Saturday, October 12, 2013

Investigation launched in Luxembourg over Skype’s links to NSA surveillance programs

(Image credit: Mark McLaughlin/Flickr)

The data protection commissioner in Luxembourg has launched an investigation into Skype’s covert involvement with surveillance programs run by the National Security Agency (NSA), according to a report Friday.

The link between the NSA and Skype is hardly secret at this point, especially given the exposure of “Project Chess,” the secret program aimed at making Skype calls easily available to intelligence agencies.

Furthermore, in early June it was revealed that Skype was one of the partners working with the NSA on their massive Prism program.

Skype, owned by Microsoft, could face both administrative and criminal sanctions, including a ban on secretly passing any user communications to US intelligence agencies, the Guardian reports.

If the investigation finds that Skype’s data sharing is found to violate Luxembourg’s data protection laws, the company, headquartered in the European country, could also be fined.

The Guardian reports that this investigation, launched by Gerard Lommel, apparently began in June after Skype’s ties to NSA surveillance were revealed.

In Luxembourg, communications can only be monitored with judicial approval or authorization of a tribunal established by the prime minister.

As the Guardian notes, “it is unclear whether Skype’s transfer of communications to the NSA have been sanctioned by Luxembourg through a secret legal assistance or data transfer agreement that would not be known to the data protection commissioner at the start of their inquiry.”

Indeed, some European countries, including Germany, have worked closely with the NSA on their surveillance program despite data protection laws.

This led to the German interior minister advising people to avoid using Google and Facebook if they’re concerned about NSA spying.

As the Guardian reported in July, after Skype was acquired by Microsoft, “the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism.”

“It is what many of us feared, and now we know for sure,” GrĂ©goire Pouget, an information security expert with Reporters Without Borders, said to the Guardian.

“If you are a journalist working on issues that could interest the US government or some of their allies, you should not use Skype,” Pouget said.

When a Microsoft representative spoke to VentureBeat, they suggested that the investigation in Luxembourg may stem from complaints filed by Europe v. Facebook, which I reported on in June.

“We regularly engage in a dialogue with data protection authorities around the world and are always happy to answer their questions,” the Microsoft representative said to VentureBeat.

“It has been previously widely reported that the Luxembourg [data protection authority] was one of the [data protection authorities] that received complaints from the Europe v. Facebook group, so we’re happy to answer any questions they may have,” the representative added.

Interestingly, the Guardian reported that Microsoft would not respond for comment.

The data protection commissioner’s office in Luxembourg did not respond to either VentureBeat or the Guardian for comment.

Source:End the Lie

Friday, October 11, 2013

Google Tells Feds It Wants to Disclose Surveillance Orders

Google, Microsoft, Facebook, Yahoo and LinkedIn are ramping up efforts in Congress and the Foreign Intelligence Surveillance Act court to win authority to publish figures about data-collection orders received from the feds. However, the Justice Department says that would undermine the intelligence community.

CIO

surveillance

Google, one of the tech companies at the heart of the public-private friction over government requests for commercial data related to national security, is planning to step up its efforts to win the authority to make public disclosures about the scope of those surveillance orders.

That campaign will play out on two fronts, according to David Lieber, a privacy policy counsel with Google.

In Congress, the search giant is backing bills introduced by Al Franken (D-Minn.) in the Senate and, in the House, by Zoe Lofgren (D-Calif.) that would authorize (but not require) companies to release aggregate statistics describing the number of national security orders they have received in a given time period and how many users have been impacted.

"We've been supportive of that legislation, along with a number of other companies, trade associations and civil society groups. And we're looking forward to a broader campaign to codify the principles that are reflected in those bills," Lieber said this week at an event hosted by the Cato Institute, a libertarian think tank.

Lieber says that those bills "advance bedrock First Amendment principles" involving disclosures that, under normal circumstances, would require no special action for companies to make. But the Justice Department and national security authorities have pushed back against the efforts of tech firms like Google, Microsoft, Facebook and Yahoo to publish aggregate data about the volume and scope of national security orders issued under the Foreign Intelligence Surveillance Act.

