Showing posts with label interception. Show all posts
Showing posts with label interception. Show all posts

Spy Trojan Seller on Ethics, Authoritarians, & 'Bad Guys' vs. 'Good Guys'

Monday, 11 March 2013

Headquartered out of a modern industrial estate in Andover, England, Gamma Group sells controversial advanced surveillance technologies to intelligence and law enforcement agencies in countries across the world. The company has been the source of widespread news coverage over the last couple of years due to its spy trojan tools — designed to secretly infiltrate computers, monitor communications and siphon data from hard drives — which security researchers say they believe are being used by authorities in a host of countries with poor human rights records, including: Bahrain, Brunei, Ethiopia, Indonesia, Mongolia, Singapore, Turkmenistan, and the United Arab Emirates.

Recently, I had an interesting and at times revealing back-and-forth email exchange with Gamma's Germany-based spokesman, Martin J. Muench. It is significant enough that I feel it is worth reproducing here, mainly because it offers an unusual level of insight into Muench's — and ultimately Gamma's — thinking.

The exchange began when I sent Muench a query regarding a prospective story I was working on — a follow-up to a Netzpolitik article detailing documents showing German federal police's plans to use Gamma's "Finfisher" (a.k.a "FinSpy") computer surveillance software. I also wanted to ask Muench about a "code of conduct" his company is apparently looking to implement in response to concerns about complicity in human rights violations.

However, the exchange, all on the record, eventually became a broader discussion about selling surveillance technologies, with Muench telling me that "we don’t necessarily agree with each other as far as the definition of what is ethical" and adding that he thought journalists had kicked up a "fuss" about Finfisher because they themselves were "guilty of the most appalling breaches."

It makes for quite a thought-provoking read, I think, especially toward the end. The content of the correspondence has not been edited, though I have removed email signatures and greetings ("Hi Ryan," "best regards," etc.) to cut out unnecessary repetition.

*****

From: Ryan Gallagher
To: Martin J. Muench

22 January 2013 12:52

I was reading this report on netzpolitik.org about the German Bundeskriminalamt acquiring Finspy: https://netzpolitik.org/2013/secret-government-document-reveals-german-federal-police-plans-to-use-gamma-finfisher-spyware/

I wanted to confirm with you:

1. is this an accurate report? Have the Bundeskriminalamt purchased Finspy or are they just testing it?

2. I note that the Netzpolitik report says you are in talks with NGOs with regards introducing a code of conduct for companies like yours. Which organizations are involved in the discussions? Can you share any information about what the code of conduct might include? And are any other companies involved?

*****

From: Martin J. Muench
To: Ryan Gallagher

22 January 2013 13:15

1. is this an accurate report? Have the Bundeskriminalamt purchased Finspy or are they just testing it?

As you can imagine this article and others relating to it have stimulated a great deal of interest...

However, I am afraid I have to tell you that Gamma simply does not discuss its client base, its exports, or any of the operations which its clients may or may not be undertaking. This is because there is usually a contractual term of confidentiality, and because naming a client can prejudice criminal or counter terror investigations and compromise the security of the members of the police or security services involved. Neither will Gamma name any countries which have not purchased its products thereby enabling customer countries to be identified by a process of elimination.

2. I note that the Netzpolitik report says you are in talks with NGOs with regards introducing a code of conduct for companies like yours. Which organizations are involved in the discussions? Can you share any information about what the code of conduct might include? And are any other companies involved?

We are currently having discussions with several groups. I don’t wish to elaborate further at the moment as some of these groups are our most vociferous public critics but who are quite prepared to discuss our ideas with us in private. In fact we have drafted a proposed Code of Conduct for the industry which goes far beyond the current ECAs.

*****

From: Ryan Gallagher
To: Martin J. Muench

22 January 2013 14:04

Regarding the code of conduct: is there any way you can send me a copy of the draft so I can get an idea of what it includes? Will it be made available publicly?

I note that Privacy International were previously reported to have turned down an invitation to discuss the code of conduct: http://www.guardian.co.uk/technology/2012/dec/26/british-company-gamma-international

Why did Privacy International refuse to engage? Do you think the code will have credibility if groups like Privacy International say they won't meet you to discuss it?

*****

From: Martin J. Muench
To: Ryan Gallagher

22 January 2013 14:16

I would honestly appreciate not putting too much focus on it at this point as I firstly would like to finish it and most of all also implement everything that has been and will be defined in there before promoting it publicly. Once it's done and we began the implementation we will definately make it public.

