The Citizen Lab https://citizenlab.org University of Toronto Tue, 11 Aug 2015 18:14:45 +0000 en-US hourly 1 http://wordpress.org/?v=4.2.4 Christopher Parsons on the Canadian government’s “secret network” hack https://citizenlab.org/2015/08/christopher-parsons-on-federal-secret-network-hack/ https://citizenlab.org/2015/08/christopher-parsons-on-federal-secret-network-hack/#comments Tue, 11 Aug 2015 17:15:31 +0000 https://citizenlab.org/?p=25947

A "secret network" launched by the Canadian federal government last year, costing millions of dollars to taxpayers, came under close scrutiny following a suspected hack. Citizen Lab Postdoctoral Fellow Christoper Parsons explains the possibilities behind the leaking of the document.

The post Christopher Parsons on the Canadian government’s “secret network” hack appeared first on The Citizen Lab.

]]>
A “secret network” launched by the Canadian federal government last year, costing millions of dollars to taxpayers, came under close scrutiny following a suspected hack. The network is based at the Federal Treasury Board, and was produced after hackers attacked department servers in 2011. In an interview with Global News, Citizen Lab Postdoctoral Fellow Christopher Parsons said that maintaining the integrity of a network is possible regardless of the number of employees, though it can be difficult.

The project has grown since this hack, including over five times the employees and further investments into it’s budget. Documents obtained by Global News following an alleged hack by Anonymous indicate that the department also required $1.05 million to purchase hardware and software last year. Initially, plans specified that 200 employees would have access to the network, though it is now estimated that nearly 1,800 full time staff are employed there. Concerns have emerged that this increase in employees has left the server more vulnerable to hacking.

“The goal with these secured networks is to keep classified material in the classified space. If that firewall is maintained between classified and unclassified material, the number of people doesn’t immediately cause a problem” Parsons said. However, introducing more individuals increases the chance a weak link will emerge. “It’s just the fact of the matter that the more people you have on any of these networks, the higher the chance someone accidentally moves a document where they weren’t supposed to, or intentionally moves a document somewhere they weren’t supposed to, or, in a worst case scenario, there’s an insider threat,” Parsons said.

Parsons went on to offer some possibilities as to how the documents revealing the servers information were revealed, saying that it was difficult to determine if it was by leak or hack. Possibilities include someone accidentally sharing the file through a program, moving from a classified to unclassified network.Also, he suggested the possibility that malware had infected a particular employee’s computer. Finally, he explained that Anonymous claim that they compromised the Treasury Board’s servers  could also be legitimate.

Parsons concluded that if this was the case, this leaves open the possibility that others could have access to this information as well. “Some of the government’s Crown Jewels lie in the Treasury Board’s networks. Having unauthorized parties within them would be a serious breach of not just cyber security, but national security … If one party is doing it, there’s no reason to think another party, like a foreign government isn’t doing the same thing.”

Read the full article.

In an article written by CBC reporter Dave Seglins for Canadian Journalists for Free Expression (CJFE), titled “The Case for Encryption,” Christopher Parsons explains the interest of security agencies in all sorts of user data. Though surveillance often pinpoints reporters covering issues such foreign conflicts, terrorism, or military espionage, targets can be varied.

“Sports reporters might be less interesting to signals intelligence organizations but might still be very interesting to other sporting organizations, criminal betting organizations and so forth” Parsons added.

Surveillance can often strike at the workplace, in particular for journalists. “Malware and spyware infect computers across Canada on a regular basis; what do you do when your work computer, holding audio or text files pursuant to a sensitive story, has been compromised?” asks Parsons. “Do you want to notify sources? Do you want to have an ‘air gapped’ computer, which is disconnected from the Internet, where you store source materials, and another computer or device for writing your stories?” Parsons said.

Read the full article.

Christopher Parsons’s piece, “Stuck on the Agenda: Drawing lessons from the stagnation of ‘lawful access’ legislation in Canada,” is published in an edited book by Michael Geist, entitled “Law, Privacy and Surveillance in Canada in the Post-Snowden Era,”  by the University of Ottawa Press.