"If these leading Internet companies are permitted to make these disclosures, the harm to national security would be compounded by the fact that other companies would surely seek to make similar disclosures."
--Department of Justice

Those four companies, joined by LinkedIn, have taken their case to the FISA court, or FISC, where they are seeking a declaratory judgment that would permit them to disclose figures about the data requests they receive under each section of the law, further parsing the numbers by delineating "content" and "non-content" requests.

In a response filed with the FISC Sept. 30 arguing against the tech firms' motion, the Justice Department cited reforms the government has taken in the interest of greater transparency, including granting permission for companies to publish aggregate figures about how many administrative subpoenas (known as national security letters) they receive from federal authorities, as well as a commitment to report the total number of orders -- broadly defined to include FISA actions and national security letters -- issued each year.

Source: CIO

Thursday, October 10, 2013

The U.S. Military Is Creating Iron Men, Super Soldiers And Terminator Robots To Fight Future Wars



The wars of the future are very likely going to resemble many of the science fiction movies that we are watching right now.   The U.S. military is in a global race to create the “technologies of the future”, and some of the things that they are coming up with are disturbing to say the least.

Are you ready for future conflicts where “Iron Men”, “super soldiers”, “Terminator robots”, and autonomous drones do most of the killing?  Are you ready for American soldiers that have been genetically modified to perform superhuman feats of strength, run at superhuman speeds and even regrow limbs?

The truth is that all of this stuff is being developed right now and most Americans have no idea that it is happening.

Have you enjoyed watching the Iron Man movies that have come out in recent years?  Tens of millions of Americans have flocked to see those films, and now they are being used as inspiration to create a new generation of “exoskeletons” for U.S. soldiers.

In fact, it is being reported that this revolutionary new “smart armor” was specifically “inspired by Tony Stark’s legendary nano suit used in the Iron Man movie series“.  This armor is currently being developed at MIT, and according to the BBC this armor will give U.S. troops “superhuman strength”…
The US Army is working to develop “revolutionary” smart armour that would give its troops “superhuman strength”.
It is calling on the technology industry, government labs and academia to help build the Iron Man-style suit.
Other exoskeletons that allow soldiers to carry large loads much further have already been tested by the army.
The Tactical Assault Light Operator Suit (Talos) would have such a frame but would also have layers of smart materials fitted with sensors.
The suit would also need to have wide-area networking and a wearable computer similar to Google Glass, the US Army said.

Most people would not object to high tech armor for the military, but what about genetically modifying soldiers themselves?

That is an entirely different thing altogether.

In a previous article, I included a quote from a Daily Mail article that discussed how DARPA is now working on ways to create “super soldiers” that will be able to run at Olympic speeds and regrow limbs that have been blown off…
Tomorrow’s soldiers could be able to run at Olympic speeds and will be able to go for days without food or sleep, if new research into gene manipulation is successful. 
According to the U.S. Army’s plans for the future, their soldiers will be able to carry huge weights, live off their fat stores for extended periods and even regrow limbs blown apart by bombs.
The plans were revealed by novelist Simon Conway, who was granted behind-the-scenes access to the Pentagon’s high-tech Defence Advanced Research Projects Agency.
How in the world could those things possibly be accomplished?

Through genetic modification of course.

A different Daily Mail article explained how this might work
Most gene modification techniques involve placing genetically modified DNA inside a virus and injecting it into the human body. The virus then enters human cells, and its modified DNA attaches itself to the human DNA inside those cells.
But should we really be using viruses to modify the DNA of our soldiers?

Should we really be modifying the DNA of anyone?

Of course not.

This is very dangerous territory.  Just because we now have the ability to “play God” and alter human DNA does not mean that we should.  If our scientists are not careful, they could end up creating monsters far beyond what anyone could imagine right now.  And once Pandora’s Box is opened and these super soldiers start spreading their DNA around, it simply will not be possible to put the genie back into the bottle.