PI was offered numerous times a visit to our offices, a full product demonstration and open discussions about various topics. They mentioned that they're discussing internally a few month ago but did not respond to any follow-up emails. No reasons were given on why the offer was ignored.

I can only guess or better wonder why Eric King of PI does not want a personal meeting and also see the other side of the stories especially as he is spending so much time and energy on them without having the full picture; but I don't think that one organisation like PI not being interested in also giving constructive criticism will affect the credibility of such a code on a global level.

*****

From: Ryan Gallagher
To: Martin J. Muench

22 January 2013 15:05

If you have not yet implemented the code of conduct, doesn't that mean you are acknowledging that thus far you have not been adhering to appropriate ethical standards? What exactly is it that you need to implement? It would be great if you could show me a draft of the code, even on a background basis, to help me understand the context of the thing.

*****

From: Martin J. Muench
To: Ryan Gallagher

22 January 2013 21:56

Firstly, let me correct you. I am not acknowledging that Gamma has not adhered to ethical standards at all. One problem with ethical standards is that we all have them and we don’t necessarily agree with each other as far as the definition of what is ethical. Who decides? You have your views, I have mine and others have theirs’. That’s not to say we all disagree on everything. It simply means that we don’t all have the same views and for very different reasons.

Our position is this; we believe in the right to privacy but we don’t believe it takes precedence over or supersedes the right to life. We believe that nation states have the right to defend themselves against terrorists and we believe in the right to fight organised crime. We sell FinFisher to governments and law enforcement agencies to do this. We don’t sell a mass-monitoring tool. We sell a highly sophisticated piece of target specific software capable of providing evidential quality reports.

Another problem, of course, is that today’s ‘good guy’ may be tomorrow’s ‘bad guy’ and vice versa. If we imposed a moral code based on our intuition as to who might become a bad guy in the future we could end up spending a lot of time thinking about it and doing very little else. So, until we can get a code of conduct up and running that will actually work, rather than pay lip service to ‘ethics’, we have decided to let the export controls authorities act as our ‘moral compass’, for want of a better expression. After all, they are best placed to know who the ‘bad guys’ are and who the likely future ‘bad guys’ will be. We follow their lead and comply with the law.

Of course one of the reasons that some of the media have picked up on FinFisher products and make such a fuss is that some of them have become the subject of law enforcement inquiries themselves by electronic means and have been shown in the past to be by their own admission guilty of the most appalling breaches. The Leveson Inquiry shows a good example of this.

*****

From: Ryan Gallagher
To: Martin J. Muench

23 January 2013 03:30

Your last email raises many questions for me.

One problem with ethical standards is that we all have them and we don’t necessarily agree with each other as far as the definition of what is ethical.

Ethical standards can sometimes be highly subjective but they are often also relative to basic standards of right and wrong. Would it be ethical for me to sell a gun to a man I knew had a history of violence and might subsequently use it to murder an innocent person? I think the answer to that question is obvious. And I think the same kind of hypotheticals can be used in the realm of surveillance technologies. Would it be ethical for me to sell a sophisticated spy technology to a notoriously brutal state security agency operating in a country ruled by a despot with a well documented record of cracking down on, beating and jailing people engaging in legitimate democratic activities?

So, until we can get a code of conduct up and running that will actually work, rather than pay lip service to ‘ethics’, we have decided to let the export controls authorities act as our ‘moral compass’, for want of a better expression.

By this I assume you mean European export controls? Or are you also including United Nations and United States sanctions?

I should point out that just because a company is not on an export control list doesn't mean it is a place where human rights violations are not rife. For instance, countries such as Turkmenistan, Kazakhstan, Uzbekistan, Morocco and Thailand are ruled by authoritarian regimes with little (if any) limitations on the use of sophisticated spy technologies to monitor innocent individuals participating in legitimate democratic activities (journalism, activism, etc.). It is a given that these countries also have serious criminals whom they wish to monitor. But they may also have a disposition towards abusing surveillance technology to stifle dissent, track dissidents, target journalists, etc.

Have you never considered conducting an analysis of each country's respective social and polititical conditions before you do business with it? This is in line with the "know your customer" program recommended by the United States and the UN Guiding Principles on Business and Human Rights, which outlines how companies should "act with due diligence to avoid infringing on human rights and address adverse impacts."

