Categories
Links Writing

WikiLeaks Isn’t Whistleblowing

Mass data releases, like the Podesta emails, conflate things that the public has a right to know with things we have no business knowing, with a lot of material in the middle about things we may be curious about and may be of some historical interest, but should not be released in this manner.

All campaigns need to have internal discussions. Taking one campaign manager’s email account and releasing it with zero curation in the last month of an election needs to be treated as what it is: political sabotage, not whistle-blowing.

These hacks also function as a form of censorship. Once, censorship worked by blocking crucial pieces of information. In this era of information overload, censorship works by drowning us in too much undifferentiated information, crippling our ability to focus. These dumps, combined with the news media’s obsession with campaign trivia and gossip, have resulted in whistle-drowning, rather than whistle-blowing: In a sea of so many whistles blowing so loud, we cannot hear a single one.

This is one of the best arguments against the recent activities of Wikileaks. Not because Wikileaks is operating as a front for Russia. Not because the contents of the recent leaks aren’t newsworthy. Not because the public doesn’t find the revelations to be interesting and fun.

No, the core issue with the latest rafts of leaks is that they were not sufficiently currated, with the impact being that obstensibly private information is taken and circulated and mischaracterized. This has the effect of stunting the electoral process while, simultaneously, reconfirming to persons in power that they need to adopt a culture of oral communications and decisions. This is not a governance direction that is in the public’s best interests.

However, it’s important to also situate Wikileaks’ activities in some context. Wikileaks is designed to clog up the machinery of government states and bureaucracies. Part of its mission is to scare organizations with the threat of leaks in an effort to hinder what Julian Assange/Wikileaks regards as harmful or objectional activities. So the leaks associated with the DNC and staff affiliated with Clinton are perfectly aligned with Wikileaks’ raison d’être. In the past such activities may have been regarded are more legitimate – the organization was principally focused on state level activities – but it is now focused on deliberately releasing information at core points in an electoral cycle. Doing so may have affected the unfolding of the election but it’s important to acknowledge that Wikileaks’ intent was not driven by Russia (presuming that was a source of at least some of the leaked information): instead, this was a case where Russian and Wikileaks just happened to have directly overlapping objectives.

Categories
Links Writing

Dissecting CSIS’ Statement Concerning Indefinite Metadata Retention

The Canada Security Intelligence Service (CSIS) released a public statement after the Federal Court found the Service to be breaking the law by permanently retaining metadata they had been collecting. To date, the Public Safety Minister has refused to clarify the numbers of Canadians who have been caught up in this ‘catch once, catch forever’ surveillance regime.

The Service’s statement is incredibly misleading. It is designed to trick Canadians and parliamentarians into thinking that CSIS didn’t do anything that was really ‘that’ bad. I fundamentally disagree with CSIS’ activities in this regard and, as a result, I’ve conducted a detailed evaluation of each sentence of the Service’s statement.

You can read my dissection of CSIS’ statement at Technology, Thoughts, and Trinkets.

Categories
Links Quotations

Police surveillance scandal: Quebec tightens rules for monitoring journalists

From the Montreal Gazette:

Mark Bantey, a specialist in media law (who is also the Montreal Gazette’s lawyer), said he was stunned by the scope of the warrant involved in the Lagacé case. He said it seems the police were more worried about who was leaking information to the press than the actual crime.

“It sure looks like they (the police) have gone overboard because they’re not out there investigating a crime, but trying to determine who in the police department is leaking information to the press. You can’t use search warrants to get that sort of information,” Bantey said in an interview Tuesday. “There’s an obligation to exhaust all other possible sources of information before targeting the media.”

As for Couillard’s new directive about obtaining search warrants, he called it a first step that was unlikely to bring an immediate change to police practices. A better solution might be to adopt new legislation — a shield law — that protects media sources, he said.

Legislation to protect journalists from police surveillance is a good idea…until you ask a question of ‘who constitutes a journalist’?

Categories
Links

“Stephen Colbert” from Fresh Air by NPR on iTunes

This was a really interesting interview with Colbert. His views on Catholicism, daily content creation linked with current events, and attitudes towards trust and working with teams make it particularly worth the listen.

Categories
Links Writing

Canada’s spy agency illegally kept data for a decade, court rules

To be clear, the judge’s ruling:

  1. Found that CSIS had deliberately been misleading/lying to the court for a decade concerning the agency’s permanent retention of metadata;
  2. Raised the prospect of contempt of court proceedings against CSIS and its attorneys at the Department of Justice;
  3. Approved changes to unknown warrants (we’re not allowed, as members of the public, to know the warranting powers of CSIS it seems);
  4. Did not require CSIS to delete or stop using the metadata it had illegally collected, on grounds that doing so could raise jurisdictional issues. Translation: the information has been shared, or mixed with, foreign agencies’ metadata already and thus prevents the court from easily crafting a judgment around its use;
  5. CSIS did not believe that it was required to be fully transparent with the federal court that issues CSIS’ warrants on grounds that the court was ‘not an oversight body’;
  6. CSIS had internally, with Department of Justice guidance, secretly reinterpreted laws to cloak its actions in the guise of lawfulness (internally) while deliberately hiding such interpretations and the implications thereof from the court.

