Posts

Showing posts with the label NSA

Cyber Security Roundup for February 2020

Image
A roundup of UK focused cyber and information security news stories, blog posts, reports and threat intelligence from the previous calendar month, January 2020. After years of dither and delay the UK government finally nailed its colours to the mast, no not Brexit but Huawei, permitting 'limited use' of the Chinese Telecoms giant's network appliances within the UK's new 5G infrastructure . Whether this is a good decision depends more on individual political persuasion than national security interest, so just like Brexit the general view on the decision is binary, either its a clever compromise or a complete sell out of UK national security. I personally believe the decision is more about national economics than national security, as I previously blogged in ' The UK Government Huawei Dilemma and the Brexit Factor' . The UK government is playing a delicate balancing to safeguard potentially massive trade deals with both of the world's largest economic superp...

Why Brexit will be Business as Usual for Cyber Security & Data Protection in the UK

So it actually happened, they have gone and done it, its shocked the world, the UK populous have voted to leave the European Union today. Now what? Well we'll have to just get on with it and starting thinking how Brexit will impact C yber Security and Data Protection in the UK from here on in.  I didn't post a word on Brexit despite being asked numerous times during the "debating" season, or as we in the security industry call it, FUD!.  But now its done and dusted, here are my thoughts, which as always on this blog, are completely  my own. Cyber Security Defence The UK is a significant player in the international cyber threat intelligence community, although a highly secretive business, the “snooping” documents leaked by Edward Snowden demonstrated how closely GCHQ works with their American counterpart agencies. When it comes to the business of protecting the UK’s critical national infrastructure, economy and businesses from cyb...

Why isn’t the GCHQ & NSA Privacy Invasion Socially Accepted?

Post Snowden it is easy to jump on the media bandwagon, cry foul that GCHQ and the NSA have gone too far, forsaking our Privacy for Security. Yet if you take a walk through any city or town in the UK, and your image and actions are recorded by hundreds of CCTV cameras, no permission is ever sort, and you have no idea who is watching you without your knowledge, yet this invasion of privacy is socially accepted.   Millions of people in the UK willingly give up their privacy on social networks, sharing almost every aspect of their private lives. This private information is commercially exploited through targeted advertising, this invasion of privacy is socially accepted. The same is true with smart phones where considerable user privacy is given up, just read Apple’s agreement and your mobile phone contract to see the extent, it goes well beyond personal details, phone calls and text messaging. These companies track the applications you use, the websites you browse and where you p...

Bullrun & Edgehill: US NSA & UK GCHQ have broken Internet Encryption

I have always suspected this and now according to newly leaked documents  by Edward Snowden, the NSA and GCHQ are said to have defeated most of the online encryption used by internet users and the likes of Microsoft, Google, Yahoo and even banks. The usage of supercomputers, court orders and the good old application of pressure to internet service providers, are all said to be tools used to gain access to encrypted data by the government agencies. "In recent years there has been an aggressive effort, lead by NSA, to make major improvements in defeating network security and privacy involving multiple sources and methods, all of which are extremely sensitive and fragile" "NSA has introduced the BULLRUN CoI to protect our abilities to defeat the encryption used in network communication technologies" The US programme name is Bullrun, and is said to have a £150m annual budget, while the UK GCHQ counterpart is called Edgehill. These codewords come from battles in ea...

PRISM, Meta Data & Minority Report: Why you should be conerned

Image
As the privacy debate continues to rage about PRISM, assurances are surfacing defending the US government agencies PRISM approach, namely the covert monitoring of all internet traffic. The arguments put forward are that "we need to have PRISM to combat terrorism", "you have no need to worry if your not a terrorist" and "don't worry its only meta data we keep".  How does PRISM combat terrorism? What is meta data? Should we really be concerned if we are not terrorists? The definition of meta data is, information about information, still not clear?  Let me explain with an example.  Take a phone call, the meta data is not the actual recording of the call, but is the information about the phone call, so who the call was made to, the length of the call, the date, time of day, and keywords spoken on the call (via voice recognition). This is an example of the meta data most likely kept. In an email monitoring context, the meta data is the recipien...

PRISM: How I would set up covertly monitor of a Country's Internet Traffic

Image
If I worked for a government intelligence agency, and I was tasked to devise a way to monitor the public Internet traffic data covertly, I would target the source of the Internet connectivity provision. The source of the internet connectivity resides within the telecommunications operators (telcos) e.g BT, Virgin Media. AT&T. Many telcos double as ISPs, but its the telcos who ultimately provide access to the Internet to ISPs. An advantage in monitoring at the source is  I don't need to tell or ask the permission to do so from a series of private companies, like Google, Facebook, Apple and Microsoft, as I can simply intercept and record all of the public's sent and received internet network traffic on route to these private companies. Typically teleco companies provide fast Internet connectivity to their clients (ISPs) over fibre optic cables. If I were to split the light signals sent over these fibre optics cables, I could allow traffic to continue on its merry way ...