Another area where the U.S. military is pushing boundaries is in the field of robotics.  For example, Northrop Grumman has developed a 1 1/2-ton unmanned killing machine that is known as MADSS
The MADSS is one mean robot. Developed by defense industry leader Northrop Grumman and currently being showcased at the Fort Benning, Ga. “Robotics Rodeo,” the MADSS is a 1 1/2-ton unmanned ground vehicle designed to provide soldiers with covering fire while cutting down targets.
Make no mistake, it’s an automatic shooting machine, But it requires people to operate it and set targets. The MADSS — Mobile Armed Dismount Support System — tracks and fires on targets only once it gets the green light. It won’t shoot unless a soldier is directing it.
It’s half killer robot, half killer giant remote-control car. While its top speed hasn’t been stated, Northrop Grumman has said that it can follow troops on foot at about five miles an hour over rough terrain that conventional combat vehicles would find impassable.
But a remote control vehicle is one thing.

A “Terminator-like Atlas robot” is another.

Right now, Boston Dynamics is working on a 330 pound humanoid robot that looks like something out of a bad science fiction movie…
Finally, there’s fresh footage of Boston Dynamics’ Terminator-like Atlas robot, which was unveiled earlier this year. The 6-foot, 330-pound humanoid, which may or may not be a future robot infantryman, is designed to use tools and walk over rough terrain. 
Check it out stomping over several boxes of rocks like nobody’s business, and then standing on one foot while being hit with a swinging weight.
Of course, it laughs on the inside at these pathetic human challenges.
You can view Atlas in action right here



And personally, I think that the very human-looking robot known as “Petman” is even creepier.
You can see “Petman” in action right here…



As long as humans are controlling this kind of technology, at least there are some safety checks.
But what if we started creating killing machines that made their own decisions?

That sounds crazy, but according to a recent National Journal article that is exactly what is being developed.  As you read this, scientists are working on ways to enable drones “to make even lethal decisions autonomously”…
Scientists, engineers and policymakers are all figuring out ways drones can be used better and more smartly, more precise and less damaging to civilians, with longer range and better staying power. One method under development is by increasing autonomy on the drone itself.
Eventually, drones may have the technical ability to make even lethal decisions autonomously: to respond to a programmed set of inputs, select a target and fire their weapons without a human reviewing or checking the result. Yet the idea of the U.S. military deploying a lethal autonomous robot, or LAR, is sparking controversy. Though autonomy might address some of the current downsides of how drones are used, they introduce new downsides policymakers are only just learning to grapple with.
The basic conceit behind a LAR is that it can outperform and outthink a human operator. “If a drone’s system is sophisticated enough, it could be less emotional, more selective and able to provide force in a way that achieves a tactical objective with the least harm,” said Purdue University Professor Samuel Liles. “A lethal autonomous robot can aim better, target better, select better, and in general be a better asset with the linked ISR [intelligence, surveillance, and reconnaissance] packages it can run.”
Would you be comfortable with unmanned drones flying over your neighborhood that are able to decide on their own whether to kill you or not?

I certainly would not be.

This kind of reminds me of the killer drones in the new movie Oblivion that Tom Cruise starred in.  I certainly would never want such technology being used to patrol the streets of America.

And what if we lose control over this kind of technology once it becomes widespread someday?

In the past, such notions where laughable.  They were used as plots for bad science fiction movies and that was about it.

But now we are moving into a time when science fiction is becoming science reality.

Are you ready for that?

Source: Activist Post

GMOs & Neurological Disease: ADHD, Autism, Alzheimer’s, Schizophrenia, Bipolar

Nervous_system_diagram

The Human Nervous System

N.L. Swanson

Acknowledgment: Jon Abrahamson helped with data mining for this article.

The endocrine disrupting properties of glyphosate can lead to neurological disorders (learning disabilities (LD), attention deficit hyperactive disorder (ADHD), autism, dementia, Alzheimer’s, schizophrenia and bipolar disorder). Those most susceptible are children and the elderly.

Glyphosate was first marketed in 1976 and its use has exploded since the advent of glyphosateresistant, genetically engineered (GE) crops in 1995. The herbicide-resistant GE crops absorb glyphosate through direct application and from the soil and it cannot be washed off. It is in the food. Glyphosate has also been found in rivers, streams, air and rain.

