Lawrence has the details. You can turn the damn stuff off. And oh by the way, they're getting sued over it.
Wednesday, November 19, 2025
Wednesday, October 8, 2025
Remember about all that Voice mail spam?
I posted about it a while back. Lawrence has been following this and has an update linking it to China:
Well, as suspected, it was China’s.
This was in fact my first thought: Smells like a State Actor.
Having thought about it, I suspect it is linked to the PRC, but "outsourced" to US-based Bad Guys. This seems a business (selling infrastructure to send out floods of voice mail spam). It looks like the guys who ran this also let people swat folks they didn't like. In fact, this is how they got caught because one of the victims was a Congressman.
And so a lack of Opsec led to compromise of the whole system. Cry me a river.
And Lawrence has a great suggestion:
If theses SIM farms are active, there should be ways for telecomms to algorithmically search for mobile call hotspots where too many calls issue from too small an area. Let’s hope they’re doing that and working with various U.S. three letter agencies to shut them down right now.
Endorsed.
Monday, August 25, 2025
SIGINT in World War II
The NSA and the UK GCHQ have jointly declassified a pile of WWII documents and actually produced a book:
Secret Messengers: Disseminating SIGINT in the Second World War.
If you are interested in Secret Squirrel stuff, this comes from Secret Squirrel Central.
(via)
Monday, August 11, 2025
When Tom Lehrer pranked NSA
Friday, June 6, 2025
A podcast recommendation
I know that some of you are former Secret Squirrel types, and a bunch more were (shall we say) Secret Squirrel adjacent. I just stumbled across a fairly new podcast called The Rest Is Classified. Really fun, and one of the guys is 100% Secret Squirrel. Former Company man, in fact.
You can get it on your favorite podcast site, or listen on Youtube. I thought that the series on Edward Snowden was very well done.
If this kind of thing was your background (heck, or just an interest) then I recommend this very highly indeed.
Tagged Burn Before Reading because that's kind of hilarious. I crack me up sometimes ...
Thursday, March 20, 2025
Security Cats and Dogs living together
The Surveillance State is bringing people together. In this case Apple (iOS) and Google (Android). You will now be able to send end-to-end encrypted messages from iPhones to Android devices and vice versa. It's kind of like what Signal and Telegram do.
You already have that capability with Apple devices sending to other Apple devices, and Android to Android. This new capability now makes it a big, happy, (more) secure world.
You will need to go into your device settings and enable Rich Communication Services (RCS) protocol. But yay for cross vendor cooperation and interoperability.
Wednesday, March 5, 2025
Tulsi Gabbard investigating UK.Gov's Apple crypto backdoor demand
Last week I posted about the Congressional request that DNI Gabbard look into the UK government's demand that Apple put an encryption backdoor into their products. She has done so:
In a written response to members of Congress, Gabbard said this week that such a demand would violate Americans’ rights and raise concerns about a foreign government pressuring a U.S.-based technology company.
“This would be a clear and egregious violation of Americans’ privacy and civil liberties,” Gabbard told Sen. Ron Wyden, D-Ore., and Rep. Andy Biggs, R-Ariz., who had written to express their worries.
...
Gabbard has asked the heads of the CIA and other U.S. intelligence agencies to study the U.K. demand and said she will discuss it with her British counterparts. She noted that existing agreements between the two nations prohibit either country from demanding cloud data about citizens or residents of the other.
This seems unprecedented to me - the relationship between the US and UK intelligence communities has been very close for literally decades - I have personal experience of this in the 1990s and it predates that by a lot.
Europe seems really intent on making all sorts of relationships worse.
Monday, March 3, 2025
The (Security) lamps are going out all across Europe
We shall not see them relit in our lifetimes:
Signal CEO Meredith Whittaker says her company will withdraw from countries that force messaging providers to allow law enforcement officials to access encrypted user data, as Sweden continues to mull such plans.