It doesn't strike me as due diligence for you to say that you will sell to any country so long as they are not on a sanctions list.

Of course one of the reasons that some of the media have picked up on FinFisher products and make such a fuss is that some of them have become the subject of law enforcement inquiries themselves by electronic means have been shown in the past to be by their own admission guilty of the most appalling breaches. The Leveson Inquiry shows a good example of this.

I find this to be a bit of an inaccurate comparison. The "phone hacking" scandal involved (unethical) tabloid journalists listening to the voicemails of individuals by entering a default PIN code into their mailbox to gain access. I don't think that it is comparable to providing authoritarian regimes with a sophisticated spy trojan that can be used to secretly take over targeted computers, intercept communications and steal data from hard disks. The scale is different, the technology is different, and, perhaps most crucially, the potential harms are different.

*****

From: Martin J. Muench
To: Ryan Gallagher

23 January 2013 08:51

Thanks for your email. It’s a fascinating debate and one in which we could engage for some time. I see you have strong views and clearly have made your own judgments but I am afraid that I am going to have to end it here.

Would it be ethical for me to sell a sophisticated spy technology to a notoriously brutal state security agency operating in a country ruled by a despot with a well documented record of cracking down on, beating and jailing people engaging in legitimate democratic activities?

This may well be a view held by some of; the UK (Northern Ireland), the USA (Guantanamo Bay) or Germany – and we are a little sensitive of our past. However, many people in the West might not view those counties that way…..

Debate aside and let’s be clear, we co-operate with the export controls agencies of Germany, the UK and the USA. Gamma simply does not discuss its client base, its exports, or any of the operations which its clients may or may not be undertaking. This is because there is usually a contractual term of confidentiality, and because naming a client can prejudice criminal or counter terror investigations and compromise the security of the members of the police or security services involved. Neither will Gamma name any countries which have not purchased its products thereby enabling customer countries to be identified by a process of elimination.

Lastly, may I suggest you have a closer look at the Leveson Inquiry — you may find it illuminating — at least in the definition of a tabloid (David Leigh of The Guardian admits to hacking an arms dealer?)

*****

From: Ryan Gallagher
To: Martin J. Muench

23 January 2013 13:33

Yes, it's an interesting discussion. I was particularly keen to hear your response to my question about due diligence and the UN Guiding Principles on Business and Human Rights, which I note that you did not answer directly.

we are a little sensitive of our past. However, many people in the West might not view those counties that way…..

What do you mean?

may I suggest you have a closer look at the Leveson Inquiry – you may find it illuminating — at least in the definition of a tabloid (David Leigh of The Guardian admits to hacking an arms dealer?)

Yes, that's right. There were a few cases included in the Leveson inquiry that focused on journalists outside the tabloids, though it was certainly a tabloid-orientated inquiry. The Leigh case is interesting because it reveals the extent to which investigative journalists will sometimes break the law in order to expose corruption — which can be deemed permissible under UK law if there is a substantial "public interest" defence. In 2006, well before Leveson, Leigh admitted to listening to voicemails of an arms dealer in order to help reveal corrupt payments. If you followed the case you would know that the UK's Crown Prosecution Service looked into Leigh's activities and advised that he not be prosecuted because on balance it was decided his actions were in the public interest: http://www.guardian.co.uk/media/2012/jun/14/police-guardian-journalist-phone-hacking

I understand why you raise the example. But ultimately it is unrelated to what we are discussing — that is, export controls and surveillance technologies. It's false equivalence for you to bring up Leveson in the context of selling spy trojans to authoritarian regimes. As I wrote in my previous message, the scale is different, the technology is different, and, perhaps most crucially, the potential harms are different.

*****

From: Martin J. Muench
To: Ryan Gallagher

23 January 2013 14:37

Thank you for your email. I do not wish to add anything at this point. You have my answers.

India's BlackBerry Snooping

Friday, 22 February 2013

The Indian government, as I reported at Slate today, is keen to obtain data on millions of BlackBerry users across the world to help its spy agencies intercept and track messages sent in and out of the country.

I was able to obtain some revealing Indian government documents, signed and dated as recently as last month, which offer an unusual level of insight into how the authorities have been negotiating with BlackBerry to enable surveillance of communications. You can find a bunch of previously unpublished extracts from these documents below.

