There have also been some interesting analyses of the leaked documents worth responding to.

First, the surveillance blog Electrospaces claimed that the secret documents seemed to have been "incorrectly interpreted" in our CBC report. The blog published an anonymous analysis from someone who says that CSEC's surveillance project was "was not surveillance of Canadian citizens per se but just a small research project." The second analysis came from Bruce Schneier, who claimed that it was "not really true" that CSEC used "airport Wi-Fi information to track travellers."

First of all, it is a mischaracterization to claim that the CSEC project was just a small research project that didn't implicate Canadians "per se." It was part of a pilot initiative that involved sweeping up data on hundreds of thousands of people — many of whom would have been Canadian citizens. Our sources for the story told us that the pliot had since gone live — i.e. that it had gone from being a "proof-of-concept" to an operationally active domestic program. This is about much more than a "small research project."

Second, it is absolutely the case that CSEC tracked travellers' movements based on the Internet activity by using IP and ID data and honing in on a major Canadian airport's WiFi system.

It may be about more than that — and I agree with Schneier when he says that it is "actually far more interesting than simply eavesdropping on airport Wi-Fi sessions" because of the wider ramifications of this kind of 'big data' analysis.

But this particular initiative was focused on pulling out a huge trove of user ID and IP data and following users "backward and forward in recent time" to and from a Canadian airport to see if it would be possible to keep tabs movements and trigger alerts based on those movements.

What we reported was accurate and remains so: "Canada's electronic spy agency used information from the free internet service at a major Canadian airport to track the wireless devices of thousands of ordinary airline passengers for days after they left the terminal."

Even CSEC chief Forster has since come out and admitted that a kind of tracking was going on (though he says it didn't occur in "real time," which is not something we actually claimed):

Forster said the agency used metadata to develop a model that showed they could track an internet user's network activity "around a public access mode," and that the tracking didn't happen in real time.

Some of the more insightful analysis on the CSEC affair has come from Bill Robinson, a Canadian surveillance expert described by the Toronto Star as "Canada's authority on CSEC."

Robinson makes some interesting points on the meaning of "tracking" in this context and CSEC's initial denial that it had tracked people — and I think he could be hitting the nail on the head here:

While normal human beings might conclude that both Canadian and foreign travellers were indeed tracked, CSEC's claim may be that only devices were tracked in the specific tests reported in the document. Since no device was tracked specifically on account of the fact that it belongs to a particular person, and the analysis itself (as far as I know) did not seek to associate particular individuals with particular devices (although it may well have utilized information associated or associatable with specific individuals), CSEC may feel it is justified in stating that no individuals were tracked. The same or similar logic seems to underlie the agency's claim that it can collect metadata related to thousands or even millions of Canadians and persons in Canada for foreign intelligence purposes while at the same time stating that its foreign intelligence operations do not "target" any Canadians or persons in Canada.

In a separate blog post after spy chief Forster's testimony before the Canadian Senate committee on Monday, Robinson wrote:

In essence, the government's position is that the metadata project reported by the CBC did take place, that its purpose was to develop targeting and analysis techniques that are in fact now being used operationally by CSEC, and that the collection, analysis, use, and retention of Canadian metadata is a normal part of CSEC's operations, necessary to those operations, and entirely legal. Officials also insist, however, that CSEC does not use the data to target Canadians for foreign intelligence purposes.
To have CSEC now appearing to admit (under pressure) that it is using metadata to conduct domestic monitoring on a mass scale is revelatory — and that is where the focus should be. As I wrote here previously, how "tracking" is being defined as a word should not be the most central point in the debate. The attention should be on CSEC conducting a large-scale surveillance operation on Canadian soil and misleading Canadian citizens about it in a series of public statements. Robinson asks the right questions in his earlier blog post:

If real-world operations are now being conducted using the techniques described in the document, or similar kinds of techniques, those operations will indeed involve the tracking of specific individuals who are either known before the tracking began or identified subsequent to their being singled out by analysis of the data.

Will the government state that no Canadian or foreign travellers have ever been tracked (or, if it prefers, detected in a number of different locations over time) in Canada, either by CSEC or by any other Canadian or allied agency, under any mandate, using these or similar metadata-based techniques?