The thyroid is an endocrine organ that secretes the thyroid hormone. Thyroid dysfunction has been identified with mood disorders. Depression is frequently associated with low levels of thyroid hormone (hypothyroidism), while mood elevation is often associated with high levels of thyroid hormone (hyperthyroidism). An endocrine disrupting chemical (EDC) can cause erratic behavior. Recent studies have shown links between food additives and neurotoxicity in cells and hyperactive behavior in children. Incidents have been reported of laboratory rats and farm animals exhibiting uncharacteristic aggressive and anti-social behavior on being fed a diet consisting of GMO soy or corn.

Many scientific studies have shown links between thyroid disruption and neurological diseases. “Thyroid hormones are critical for development of the fetal and neonatal brain, as well as for many other aspects of pregnancy and fetal growth. Hypothyroidism in either the mother or fetus frequently results in fetal disease; in humans, this includes a high incidence of mental retardation. … numerous studies with rats, sheep and humans have reinforced this concept…” According to de Cock et al, “Perinatal exposure to EDCs appears to be associated with the occurrence of ASD [autism spectrum disorder] as well as ADHD. Disruption of thyroid hormone function … may offer an explanation for the observed relations….” MacSweeney et al. report, “that the mothers of 104 schizophrenic patients had: (1) a significantly higher incidence of thyroid disease than a carefully matched control group; (2) significantly more abortions, still-births and greater infant mortality. The findings and possible relevance of thyroid disease to schizophrenia are discussed.” Strong correlation was shown between cancer of the thyroid and glyphosate use on corn and soy crops and that thyroid cancer affects women more than men. It seems that women are more sensitive to thyroid disruption.

The incidence and prevalence for neurological disorders have been skyrocketing. Data trends over time for neurological disorders are not readily available for two reasons: they are not as well-studied as other diseases (cancer, diabetes etc.), and the diagnostic methods keep changing. The experts argue over whether the increases are real, or a by-product of changes in diagnostics along with greater attention given to these disorders in recent times. For example, a former diagnosis of mental retardation might now result in a diagnosis of autism. Furthermore there is a large degree of overlap in symptoms. Typical manifestations of ADHD, such as distractibility or hyperactivity are also present in pediatric bipolar disorder, for example.

Children

ADHD

According to the New York Times, “an estimated 6.4 million children ages 4 through 17 had received an A.D.H.D. diagnosis at some point in their lives, a 16 percent increase since 2007 and a 41 percent rise in the past decade.” From the Center for Disease Control (CDC), “rates of ADHD diagnosis increased an average of 3% per year from 1997 to 2006 and an average of 5.5% per year from 2003 to 2007. … It is not possible to tell whether this increase represents a change in the number of children who have ADHD, or a change in the number of children who were diagnosed.” It alsomakes a great deal of difference who is doing the reporting: parents or doctors. The disorder affects boys more than girls. Whatever the numbers, there seems to be an increasing behavioral problem with our youth. Our solution is to give them more chemicals in the form of mood-altering drugs.

Bipolar

According to a 2007 report by Moreno et al., “the annual number of office-based visits with a diagnosis of bipolar disorder was estimated to increase in youth from 25 (1994-1995) to 1003 (2002-2003) per 100,000 population, whereas in adults it increased from 905 (1994-1995) to 1679 (2002-2003) per 100,000 population. … most youth bipolar disorder visits were by males (66.5%), whereas most adult bipolar disorder visits were by females (67.6%).”

Autism

The number of autistic children has exploded during the last decade, and some are calling it an epidemic. There is great controversy over what is causing this and whether all of it is real. “But many researchers now say that at least part of the rise in autism is real and caused by something in the environment. Rather than quibbling over recounts they are focusing on finding the causes.”

It was shown in previous articles that there has been a huge increase in the amount of glyphosates applied to corn and soy crops grown in the U.S. corresponding to the rise in the percentage of corn and soy planted with genetically engineered (GE) varieties. Those data represent only a portion of the total GE crops and amount of glyphosates applied. The USDA only collects data on GE crops for corn, cotton and soy. Since most of the corn (88%) and soy (94%) planted now is GE, these data give a representation of the rising trends in both GE crops and herbicide use.