Canada has a national security consultation going on, and part of it raises the question of ‘does Canada have sufficient oversight and accountability for its national security operations?’ If you care about these issues, go and spend some time sending a message to the government.

Categories
Links

How Canada’s Anti-Cyberbullying Law Is Being Used to Spy on Journalists

From Motherboard:

According to Citizen Lab researcher Christopher Parsons, these same powers that target journalists can be used against non-journalists under C-13. And the only reason we know about the aforementioned cases is that the press has a platform to speak out.

“This is an area where transparency and accountability are essential,” Parsons said in an interview. “We’ve given piles and piles of new powers to law enforcement and security agencies alike. What’s happened to this journalist shows we desperately need to know how the government uses its powers to ensure they’re not abused in any way.”

…

“I expect that the use of these particular powers will become more common as the police get more used to using it and more savvy in using them,” Parsons said.

These were powers that were ultimately sold to the public (and passed into law) as needed to ‘child pornography’. And now they’re being used to snoop on journalists to figure out who their sources are, without being mandated to report on the regularity at which the powers are used to the efficacy of such uses. For some reason, this process doesn’t inspire a lot of confidence in me.

Categories
Links

Donald Trump’s companies destroyed or hid documents in defiance of court orders

Newsweek:

Trump’s use of deception and untruthful affidavits, as well as the hiding or improper destruction of documents, dates back to at least 1973, when the Republican nominee, his father and their real estate company battled the federal government over civil charges that they refused to rent apartments to African-Americans. The Trump strategy was simple: deny, impede and delay, while destroying documents the court had ordered them to hand over.

Shortly after the government filed its case in October, Trump attacked: He falsely declared to reporters that the feds had no evidence he and his father discriminated against minorities, but instead were attempting to force them to lease to welfare recipients who couldn’t pay their rent.

The debates about who had hidden the most, and the significance of such hiding, continues unabated in the American election…

Categories
Links

Why DDoS attacks matter for journalists

Two reasons that journalists should be concerned about DDoS attacks:

First, while the use of common household devices to execute the attacks against Krebs and Dyn was novel, the hackers got control of those devices using one of the oldest and easiest methods out there: bad passwords, a vulnerability most journalists share.

…

The second reason journalists should attend to these attacks is that strategic use of both DDoS attacks (for example, recent attacks on Newsweek and the BBC) and DNS manipulation are common tools for censorship. This is in part because they are cheap, easy (the software credited with Friday’s attack was posted openly just a few weeks ago), and highly effective in preventing some or all internet users from accessing the content they target.

We’re at the edge of a particularly bad security chasm we’re just about to fall into (if we haven’t already!). The question is whether we can actually avoid the fall or whether the best we can do right now is lessen the hurt on the way down.

Categories
Links

How one rent-a-botnet army of cameras, DVRs caused Internet chaos

Ars Technica:

But even in the midst of the Dyn attack, some of the Mirai-infected devices were being used to attack another target—the infrastructure of a gaming company, according to Allison Nixon, the director of security research at security company Flashpoint. That idea matches up with what others who had some insight into the attack have told Ars confidentially—that it was also pointed at Sony’s PlayStation Network, which uses Dyn as a name service provider.

For now, it’s not clear that the attacks on Dyn and the PlayStation Network were connected. And with a criminal investigation underway, a Dyn spokesperson declined to confirm or deny that Sony was also a target. “We are continuing to work closely with the law enforcement community to determine the root cause of the events that occurred during the DDoS attacks last Friday,” Adam Coughlin, Dyn’s director of corporate communications, told Ars. “Since this is an ongoing investigation, we cannot speculate on these events.”

Regardless of the reasons behind it, the attack on Dyn further demonstrates the potential disruptive power of the millions of poorly protected IoT devices. These items can be easily turned into a platform for attacking anything from individual websites to core parts of the Internet’s infrastructure. And Mirai has demonstrated that it doesn’t take “zero-day” bugs to make it happen; attackers only need poorly implemented security on devices that can’t be easily fixed.

This is definitely one of the best writeups of the DDoS attacks launched againgst Dyn last week, which led to the downtime of major Internet properties. If you want to understand some of the security-related issues associated with the Internet of Things as well as challenges of attributing attacks to different attack infrastructures and intents, this is worth your time.

Categories
Links

Android phones rooted by “most serious” Linux escalation bug ever

Ars Technica:

Just as Dirty Cow has allowed untrusted users or attackers with only limited access to a Linux server to dramatically elevate their control, the flaw can allow shady app developers to evade Android defenses that cordon off apps from other apps and from core OS functions. The reliability of Dirty Cow exploits and the ubiquity of the underlying flaw makes it an ideal malicious root trigger, especially against newer devices running the most recent versions of Android.

“I would be surprised if someone hasn’t already done that this past weekend,” Manouchehri said.

Another week, another extremely serious Android vulnerability that will remain unpatched for the majority of consumers until they throw out their current Android phone and purchase another one (though even that new one might lack the patches!). I wonder what serious vulnerability will come through next week?