India's BlackBerry Snooping

Friday, 22 February 2013

The Indian government, as I reported at Slate today, is keen to obtain data on millions of BlackBerry users across the world to help its spy agencies intercept and track messages sent in and out of the country.

I was able to obtain some revealing Indian government documents, signed and dated as recently as last month, which offer an unusual level of insight into how the authorities have been negotiating with BlackBerry to enable surveillance of communications. You can find a bunch of previously unpublished extracts from these documents below.

Why they are of particular interest is because they disclose the level of cooperation between BlackBerry and spy agencies. It is highly likely that BlackBerry has worked with other countries — not only India — to help them monitor communications sent via BlackBerry's unique "BBM" messaging service, which allows BlackBerry users to communicate for free with each other.

Authorities in the United Kingdom, for instance, struggled to intercept BlackBerry messages during the riots in 2011 due to the encryption the technology uses. However, BlackBerry later admitted that it had "engaged with the authorities to assist," presumably by providing the type of interception function that is currently being used in India. The Indian government document I obtained show the authorities there have been working with RIM to:
  • Enable interception of emails and email attachments sent using BlackBerry devices.
  • Enable monitoring of web browsing by people using BlackBerry handsets.
  • Enable eavesdropping on messages sent via BlackBerry messenger.
  • Enable the interception of "delivery reports" showing when a sent message has been received.
  • Obtain access to a trove of the unique PIN codes of all BlackBerry phones shipped to India. (These codes can be used to trace and intercept BlackBerry messenger communications. Indian authorities are seeking access to all PIN codes belonging to every BlackBerry handset across the world. They say this will enable them to track and monitor BlackBerry messages going from India to countries overseas.)

It also caught my eye that the US-based company Verint, which I recently reported is offering governments a mass surveillance system to help intercept "billions" of communications, was present while India's BlackBerry monitoring system was being tested.

You can read the specific details in the extracts indented below, taken from an Indian government department of telecommunication report, produced by its "security wing." There is quite a lot of telecom jargon in there, unfortunately, but if you can cut through the acronyms you will see that the content is significant. I've included a little glossary/acronym debunker at the bottom of this post which may help translate. I've also bolded some bits that stand out to me as particularly noteworthy.

Research in Motion (RIM), Canada, is providing the Blackberry services in India through the licensed Telecom Service Providers.

Since Blackberry services are not getting intercepted in a readable format while lawful interception and monitoring by Security agencies, RIM was asked to provide the solution for lawful interception and monitoring in a readable format.

Accordingly, RIM offered the Interception solution for testing on 19.07.2012. During the testing, some observations were made by the testing team which were forwarded to RIM for compliance vide this office even letter dated 27.07.2012.

We may ask all the TSPs [telecom service providers] to comply with the Blackberry Interception requirements by 31.12.2012.

...the initial testing of various Blackberry services offered in India by Research In Motion (RIM), Canada, was carried out on 19 July, 2012 at Mumbai. During the testing on 19 July, 2012, some observations were made and conveyed to RIM as well as Vodafone to comply, which are as follows:

  • (i) PIN resolution is required to identify the actual user behind Blackberry PIN.
  • (ii) Web-browsing services which are being offered under BIS [are] also required to be decrypted.
  • (iii) CRI [call related information] is required in the standard format as applicable for Non-Blackberry cases.
  • (iv) Correlation between attachment intercepted communication and its initial email communication is required.
  • (v) The correct direction has to be provided in the CRI as per actual case scenario.
  • (vi) In case of BES services, Enterprise server and its Public IP address should be made available.
  • (vii) The delivery & read acknowledgment communications/signaling messages are not getting intercepted.
For the compliance of the above observations, RIM offered the testing in the network of Vodafone for the verification of compliances against the observations made on 19 July 2012. Accordingly, the testing was conducted on 10 Dec 2012 at Vodafone Data Center, Sahas, Mumbai. Besides the representatives of RIM Canada, Verint & Vodafone...officers were present during the testing...