The amount of glyphosate applied to U.S. corn and soy crops is plotted against the prevalence of autism in the graph below. The prevalence of autism was difficult to find and the values shown on this graph came from many sources using different methods and different age groups. A better estimate was obtained from the U.S. Department of Education, which keeps track of school age children receiving services under the Individuals with Disabilities Education Act (IDEA). A second plot is shown using data from USDE for the number of autistic children receiving services. The correlation is quite strong which may indicate that glyphosate is a contributing factor in the rise of autism

ND1

ND2

Elderly

The elderly are susceptible because they may already have a great body burden of chemical exposure over their lifetime and because some of their body processes are shutting down and hormonal disruptions can have a much greater effect on them.

According to the University of Washington Institute for Health Metrics and Evaluation, Alzheimer’s disease went from number 32 in 1990 to number nine in 2010 in the ranking of leading causes of death in the U.S. Senile Dementia and it’s care costs have also skyrocketed in the last two decades.

Prevalence and incidence data were sparse, but data on death rates were available from 1979. Graphs of the death rates for Alzheimer’s, Parkinson’s disease and Senile Dementia have been plotted against glyphosate applications to U.S. corn and soy crops. Again, the correlations are quite strong. Deaths due to Alzheimer’s have been rising since 1980, but there is a sharp spike in 1999.

Correlation does not necessarily imply causation and there are now a host of chemicals in our food and our environment. The huge increase in the amount of glyphosate applied to GE food and feed crops has significantly increased our exposure to endocrine disrupting chemicals. In a previous article, correlations were shown between glyphosate use, GMO crop increase and: thyroid cancer, liver cancer, obesity, high blood pressure, acute kidney injury, incidence and prevalence of diabetes and end stage renal disease. All of these diseases and disorders were carefully chosen based on:

1 Glyphosate is a known endocrine disruptor.

2. Endocrine disruptors can cause organ and neurological damage.

3. Roundup™ and GMOs have shown liver and kidney damage and abnormal behavior in rat studies.

4. Use of glyphosate on herbicide-resistant crops has skyrocketed since 1995.

5. Incidence, prevalence and deaths due to these diseases has also skyrocketed since 1995.

It seems improbable that the correlations in the nine graphs of glyphosates and organ disease, and the three presented here (for a total of 12), can all be coincidence. There has been a trend among the agricultural and food industries and their regulators to engage in practices that place the consumers at risk, emerging in the mid-1990s and growing. It involves not just GMOs but many other things as well and those factors may may be correlated with each other. That may make it impossible to separate out which one caused a particular effect. Much more research needs to be done. Our children are disturbed and our elders are dying horribly.

ND3

ND4

ND5

Notes:

In 2006 Irena Ermakova reported to the European Congress of Psychiatry that, “As in previous series the behavior of males from GM group was compared with the behavior of control rats. Obtained data showed a high level of anxiety and aggression in males, females and young pups from GM groups. Aggression was more expressed in females and rat pups: they attacked and bite each other and the worker.” 14th European Congress of Psychiatry, Nice, France, Sunday, March 5 2006, Poster #048.

Numerous anecdotal reports of animals on GMO diets behaving aggressively and anti-socially have been reported by farmers and veterinarians.

In 2010 Shelton et al. published a paper describing potential mechanisms linking pesticides and autism.

In 2006, Grandjean and Landrigan reported on developmental neurotoxicity of industrial chemicals. “Neurodevelopmental disorders such as autism, attention deficit disorder, mental retardation, and cerebral palsy are common, costly, and can cause lifelong disability. … Exposure to these chemicals during early fetal development can cause brain injury at doses much lower than those affecting adult brain function.”

Data sources:

Alzheimer’s & Senile Dementia death data : CDC compressed mortality files

Autism prevalence: CDC: 1975* & 1995* from NAT U R E | VO L 4 7 9 | 3 NOV E M B E R 2 0 1 1

Autism IDEA data: 1992-1998

1999-2010 http://nces.ed.gov/FastFacts/display.asp?id=64

U.S. Dept. of Education, National Center for Education Statistics (2012). Digest of Education Statistics, 2011 (NCES 2012-001), Chapter 2.