Whittaker said Signal intends to exit Sweden should its government amend existing legislation essentially mandating the end of end-to-end encryption (E2EE), an identical position it took as the UK considered its Online Safety Bill, which ultimately did pass with a controversial encryption-breaking clause, although it can only be invoked where technically feasible.
Basically the Sweden.Gov is asking Signal to get pregnant, but only a little bit pregnant. But vulnerabilities (and that's exactly what a government mandated encryption backdoor is) don't work that way.
And from the Department of Irony, the Swedish military oppose this:
The Swedish Armed Forces routinely use Signal and are opposing the bill, saying that a backdoor could introduce vulnerabilities that could be exploited by bad actors.I guess this is just Exhibit 14,543,928 that Europe is fundamentally unserious about their own defense.
This follows hard on the heels of Apple turning off encryption in the UK.
Looking at what's going on over there, it makes me think that maybe we should just cut the whole of them loose, to sink or swim on their own. Unwilling to defend themselves, increasingly despotic to their subjects at home, maybe JD Vance is right after all that we no longer have shared values.
Tuesday, February 25, 2025
Congress pushes back on UK snooping
Maybe there's something in the water in Washington D.C. these days, but this is clearly A Very Good Thing Indeed:
A bipartisan, bicameral pair of lawmakers urged newly confirmed Director of National Intelligence Tulsi Gabbard to reevaluate U.S. cybersecurity and intelligence-sharing relations with the United Kingdom in response to a report revealing that the UK secretly ordered Apple to build a backdoor into encrypted iCloud backups.
The Feb. 7 report from the Washington Post says that the order issued last month demands UK law enforcement and intelligence operatives be granted worldwide, unfettered access to users’ protected cloud data. Apple customers residing in the United States would be cast into that dragnet.
Sen. Ron Wyden, D-Ore., and Rep. Andy Biggs, R-Ariz., asked Gabbard in the Thursday missive if the Trump administration was made aware of the order by stakeholders and whether the White House has understanding of the CLOUD Act, which lets U.S. law enforcement get data stored by American tech companies, even if that data is on servers outside the U.S., by using warrants or subpoenas.
“If Apple is forced to build a backdoor in its products, that backdoor will end up in Americans’ phones, tablets, and computers, undermining the security of Americans’ data, as well as of the countless federal, state and local government agencies that entrust sensitive data to Apple products,” they wrote in their letter to Gabbard.
Remember, Encryption Backdoors are a Very Bad Idea. It's not just me saying this, it's the former Director of the UK's GCHQ (their NSA equivalent).
And well done to Congresscritters from both parties in both the House and Senate for putting some pressure on the idiots in Blimey.
Saturday, June 15, 2024
It's time to opt out of Windows Recall
Holy cow, what a nightmare:
Microsoft is not giving up on its controversial Windows Recall, though says it will give customers an option to opt in instead of having it on by default, and will beef up the security of any data the software stores.
Recall, for those who missed the dumpster fire, was announced on May 20 as a "feature" on forthcoming Copilot+ Windows PCs. It takes a snapshot of whatever is on the user's screen every few seconds. These images are stored on-device and analyzed locally by an AI model, using OCR to extract text from the screen, to make past work searchable and more accessible.
The ultimate goal for Recall is to record nearly everything the user does on their Windows PC, including conversations and app usage, as well as screenshots, and present that archive in a way that allows the user to remind themselves what they were doing at some point in the past and pull up relevant files and web pages to interact with again. The archive can be searched using text, or the user can drag a control along a timeline bar to recall activities.
But security testers have raised doubts about the safety of recorded information and have developed tools that can extract these snapshots and whatever sensitive information they contain. The data is for now stored as an easy to access non-encrypted SQLite database in the local file system.
"Dumpster fire" doesn't even begin to describe it. It's easy to imagine all sorts of ways that this would violate laws (e.g. storing healthcare PII unencrypted is a HIPAA violation).