Why they are of particular interest is because they disclose the level of cooperation between BlackBerry and spy agencies. It is highly likely that BlackBerry has worked with other countries — not only India — to help them monitor communications sent via BlackBerry's unique "BBM" messaging service, which allows BlackBerry users to communicate for free with each other.

Authorities in the United Kingdom, for instance, struggled to intercept BlackBerry messages during the riots in 2011 due to the encryption the technology uses. However, BlackBerry later admitted that it had "engaged with the authorities to assist," presumably by providing the type of interception function that is currently being used in India. The Indian government document I obtained show the authorities there have been working with RIM to:
  • Enable interception of emails and email attachments sent using BlackBerry devices.
  • Enable monitoring of web browsing by people using BlackBerry handsets.
  • Enable eavesdropping on messages sent via BlackBerry messenger.
  • Enable the interception of "delivery reports" showing when a sent message has been received.
  • Obtain access to a trove of the unique PIN codes of all BlackBerry phones shipped to India. (These codes can be used to trace and intercept BlackBerry messenger communications. Indian authorities are seeking access to all PIN codes belonging to every BlackBerry handset across the world. They say this will enable them to track and monitor BlackBerry messages going from India to countries overseas.)

It also caught my eye that the US-based company Verint, which I recently reported is offering governments a mass surveillance system to help intercept "billions" of communications, was present while India's BlackBerry monitoring system was being tested.

You can read the specific details in the extracts indented below, taken from an Indian government department of telecommunication report, produced by its "security wing." There is quite a lot of telecom jargon in there, unfortunately, but if you can cut through the acronyms you will see that the content is significant. I've included a little glossary/acronym debunker at the bottom of this post which may help translate. I've also bolded some bits that stand out to me as particularly noteworthy.

Research in Motion (RIM), Canada, is providing the Blackberry services in India through the licensed Telecom Service Providers.

Since Blackberry services are not getting intercepted in a readable format while lawful interception and monitoring by Security agencies, RIM was asked to provide the solution for lawful interception and monitoring in a readable format.

Accordingly, RIM offered the Interception solution for testing on 19.07.2012. During the testing, some observations were made by the testing team which were forwarded to RIM for compliance vide this office even letter dated 27.07.2012.

We may ask all the TSPs [telecom service providers] to comply with the Blackberry Interception requirements by 31.12.2012.

...the initial testing of various Blackberry services offered in India by Research In Motion (RIM), Canada, was carried out on 19 July, 2012 at Mumbai. During the testing on 19 July, 2012, some observations were made and conveyed to RIM as well as Vodafone to comply, which are as follows:

  • (i) PIN resolution is required to identify the actual user behind Blackberry PIN.
  • (ii) Web-browsing services which are being offered under BIS [are] also required to be decrypted.
  • (iii) CRI [call related information] is required in the standard format as applicable for Non-Blackberry cases.
  • (iv) Correlation between attachment intercepted communication and its initial email communication is required.
  • (v) The correct direction has to be provided in the CRI as per actual case scenario.
  • (vi) In case of BES services, Enterprise server and its Public IP address should be made available.
  • (vii) The delivery & read acknowledgment communications/signaling messages are not getting intercepted.
For the compliance of the above observations, RIM offered the testing in the network of Vodafone for the verification of compliances against the observations made on 19 July 2012. Accordingly, the testing was conducted on 10 Dec 2012 at Vodafone Data Center, Sahas, Mumbai. Besides the representatives of RIM Canada, Verint & Vodafone...officers were present during the testing...

*****

The IMEI was populated in all the scenarios of BBM (incoming / outgoing) and PIN-to-PIN messages (incoming and outgoing) correctly along with the PIN details (and IMEI) details of both the target and the other communicated party. However, if the target/communicated party is international then correlation between Blackberry PIN and IMEI does not appear.

During interaction, it was clarified by RIM that database provided in the CRS [carrier routing system] is based on the information of the PINs which have been officially shipped to India and data pertaining to other countries have not been provided due to privacy and other legal provisions of those countries. However, if data for entire world is loaded in the CRS, it can correlate each & every PIN.

In OS5 — the Web browsing service is based on RIM proprietary protocol (IPPP). Presently, it cannot be intercepted in a readable format through the proposed solution. As per RIM, the solution for OS5 is still under development and will be deployed and tested by end of April 2013.

Correlation between attachment intercepted communication and its initial email communication is required. Email Attachments — In BIS Email service, attachments are not downloaded automatically for incoming mails. Attachment gets transmitted after email is delivered when the user initiates an event to download it. Thus, the attachment arrives in a later stage (after the Email product has already been marked and stored), the system shall mark an independent File Transfer product (like Email).