Glyphosate: USDA:NASS National Agricultural Statistics Service (NASS)

Percent GE corn & soy data: 1996-1999 data: USDA Agricultural Economic Report No. (AER-810) 67 pp, May 2002

2000-2012 data: USDA:NASS National Agricultural Statistics Service

Source: Farm Wars

Wednesday, October 9, 2013

Cyborg Cockroach Sparks Ethics Debate

 

At the TEDx conference in Detroit last week, RoboRoach #12 scuttled across the exhibition floor, pursued not by an exterminator but by a gaggle of fascinated onlookers. Wearing a tiny backpack of microelectronics on its shell, the cockroach—a member of the Blaptica dubia species—zigzagged along the corridor in a twitchy fashion, its direction controlled by the brush of a finger against an iPhone touch screen (as seen in video above).

RoboRoach #12 and its brethren are billed as a do-it-yourself neuroscience experiment that allows students to create their own “cyborg” insects. The roach was the main feature of the TEDx talk by Greg Gage and Tim Marzullo, co-founders of an educational company called Backyard Brains. After a summer Kickstarter campaign raised enough money to let them hone their insect creation, the pair used the Detroit presentation to show it off and announce that starting in November, the company will, for $99, begin shipping live cockroaches across the nation, accompanied by a microelectronic hardware and surgical kits geared toward students as young as 10 years old.

That news, however, hasn’t been greeted warmly by everyone. Gage and Marzullo, both trained as neuroscientists and engineers, say that the purpose of the project is to spur a “neuro-revolution” by inspiring more kids to join the fields when they grow up, but some critics say the project is sending the wrong message. "They encourage amateurs to operate invasively on living organisms" and "encourage thinking of complex living organisms as mere machines or tools," says Michael Allen Fox, a professor of philosophy at Queen's University in Kingston, Canada.

“It’s kind of weird to control via your smartphone a living organism,” says William Newman, a presenter at TEDx and managing principal at the Newport Consulting Group, who got to play with a RoboRoach at the conference. At the same time, he says, he is pleased that the project will teach students about the neuroscience behind brain stimulation treatments that are being used to treat two of his friends with Parkinson’s disease.

The roaches’ movements to the right or left are controlled by electrodes that feed into their antennae and receive signals by remote control—via the Bluetooth signals emitted by smartphones. To attach the device to the insect, students are instructed to douse the insect in ice water to “anesthetize” it, sand a patch of shell on its head so that the superglue and electrodes will stick, and then insert a groundwire into the insect’s thorax. Next, they must carefully trim the insect’s antennae, and insert silver electrodes into them. Ultimately, these wires receive electrical impulses from a circuit affixed to the insect’s back.

Gage says the roaches feel little pain from the stimulation, to which they quickly adapt. But the notion that the insects aren’t seriously harmed by having body parts cut off is “disingenuous,” says animal behavior scientist Jonathan Balcombe of the Humane Society University in Washington, D.C. “If it was discovered that a teacher was having students use magnifying glasses to burn ants and then look at their tissue, how would people react?”

Gage says that in his experience, working carefully and closely with insects and other animals in experiments can sensitize students to the fact that roaches “are actually similar to us and have the same neurons that we have.” He also notes that the company doesn’t kill their own roaches after the experiments, but sends them to a “retirement” tank that the team calls Shady Acres. Although they may be missing legs or antennae, the insects tend to get on with their lives after the experiments, he says. “They do what they like to do: make babies, eat, and poop.”

“I try not to downplay the fact that in science we use animal models and a lot of times they are killed,” Gage says. “As scientists, we do this all the time, but it happens behind closed doors.” By following the surgical instructions, he says, all students learn that they have to care for the roaches—treating wounds by “putting a little Vaseline” on them, and minimizing suffering whenever possible. Still, Gage acknowledges, “we get a lot of e-mails telling us we’re teaching kids to be psychopaths.”