Never mind what sort of reindeer games hackers might get up to - after all, Windows has historically been so difficult for viruses and malware to invade, amirite?
If you're still using Windows, you should configure it to opt out of Recall. Or upgrade to Linux. All the cool kids are.
Wednesday, May 15, 2024
Is the Signal secure messaging platform actually secure?
A competitor claims that it's not:
Telegram CEO Pavel Durov issued a scathing criticism of Signal, alleging the messaging service is not secure and has ties to US intelligence agencies.I'm not sure what to think here, other than the US Intelligence Community is doing no favors for US tech businesses, and hasn't for a long, long time. This sort of accusation will get some traction, whether it is true or not.
...
Durov made his remarks on his Telegram channel on Wednesday, pushing a variety of points against the rival messenger app, including alleging it has ongoing ties to the US government, casting doubt over its end-to-end encryption, and claiming a lack of software transparency, as well as describing Signal as "an allegedly "secure" messaging app.
...
The Register could not find public reports of Signal messages leaking due to faulty encryption. We also have reached out to the company and will update accordingly.
Thursday, April 18, 2024
Remember the FISA renewal vote?
You know, the one today? Guess what?
It's actually got new stuff in it - and you are now required to spy for Uncle Sam.
Yes, you. But fear not, Citizen: NSA no doubt will be responsible in how they use this.
Monday, March 4, 2024
Judge issues restraining order keeping DOE from tracking bitcoin miners
Earlier this month, the US Department of Energy (DOE) announced its intention to gather basic information about the energy consumed by bitcoin mining. In making the decision, the DOE noted that the share of bitcoin mining happening in the US has shot up by a factor of over 10 just within the last three years, leaving the activity consuming as much electricity as a fairly populous state....
Albright's decision to issue the injunction is based largely on the fact that the DOE's decision to delay going forward with the survey was voluntary and could be rescinded at any time.
But he went beyond that by saying that the mining companies were likely to succeed on the merits of their case. In general terms, he noted that the DOE relied on its ability to enact emergency measures, and those are only applicable if there's a risk of public harm. The DOE will likely try to make the case that elevated carbon emissions and electricity costs both count as public harms, so Albright is suggesting that he's unlikely to find those compelling.
Ah, Climate Change. Is there anything it can't do? Except in west Texas, where the Judge doesn't buy the whole "Climate Emergency means more Government" thing.
Wednesday, January 3, 2024
So which stores use facial recognition technology to track you when you shop there?
Interesting. There are a lot of surprises on this list, both stores I expected to use this tech who say they won't, and stores I expected not to who do.
(via)
Thursday, December 21, 2023
Big Pharmacy chains turn over medical into to police without warants
Hey, you can trust the Government, right?
All of the big pharmacy chains in the US hand over sensitive medical records to law enforcement without a warrant—and some will do so without even running the requests by a legal professional, according to a congressional investigation.
...
They include the seven largest pharmacy chains in the country: CVS Health, Walgreens Boots Alliance, Cigna, Optum Rx, Walmart Stores, Inc., The Kroger Company, and Rite Aid Corporation. The lawmakers also spoke with Amazon Pharmacy.
All eight of the pharmacies said they do not require law enforcement to have a warrant prior to sharing private and sensitive medical records, which can include the prescription drugs a person used or uses and their medical conditions. Instead, all the pharmacies hand over such information with nothing more than a subpoena, which can be issued by government agencies and does not require review or approval by a judge.
This sure seems like a violation of HIPAA, not to mention that pesky Fourth Amendment.
(via)
Saturday, September 30, 2023
Signal to leave UK rather than backdoor their crypto
Onstage at TechCrunch Disrupt 2023, Meredith Whittaker, the president of the Signal Foundation, which maintains the nonprofit Signal messaging app, reaffirmed that Signal would leave the U.K. if the country’s recently passed Online Safety Bill forced Signal to build “backdoors” into its end-to-end encryption.