With respect to PIN to IMEI resolution, the tested solution is apparently satisfactory for all the handsets officially shipped to India. With regard to handsets shipped to other countries, RIM intimated that PIN to IMEI correlation in such cases can be obtained through Blackberry Public safety office (PSO). However, we may negotiate with RIM to provide the entire IMEI-PIN correlation data including other countries.

it is proposed that:

(i) We may initiate a process to take over the possession of RIM infrastructure created at Mumbai for which a suitable agreement may be entered between DOT [department of telecommunication] and RIM.

(ii) We may negotiate with RIM to provide the Blackberry PIN-IMEI Correlation data for all the Blackberry handsets.

(iii) RIM and Vodafone may be asked to demonstrate the final solution in respect in respect of [interception of delivery reports] by end of January 2013 and [email attachment monitoring and web browsing tracking/decryption] by end of April 2013.

Acronym debunker: PIN = Personal Identification Number (a unique code every BlackBerry is allocated, can be used to track and monitor communications and identify the sender); BBM = BlackBerry Messenger; IMEI = International Mobile Station Equipment Identity (another unique code used to identify a phone); OS5 = a BlackBerry operating system; BIS = BlackBerry Internet Service; CRI = Call Related Information (the who, where and when of a communication — like the time a call was made and the number of the caller and recipient); CRS = Carrier Routing System (network infrastructure through which communications travel).

Surveillance, Britain's Secret Agencies, and Drowning in Data

Thursday, 25 October 2012

I was speaking to someone today about this, and it occurred to me that it is a piece of information that is not widely known but should be.

Every year in Britain, there is an official report that comes out detailing the activities of the UK's spy agencies — MI5, MI6 and GCHQ. It is authored by a group of politicians who function as a kind of oversight authority, under the name the Intelligence and Security Committee.

In this year's report, published in July, I noticed a section of particular interest in light of new proposals for more surveillance powers in the UK. The second paragraph is what is important here — it is a comment made by Jonathan Evans, chief of domestic security agency MI5.

The Security Service is undertaking a number of major projects covering estates, business continuity, core IT systems and improving its digital investigative capabilities. A notable success during the reporting period was the completion of the Digital Intelligence (DIGINT) programme, which aimed to improve systems for the collection and analysis of intelligence material gathered electronically. The Director General explained:

"One of the things that really drove us on the investment of DIGINT was a discussion where the relevant directors explained that actually, of all the material that we’ve caught, over half was not being processed. Now, as an intelligence organisation, that’s a nightmare. I mean, quite frankly, I would rather not have the intelligence at all and miss something than have the intelligence and not actually having processed it… We have made real progress on that, and I’m very proud on DIGINT." (Emphasis added)

What this comment suggests, for the sake of clarity, is that the UK's spy agencies in recent years have been mining and storing quantities of electronic data — or "digital intelligence" — so large that they have not been able to analyse it. The data, most of it I would expect is mined from the internet, has probably been gathered and then left to sit and gather digital dust in a secret storeroom somewhere. The claim from Evans in the above quote is that MI5 has worked to address the problem as part of a new programme, which presumably involves a great deal of automated analysis. But the statement also illustrates how new surveillance powers currently being proposed in the UK could pose problems for the UK if the security services are already near a point where they are drowning in data.

There tends to be two main schools of thought within the intelligence community. Some believe that targeted surveillance of specific individuals and groups is the best method, because it provides information that can be dissected and acted upon fairly quickly by human analysts. The other school of thought, and the one which seems to be prevailing, is that a kind of dragnet surveillance is superior. What this entails is gathering huge quantities of data based on key words, locations, phrases, and then mining through it to find anything useful. From a rights and civil liberties perspective, targeted surveillance is clearly more attractive because it is likely to involve much less intrusion of innocent individuals' communications. But rights and civil liberties do not appear to be high on the agenda at our secret agencies, and so what we get is something closer to the dragnet option.

I should add that surveillance in the UK is not without regulation. To intercept domestic communications, police and security services require ministerial authorisation, and must show that any interception is in the interests of national security, safeguarding economic well being, or to prevent and detect serious crime. That said, these justifications are fairly broad, and there were 2,911 interception warrants granted in 2011 — but any one warrant can cover countless individuals, so we actually have little idea how many people had their communications snooped on. (Also, to monitor content posted on social networks and other "open source" websites, there are no laws or restrictions at all. So websites like Facebook, Twitter and Foursquare are all fair game for the likes of MI5's "DIGINT" team to gather data from.)