The RoboRoach “gives you a way of playing with living things,” like a short-lived version of the forbidden “Imperius Curse” in the Harry Potter novels, says bioethicist Gregory Kaebnick of the Hastings Center in Garrison, New York. He finds the product “unpleasant,” but adds that he won’t be calling for a boycott, either. “I’ll just be happy that I found a cleverly marketed consumer item that I am very happy not to own.”

Source: Science Mag

How The NSA Deploys Malware: An In-Depth Look at the New Revelations

We've long suspected that the NSA, the world's premiere spy agency, was pretty good at breaking into computers. But now, thanks to an article by security expert Bruce Schneier—who is working with the Guardian to go through the Snowden documents—we have a much more detailed view of how the NSA uses exploits in order to infect the computers of targeted users. The template for attacking people with malware used by the NSA is in widespread use by criminals and fraudsters, as well as foreign intelligence agencies, so it's important to understand and defend against this threat to avoid being a victim to the plethora of attackers out there.

How Does Malware Work Exactly?

Deploying malware over the web generally involves two steps. First, as an attacker, you have to get your victim to visit a website under your control. Second, you have to get software—known as malware—installed on the victim's computer in order to gain control of that machine. This formula isn't universal, but is often how web-based malware attacks proceed.

In order to accomplish the first step of getting a user to visit a site under your control, an attacker might email the victim text that contains a link to the website in question, in a so-called phishing attack. The NSA reportedly uses phishing attacks sometimes, but we've learned that this step usually proceeds via a so-called “man-in-the-middle” attack.1 The NSA controls a set of servers codenamed “Quantum” that sit on the Internet backbone, and these servers are used to redirect targets away from their intended destinations to still other NSA-controlled servers that are responsible for the injection of malware. So, for example, if a targeted user visits “yahoo.com”, the target's browser will display the ordinary Yahoo! landing page but will actually be communicating with a server controlled by the NSA. This malicious version of Yahoo!'s website will tell the victim's browser to make a request in a background to another server controlled by the NSA which is used to deploy malware.

Once a victim visits a malicious website, how does the attacker actually infect the computer? Perhaps the most straightforward method is to trick the user into downloading and running software. A cleverly designed pop-up advertisement may convince a user to download and install the attacker's malware, for example.

But this method does not always work, and relies on a user taking action to download and run software. Instead, attackers can exploit software vulnerabilities in the browser that the victim is using in order to gain access to her computer. When a victim's browser loads a website, the software has to perform tasks like parsing text given to it by the server, and will often load browser plugins like Flash that run code given to it by the server, in addition to executing Javascript code given to it by the server. But browser software—which is becoming increasingly complex as the web gains more functionality—doesn't work perfectly. Like all software, it has bugs, and sometimes those bugs are exploitable security vulnerabilities that allow an attacker to gain access to a victim's computer just because a particular website was visited. Once browser vendors discover vulnerabilities, they are generally patched, but sometimes a user has out of date software that is still vulnerable to known attack. Other times, the vulnerabilities are known only to the attacker and not to the browser vendor; these are called zero-day vulnerabilities.

The NSA has a set of servers on the public Internet with the code name “FoxAcid” used to deploy malware. Once their Quantum servers redirect targets to a specially crafted URL hosted on a FoxAcid server, software on that FoxAcid server selects from a toolkit of exploits in order to gain access to the user's computer. Presumably this toolkit has both known public exploits that rely on a user's software being out of date, as well as zero-day exploits which are generally saved for high value targets.2 The agency then reportedly uses this initial malware to install longer lasting malware.

Once an attacker has successfully infected a victim with malware, the attacker generally has full access to the user's machines: she can record key strokes (which will reveal passwords and other sensitive information), turn on a web cam, or read any data on the victim's computer.

What Can Users Do To Protect Themselves?

We hope that these revelations spur browser vendors to action, both to harden their systems against exploits, and to attempt to detect and block the malware URLs used by the FoxAcid servers.

In the meantime, users concerned about their security should practice good security hygiene. Always keep your software up to date—especially browser plugins like Flash that require manual updates. Make sure you can distinguish between legitimate updates and pop-up ads that masquerade as software updates. Never click a suspicious looking link in an email.