“We would leave the U.K. or any jurisdiction if it came down to the choice between backdooring our encryption and betraying the people who count on us for privacy, or leaving,” Whittaker said. “And that’s never not true.”
The Online Safety Bill, which was passed into law in September, includes a clause — clause 122 — that, depending on how it’s interpreted, could allow the U.K.’s communications regulator, Ofcom, to break the encryption of apps and services under the guise of making sure illegal material such as child sexual exploitation and abuse content is removed.
"Child sexual exploitation". Oooooh kaaaaay. No doubt the UK.Gov is very concerned indeed at getting access to Prince Andrew's communications with Jeffery Epstein. Or something.
(via)
Tuesday, September 12, 2023
Data privacy in cars is basically non-existent
This is not surprising, but a systematic analysis from the Mozilla Foundation shows that no car company takes data privacy seriously - and Tesla tops the list of shame by having serious shortfalls in each of the five key privacy areas. Most of the other big names (Ford, Mercedes, BMW, the GM stable) have issues on four.
Here are some highlights:
Some not-so-fun facts about these rankings:
- Tesla is only the second product we have ever reviewed to receive all of our privacy “dings.” (The first was an AI chatbot we reviewed earlier this year.) What set them apart was earning the “untrustworthy AI” ding. The brand’s AI-powered autopilot was reportedly involved in 17 deaths and 736 crashes and is currently the subject of multiple government investigations.
- Nissan earned its second-to-last spot for collecting some of the creepiest categories of data we have ever seen. It’s worth reading the review in full, but you should know it includes your “sexual activity.” Not to be out done, Kia also mentions they can collect information about your “sex life” in their privacy policy. Oh, and six car companies say they can collect your “genetic information” or “genetic characteristics.” Yes, reading car privacy policies is a scary endeavor.
- None of the car brands use language that meets Mozilla’s privacy standard about sharing information with the government or law enforcement, but Hyundai goes above and beyond. In their privacy policy, it says they will comply with “lawful requests, whether formal or informal.” That’s a serious red flag.
- All of the car brands on this list except for Tesla, Renault, and Dacia signed on to a list of Consumer Protection Principles from the US automotive industry group ALLIANCE FOR AUTOMOTIVE INNOVATION, INC. The list includes great privacy-preserving principles such as “data minimization,” “transparency,” and “choice.” But the number of car brands that follow these principles? Zero. It’s interesting if only because it means the car companies do clearly know what they should be doing to respect your privacy even though they absolutely don’t do it.
So what do you do when choosing a new ride? Some ideas come to mind ...
(via)
Thursday, August 31, 2023
For Sale: NASA Security Van
Low mileage. Serious inquiries only.
Extra bonus points if you install a WiFi router and set the SSID to "NSA Surveillance Van 117" ...
(via)
Thursday, August 17, 2023
Zoom reserves the right to spy on your calls
Their new Terms Of Service say that they have the right to listen in on your calls and use them to train their AI. Their execs say that they'd never do that, honest you guys.
Allrightee, then.
(source)
Friday, July 28, 2023
TETRA Police Radios have a cryptographic backdoor
Most interestingly is the researchers’ findings of what they describe as the backdoor in TEA1. Ordinarily, radios using TEA1 used a key of 80-bits. But Wetzels said the team found a “secret reduction step” which dramatically lowers the amount of entropy the initial key offered. An attacker who followed this step would then be able to decrypt intercepted traffic with consumer-level hardware and a cheap software defined radio dongle.
Looks like the encryption algorithm was intentionally weakened by intelligence agencies to facilitate easy eavesdropping.
There's an old saying that while there may be friendly foreign governments, there are no friendly foreign Intelligence Agencies. Or domestic ones either, seemingly.
Even if you're a LEO. Note that this makes secure police communications problematic. Not cool.