Encroaching Constant Surveillance 'Scares' Senior Clinton Adviser

Tuesday, 4 September 2012

Some interesting remarks were made last week by Alec Ross, a senior adviser to US secretary of state Hillary Clinton. In an interview aired Thursday on C-SPAN, Ross spent a few minutes dealing with some of the big questions around surveillance technologies, control, and the Internet.

Ross acknowledged the incremental advance of "near constant surveillance" was something that personally "scares" him. He also claimed the US restricts the sale of technologies that can be used "to oppress people in countries where we have sanctions," though admitted that stopping repressive nations getting their hands on surveillance tools was difficult: "There are a lot of vendors out there now... we can restrict the sale of exports from American companies... But then they [oppressive governments] are able to turn around and buy it from another country."

He went on to add that a fundamental problem is that the surveillance industry has become a multi-billion dollar industry: "It's a very remunerative environment... Whenever you've got that much money at play, there are going to be people who are trying to make the money."

Here's a transcript (plus audio):

I think that as networking technologies become increasingly powerful and increasingly ubiquitous, their ability to oppress a people also grows. You know, you can't take a utopian view of the Internet and of network technologies. In fact, a government with malignant intent can bend these networks to infiltrate, monitor and manipulate what's happening there, and to surveil its citizens.

This is something that, let me be blunt, it really scares me. I've got a five year old, a seven year old, and a nine year old, and the world that they grow up in is going to be a very different one that the world that I did, in terms of hyper-transparency and in terms of near constant surveillance.

The responsibility of the State Department - there are a couple of things. First of all we restrict the sale of technologies which can be used to oppress people in countries where we have sanctions. In other cases there are export controls, where we can help inform the licensing of certain products and services.

But in your question you made the right point. Certain of the use of these technologies are utterly benign. So the same thing which can be used to inspect a packet to determine whether people are organising a protest can also be used to reasonably filter out spam. So you've got to remember that the very same technologies that can be used for reasonable and benign purposes can also be used for malignant purposes.

[What's an example of one of those technologies that might be restricted?]

There are a variety of different technologies that governments - the Syrian government, the Iranian government, and others - have tried to access, either from the United States or from Europe. The problem is, just to be blunt, there are a lot of vendors out there now. You know, we can restrict the sale of exports from American companies. I'm really glad that the Europeans have joined us in similarly restricting sales of a lot of things from Europe, to certain of these oppressive environments. But then they are able to turn around and buy it from another country.

You know, there are not two or three or four companies out there selling gear. And it's a very remunerative environment. I mean there are countries around the world who are spending billions - tens of billions of dollars – to try to monitor its information environment. Whenever you've got that much money at play, there are going to be people who are trying to make the money. And so this has been a big problem.

No doubt some people will be quick to call out Ross for his remarks. Why? Well, for starters, US technology used to monitor and censor the Internet has made it into the hands of despots despite US trade embargoes. Several US companies also participate in ISS World, a series of international surveillance industry conferences organised by an American businessman, where governments from all corners of the globe come to purchase the latest spy tools and learn about new surveillance techniques. And the US itself is hardly a surveillance-free zone. Serious questions remain unanswered about a new National Security Agency data centre in Utah which it is alleged will intercept and store "complete contents of private emails, cell phone calls, and Google searches, as well as all sorts of personal data trails—parking receipts, travel itineraries, bookstore purchases, and other digital 'pocket litter'." Not to mention the role so-called 'Fusion Centres' play across the US, monitoring 'suspicious activity' and keeping tabs on social networks. I could go on...

That said, Alec Ross is one of a tiny handful of political figures who appears to be clued up on the complex issues - political, moral, technological, legal - around surveillance and its rapid, incremental encroachment across the world. You will see few senior political figures in any country talking publicly on this topic as Ross does, and that in itself is worth something.

Last year, for instance, I interviewed Jerry Lucas, the American who organises the ISS World surveillance conferences. During the interview, extracts from which were later published in an article for the Guardian, Lucas gave some freakishly blasé responses to my questions about surveillance tools being sold to repressive governments. He was dismissive of human rights concerns, compared mass surveillance tech to "cars and trucks," and said that "you can't stop the flow of surveillance equipment." Shortly after, Alec Ross issued a stern public condemnation of the businessman's comments, telling him he should "be more thoughtful about the consequences of his beliefs. With all due respect, Mr. Lucas, people are tortured + there can be life/death consequences to sales of these products."