*****

The IMEI was populated in all the scenarios of BBM (incoming / outgoing) and PIN-to-PIN messages (incoming and outgoing) correctly along with the PIN details (and IMEI) details of both the target and the other communicated party. However, if the target/communicated party is international then correlation between Blackberry PIN and IMEI does not appear.

During interaction, it was clarified by RIM that database provided in the CRS [carrier routing system] is based on the information of the PINs which have been officially shipped to India and data pertaining to other countries have not been provided due to privacy and other legal provisions of those countries. However, if data for entire world is loaded in the CRS, it can correlate each & every PIN.

In OS5 — the Web browsing service is based on RIM proprietary protocol (IPPP). Presently, it cannot be intercepted in a readable format through the proposed solution. As per RIM, the solution for OS5 is still under development and will be deployed and tested by end of April 2013.

Correlation between attachment intercepted communication and its initial email communication is required. Email Attachments — In BIS Email service, attachments are not downloaded automatically for incoming mails. Attachment gets transmitted after email is delivered when the user initiates an event to download it. Thus, the attachment arrives in a later stage (after the Email product has already been marked and stored), the system shall mark an independent File Transfer product (like Email).

With respect to PIN to IMEI resolution, the tested solution is apparently satisfactory for all the handsets officially shipped to India. With regard to handsets shipped to other countries, RIM intimated that PIN to IMEI correlation in such cases can be obtained through Blackberry Public safety office (PSO). However, we may negotiate with RIM to provide the entire IMEI-PIN correlation data including other countries.

it is proposed that:

(i) We may initiate a process to take over the possession of RIM infrastructure created at Mumbai for which a suitable agreement may be entered between DOT [department of telecommunication] and RIM.

(ii) We may negotiate with RIM to provide the Blackberry PIN-IMEI Correlation data for all the Blackberry handsets.

(iii) RIM and Vodafone may be asked to demonstrate the final solution in respect in respect of [interception of delivery reports] by end of January 2013 and [email attachment monitoring and web browsing tracking/decryption] by end of April 2013.

Acronym debunker: PIN = Personal Identification Number (a unique code every BlackBerry is allocated, can be used to track and monitor communications and identify the sender); BBM = BlackBerry Messenger; IMEI = International Mobile Station Equipment Identity (another unique code used to identify a phone); OS5 = a BlackBerry operating system; BIS = BlackBerry Internet Service; CRI = Call Related Information (the who, where and when of a communication — like the time a call was made and the number of the caller and recipient); CRS = Carrier Routing System (network infrastructure through which communications travel).

When Stories Cross Borders

Sunday, 13 January 2013

One of the many cool things about the Internet, from the perspective of a journalist, is the way it can massively enhance the reach of a story and evolve it from something that is national to something that is truly international.

Case in point: this evening I stumbled across this Canadian news report from late last year: Police Departments Won't Say if They Use Cellphone ID Tech. It is about how a Canadian civil liberties group, prompted by an investigation I produced for the Guardian in late 2011, tried to uncover whether police in the country are using a sophisticated mobile phone spy technology made by a UK company called Datong.

Here's a snippet:

Police in three major Canadian departments have declined to confirm whether they have the technology to identify people in a crowd based on the unique identifiers on their cellphones.

"It reflects a massive invasion of privacy," said David Eby, the executive director of the B.C. Civil Liberties Association, speaking about the technology which can be used to capture the International Mobile Subscriber Identity or International Mobile Equipment Identity on cellphones and other devices.

Eby said the BCCLA became interested in whether the technology was being used here after reading about it in a British newspaper article.

The organisation tried to contact Vancouver Police, Royal Canadian Mounted Police and Ontario Provincial Police because it discovered that a Canadian company called Dyplex Communications was a distributor of the the secretive UK-made technology in question.

Unsurprisingly, and in keeping with the position taken by most police forces across the world, the Canadian cops declined to confirm or deny whether they used the snooping gear on the grounds that they "do not disclose electronic surveillance techniques or equipment on the primary grounds of concern for officer safety and the integrity of current or future investigations."

You can read the full correspondence between the police forces and the civil liberties group here [pdf], courtesy of news site The Tyee.