For users who want to go an extra step towards being more secure—and we think everyone should be in this camp—consider making plugins like Flash and Java “click-to-play” so that they are not executed on any given web page until you affirmatively click them. For Chromium and Chrome, this option is available in Settings => Show Advanced Settings => Privacy => Content Settings => Plug-ins. For Firefox, this functionality is available by installing a browser Add-On like “Click to Play per-element”. Plugins can also be uninstalled or turned off completely. Users should also use ad blocking software to stop unnecessary web requests to third party advertisers and web trackers, and our HTTPS Everywhere add-on in order to encrypt connections to websites with HTTPS as much as possible.

Finally, for users who are willing to notice some more pain when browsing the web, consider using an add-on like NotScripts (Chrome) or NoScript (Firefox) to limit the execution of scripts. This means you will have to click to allow scripts to run, and since Javascript is very prevalent, you will have to click a lot. For Firefox users, RequestPolicy is another useful add-on that stops third-party resources from loading on a page by default. Once again, as third-party resources are popular, this will disrupt ordinary browsing a fair amount. Finally, for the ultra paranoid, HTTP Nowhere will disable all HTTP traffic completely, forcing your browsing experience to be entirely encrypted, and making it so that only websites that offer an HTTPS connection are available to browse.

Conclusion

The NSA's system for deploying malware isn't particularly novel, but getting some insight into how it works should help users and browser and software vendors better defend against these types of attacks, making us all safer against criminals, foreign intelligence agencies, and a host of attackers. That's why we think it's critical that the NSA come clean about its capabilities and where the common security holes areour online security depends on it.

Source: EFF

Monday, October 7, 2013

Widely Popular Nanoparticles Could Be Giving You Cancer, Nutritional Deficiencies

labchemical 210x131 Widely Popular Nanoparticles Could Be Giving You Cancer, Nutritional Deficiencies

There is a bit of controversy revolving around nanoparticles, which involve the manipulation of elements as well as other matter on an atomic and molecular scale. Found in consumer products, many foods, and in pharmaceutical drugs, nanoparticles are increasingly being found in more products every year. Many people assume nanoparticles are safe, but they have actually been shown to pose a threat to your health.

Nanoparticles Shown to be Dangerous, Block Nutrient Absorption

According to the Project on Emerging Nanotechnologies (PEN), over 1,300 manufacturer nanotechnology-enabled products are in the global commercial marketplace. Nanoparticles can be found in car batteries, appliances, aluminum foil, non-stick cookware, and is especially present in health and fitness items. PEN Director David Rejeski states:

“The use of nanotechnology in consumer products continues to grow on a rapid and consistent basis…when we launched the inventory in March 2006 it contained 212 products. If the current trend continues, the number of products could reach 3,400 by 2020.”

Nanotechnology is much like organism-based biotechnology, where even supporters of the technologies know there needs to be more long term testing to determine safety. Genetically modified foods have already been shown to cause numerous health and environmental complications, but they continue to be pushed. Similarly, nanotechnology is believed by some to be the ‘next industrial revolution’, but like genetically modified foods, it has never been proven totally safe for use or consumption.

A recent study published in the journal Nature titled “Oral exposure to polystyrene nanoparticles affects iron absorption” examined chickens fed a diet which included polystyrene nanoparticles. Researchers found that intestinal changes affecting iron absorption occurred due to the polystyrene nanoparticles. They also expect to see an alteration in absorption of calcium, copper, zinc, and vitamins A, D, E, and K.

Another study conducted in 2004 found that nanoparticles cause brain damage in fish and other aquatic species.

In addition, Oxford University and Montreal University in 1997 linked titanium dioxide and zinc oxide nanoparticles in sunscreen to free radical and DNA damage. But still, even in 2011, the U.S. Food and Drug Administration declined to put any warning labels on sunscreens that contain nanomaterials.

Scientists worry about the place nanoparticles have in our society. These particles have fundamentally different physical, biological, and chemical properties than their larger counterparts, and continue to be shown as a danger to human health.

Source: Natural Society