Of course, actions speak louder than words. More could certainly be done by legislators in the US to crack down on, and hold to account, companies exporting surveillance technology to places where it may be abused. And, as mentioned above, the US has its own serious, unresolved domestic issues regarding surveillance.

However, at the very least it is somewhat reassuring to know that there is a senior adviser in the State Dept. who seems to have a grasp on the basic fact that there is a problem. In the UK that is far from the case, which is a cause for considerable concern. I can't name one senior British political figure - or an adviser to a senior figure - who has spoken out about the myriad problems heralded by the booming surveillance industry. Advisers in London could probably learn a thing or two from Ross by trying to engage with the subject in a public forum. But I won't be counting on that happening any time soon.

Hacking Team: Mass Surveillance Made In Milan

Monday, 27 August 2012

Of all the companies I have encountered while working on stories about surveillance technology used by police and governments, Italy's Hacking Team is one of the most intriguing.

The Milan-based "offensive security" firm manufactures a kind of spy software, called "Remote Control Systems" (RCS), that infects computers and mobile phones in order to secretly siphon data.

RCS is designed to covertly record emails, text messages, phone (or Skype) calls, GPS location, and take screenshots - before sending this information back to law enforcement agencies for inspection. It can be used to target almost any device or platform - Windows, OSX (operating system that runs on Mac computers), iOS (used by iPhones and iPads), Android, Blackberry, Symbian, Linux - and can infect a computer or phone by tricking a user into opening an fake document file.

The technology is controversial, not least because Hacking Team boasts in its own marketing materials that it can be deployed "country-wide" to spy on the communications of more than 100,000 people simultaneously.

Human rights groups say that it could, in the wrong hands, easily be abused to target activists, political opponents, or anyone else deemed a worthy target - and these concerns certainly appear to be well founded. As I reported for Slate last week, the first instance of Hacking Team's spyware being used for nefarious purposes has purportedly been found in Morocco, where a team of award-winning citizen journalists (and prominent critics of Morocco's government) were targeted with what security experts say they are certain is a version of Hacking Team's RCS spyware.

Due to the secretive nature of Hacking Team's work, there is much we still don't know about where and how this technology is being deployed. However, in the months ahead, I fully expect that more details about countries using Hacking Team's technology will inevitably emerge.

In the meantime, I've decided to share here a summary of the main issues and things I've discovered so far. The information comes from a combination of sources: primarily an interview I conducted with Hacking Team's co-founder David Vincenzetti in October 2011 (a portion of which appeared later in the Guardian), along with marketing materials and documents published in the WikiLeaks Spy Files in December. If you have information you would like to add - or if you have source material related to Hacking Team which has not yet entered the public domain - please contact me.

Who uses Hacking Team's spy technology?

Hacking Team refuses to divulge details about specific customers and/or countries it deals with. However, the company's co-founder told me in 2011 that it had sold the RCS spyware to "approximately 50 clients in 30 countries in all five continents" since 2004. The company's website says it only sells its software to governments and law enforcement agencies.

What is Hacking Team's technology used for and why?

Hacking Team says its spy software is necessary in a world where terrorists and other serious criminals are constantly crossing borders, using various devices to communicate while sometimes using encryption. RCS allows law enforcement agencies to bypass encryption by recording data before it becomes encrypted. It also allows them to monitor targets across borders and gives them access to data that they might otherwise find very hard to otherwise obtain, such as photographs or document files stored on hard disks.

Most western democracies have laws governing the use of surveillance technology of this kind, and will use it only when they believe it necessary to detect or prevent serious criminal activity. The fear held by human rights groups is that Hacking Team's technology may have been sold to countries that do not have strict laws governing its use, which could mean that it is being abused to target, for instance, pro-democracy activists.

The fact that Hacking Team openly advertises that its software can be used to spy on hundreds of thousands of people's communications is a particular cause for concern, as it is difficult to conceive of any situation where the mass interception of communications on this scale could be justified.

(Note: A French company that in 2007 sold Gaddafi's Libyan regime surveillance technology, used to spy on dissidents, is currently facing a judicial probe for alleged complicity in crimes against humanity.)

