Obama signs NDAA 2014 indefinite detention remains

On Thursday President Obama signed into law the 2014 National Defense Authorization Act (NDAA), a sweeping defense policy bill, which includes some improvements in terms of civil liberties and human rights on its previous two iterations. However, a number of provisions — as in the 2012 and 2013 NDAAs — should keep civil libertarians concerned.
http://www.salon.com/2013/12/27/obama_signs_ndaa_2014_indefinite_detention_remains/

NSA revelations: the 'middle ground' everyone should be talking about

NSA revelations: the ‘middle ground’ everyone should be talking about | Matt Blaze

As if there wasn’t already enough NSA mass surveillance to worry about, last week we got a peek at the agency’s arsenal of tools for exploiting the hardware and software of its targets. They’re best described as a veritable SpyMall catalog of sophisticated concealed gadgets and surreptitious software “implants”, each sneakier than the last in its ability to compromise and extract private data from the computers and phones on which they’re installed. If you still thought there was anywhere in the electronic world to hide after you’re in their sights, this should be enough to disabuse you of that notion once and for all.
This lies atop six months of news of the myriad ways our metadata and, in some cases, our content, is being routinely collected and analyzed, cloud services and communications providers being compromised, and security standards that should be protecting us being sabotaged. The sane reaction seems to lie somewhere between paranoia and despair.
So we have to take small comforts where we can find them. And, paradoxically as it may seem, at least two of the most egregious revelations might actually hold out a glimmer of hope for privacy going forward.
First, we now have evidence, albeit indirect, that the NSA might not have the cryptologic superpowers that some feared they might. In particular, they have had to resort to outright sabotage of a range of security standards and systems that give them trouble. This suggests that a more robust (and un-sabotaged) infrastructure – secured by proper cryptography and without hidden backdoors or so-called “lawful intercept” interfaces – can make mass surveillance genuinely difficult. (And not just more difficult for the NSA. More difficult for other, perhaps less benevolent, nations’ intelligence services as well.) So perhaps we stand a chance after all, at least if we’re not being individually targeted.
Which brings us to the second encouraging bit of news, which is that if you are being individually targeted, you really don’t stand a chance. The NSA’s tools are very sharp indeed, even in the presence of communications networks that are well hardened against eavesdropping. How can this be good news? It isn’t if you’re a target, to be sure. But it means that there is no good reason to give in to demands that we weaken cryptography, put backdoors in communications networks, or otherwise make the infrastructure we depend on be more “wiretap friendly”. The NSA will still be able to do its job, and the sun need not set on targeted intelligence gathering.
[snip]

My 2014 resolution: stop my country from becoming a surveillance state

My 2014 resolution: stop my country from becoming a surveillance state by Dan Gillmore

Our New Year’s resolutions tend to be well-meaning and hard to keep. That’s because we resolve to change our lives in fundamental ways – get fit, etc. But inertia and habit are the enemy of change, and we usually fall back into old patterns. It’s human nature.
Despite all that, I’ve made a resolution for 2014. It is to do whatever I can to reverse my country’s trajectory toward being a surveillance state, and to push as hard as possible for a truly open internet.
I realize I can’t do much on my own, and hope many others, especially journalists, will join in. This year may be pivotal; if we don’t make progress, or worse, lose ground, it may be too late.
Thanks to whistleblowers, especially Edward Snowden, and the journalists who’ve reported on what they’ve been shown, the citizens of many countries have a far better idea than before about the extent to which security and law enforcement services have invaded their lives. We’ve learned about the stunning capabilities of the National Security Agency and others to create a real-life Panopticon, spying on and recording everything we say and do. We’ve learned that they abuse their powers – because that is also human nature – and lie incessantly, even to the people who are supposed to keep them in check. And we’ve learned that the technology industry is, if not in bed with the surveillance state, its chief arms dealer.
[snip]

Researchers warn of new, meaner ransomware with unbreakable crypto

Researchers warn of new, meaner ransomware with unbreakable crypto
Move over, CryptoLocker. Criminals are talking up more advanced PowerLocker.
By Dan Goodin
Jan 6 2014
<http://arstechnica.com/security/2014/01/researchers-warn-of-new-meaner-ransomware-with-unbreakable-crypto/>
Security researchers have uncovered evidence of a new piece of malware that may be able to take gigabytes’ worth of data hostage unless end users pay a ransom.
Discussions of the new malware, alternately dubbed PrisonLocker and PowerLocker, have been occurring on underground crime forums since November, according to ablog post published Friday by Malware Must Die, a group of researchers dedicated to fighting online crime. The malware appears to be inspired by CryptoLocker, the malicious software that wreaked havoc in October when it used uncrackable encryption to lock up victims’ computer files until they paid hundreds of dollars for the decryption key.
PowerLocker could prove an even more potent threat because it would be sold in underground forums as a DIY malware kit to anyone who can afford the $100 for a license, Friday’s post warned. CryptoLocker, by contrast, was custom built for use by a single crime gang. What’s more, PowerLocker might also offer several advanced features, including the ability to disable the task manager, registry editor, and other administration functions built into the Windows operating system. Screen shots and online discussions also indicate the newer malware may contain protections that prevent it from being reverse engineered when run on virtual machines.
PowerLocker encrypts files using keys based on the Blowfish algorithm. Each key is then encrypted to a file that can only be unlocked by a 2048-bit private RSA key. The Malware Must Die researchers said they had been monitoring the discussions for the past few months. The possibility of a new crypto-based ransomware threat comes as developers continue to make improvements to the older CryptoLocker title. Late last month, for instance, researchers at antivirus provider Trend Micro said newer versions gave the CryptoLocker self-replicating abilities that allowed it to spread through USB thumb drives.