What is Hacking Team's position on potential human rights violations?

In the words of David Vincenzetti: "We pay the utmost attention to whom we are selling the product to. Our investors have set up a legal committee whose goal is to promptly and continuously advise us on the status of each country we are talking to. The committee takes into account UN resolutions, international treaties, Human Rights Watch and Amnesty International recommendations."

What kinds of communications can RCS record?

The short answer is: everything. RCS has the capacity to record emails, Skype chats, instant messenger conversations, and text messages. It can log keystrokes (and passwords), mine documents from a hard drive, and steal private encryption keys. The software also has a function called "remote audio spy" which can be used to turn on a laptop or mobile phone's microphone, recording audio from a device without its user's knowledge.

Won't anti-virus software pick up RCS?

Hacking Team boasts that its spyware is "stealth" and "is totally invisible to the target. Our software bypasses protection systems such as antivirus, antispyware and personal firewalls."

How much do governments and LEAs pay for Hacking Team's technology?

According to David Vincenzetti: "RCS is a complex system and its price varies greatly depending on the number of targets to be monitored and the features included in it. RCS can be used for monitoring just a few targets (tactical use) or for monitoring targets 'country-wide', that is, hundreds of thousands of targets. Just to provide you with a very approximate price figure, I can tell you that a medium-sided installation might cost 600k euros." (€600,000 = £475,000 or $751,000.)

Who are the people that work at Hacking Team?

Hacking Team was founded in 2003 by self-described "serial entrepreneurs" David Vincenzetti and Valeriano Bedeschi. Valeriano and Vincenzetti say they have been working together in computer security for more than 20 years and Hacking Team is their fourth company. Their previous company was called Intesis srl, a software firm Vincenzetti describes "one of the most successful ventures in the Italian IT market." Since 2007 Hacking Team has had venture capital backing from two Italian funds: Innogest and Finlombarda.

The company employs around 35 people, and as of August 2012 was recruiting a "Field Application Engineer" to "guide them [our customers] through the process of learning, testing and adopting our Solution." It added that prospective candidate must be "willing to travel all over the world!" (Screenshot, 27 August, 2012.)

How does Hacking Team design its surveillance tools?

An interesting insight into the type of software programming used by Hacking Team was offered by a job vacancy description posted on its website in 2012. Hacking Team said it was looking for a "hacker / developer" with knowledge of the following: "C++, Objective-C, some x86 or ARM Assembly, Ruby or Python, ActionScript or reversing skills. Design Patterns and Agile Programming are a must."

In layman's terms, this means Hacking Team uses a series of programming languages used on different devices (Macs, PCs, mobile phones), and also works with code (Actionscript) primarily used with Adobe Flash Player. Many Trojan-style tools exploit security flaws in Adobe Flash Player to infect users with spyware.

UPDATE I, 10 October 2012: A new report by Citizen Lab security researchers has found evidence suggesting Hacking Team's surveillance spyware was used to target a prominent activist in the United Arab Emirates. Similar to the tactic used against the Moroccan journalists (see above), an email was sent to the UAE activist that tricked him into downloading the spyware. The email claimed to be from "Arabic WikiLeaks" and included a link to an infected file purporting to be a .doc file named "veryimportant". Hacking Team has so far not issued comment. Read more details in my report for Slate, here.

UPDATE II, 25 April 2013: In February, a detailed analysis by a researcher at Russia's Kaspersky Lab dissected Hacking Team's spy technology. Notably, the Kaspersky researcher claims to have found "about 50 incidents" in which Hacking Team's surveillance tool was used in countries including Italy, Mexico, Kazakhstan, Saudi Arabia, Turkey, Argentina, Algeria, Mali, Iran, India and Ethiopia. An updated Kaspersky analysis in April states that it has detected Hacking Team's technology in 37 countries. The highest number of attacks using the spy tool were found in Mexico, Italy, Vietnam and the United Arab Emirates. However, a small handful of attacks on users allegedly involving the Hacking Team technology were also detected in Iraq, Lebanon, Morocco, Panama, Tajikistan, India, Iran, Saudi Arabia, South Korea, Spain, Poland, Turkey, Argentina, Canada, Mali, Oman, China, the United States, Kazakhstan, Egypt, Ukraine, Uzbekistan, Colombia, Taiwan, Brazil, Russia, Kyrgyzstan, the United Kingdom, Bahrain, Ethiopia, Indonesia, Germany, and Libya.