In addition, along with Citizen Lab Research Fellow Andrew Hilts, Parsons also published an article describing the motivation, design, implementation, and impact of Access My Info (AMI), a tool which the two created to generate legal requests for Canadians to access the data that telecommunications service providers had collected about them. AMI’s release was part of a larger effort to encourage Canadian telecommunications service providers to be more transparent about the personal information that they disclose to state agencies and other third parties.

The post Christopher Parsons on the Canadian government’s “secret network” hack appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/christopher-parsons-on-federal-secret-network-hack/feed/ 0
Canada’s Quiet History Of Weakening Communications Encryption https://citizenlab.org/2015/08/canadas-quiet-history-of-weakening-communications-encryption/ https://citizenlab.org/2015/08/canadas-quiet-history-of-weakening-communications-encryption/#comments Tue, 11 Aug 2015 14:00:27 +0000 https://citizenlab.org/?p=25937

This article, written by Postdoctoral Fellow Christopher Parsons and CIPPIC Staff lawyer Tamir Israel, analyzes how successive federal governments of Canada have actively sought to weaken the communications encryption available to Canadians. The article covers regulations imposed on mobile telecommunications providers, state authorities' abilities to compel decryption keys from telecommunications providers writ large, and Canada's signals intelligence agency's deliberate propagation of flawed encryption protocols.

The post Canada’s Quiet History Of Weakening Communications Encryption appeared first on The Citizen Lab.

]]>
Authors: Christopher Parsons, Tamir Israel

Introduction

American and British officials have been warning with an increasing sense of purported urgency that their inability to decrypt communications could have serious consequences. American authorities have claimed that if they cannot demand decrypted communications from telecommunications providers then serious crimes may go unsolved. In the UK this danger is often accentuated by the threat of terrorism. In both nations, security and policing serviceswarn that increased use of encryption is causing communications to ‘go dark’ and thus be inaccessible to policing and security services. These dire warnings of the threats potentially posed by criminals and terrorists ‘going dark’ have been matched over the years with proposals that would regulate encryption or mandate backdoors into any otherwise secure system. Comparatively little has been said about Canada’s long-standing efforts to inhibit end-user encryption despite the federal government’s longstanding efforts to restrict the security provided to Canadians by encryption.

This article outlines some of the federal government of Canada’s successful and unsuccessful attempts to weaken cryptographic standards. It starts by explaining (in brief) what communications encryption is, why it matters, and the implications of enabling unauthorized parties to decrypt communications. With this primer out of the way, we discuss why all of Canada’s mobile telecommunications carriers agree to implement cryptographic weaknesses in their service offerings. Next, we discuss the legislation that can be used to compel telecommunications service providers to disclose decryption keys to government authorities. We then briefly note how Canada’s premier cryptologic agency, the Communications Security Establishment (CSE), successfully compromised global encryption standards. We conclude the post by arguing that though Canadian officials have not been as publicly vocal about a perceived need to undermine cryptographic standards the government of Canada nevertheless has a history of successfully weakening encryption available to and used by Canadians.

Communications Encryption 101

A range of technologies help individuals keep the content of their communications private from third-parties. Third-parties include the intermediaries which are involved in transmitting a communication between the two or more individuals who are communicating with one another. To protect email, the persons who generate and receive the message might transform the text so that third-parties cannot read it. Sometimes encryption is deliberately added by the end-user. As an example Alice could use a tool called GPG to encrypt her email to Bob before she sends it. At other times, encryption could be applied automatically without the end-user intervening. An example of such an application could involve the user browsing to https://server.ca and having all the communications between the web server and web browser encrypted using a protocol called SSL/TLS. Instant message-based communications can also be encrypted such that only the sender and recipient, and not the intermediaries responsible for transiting the messages, can decode them. Instant messages can be encrypted either through user intervention (such as by using tools like OTR) or automatically by the service provider (using tools such as Apple’s Messages application).

Most encryption techniques use random character strings called ‘keys’. Keys are employed to manipulate the message being sent so that it is unreadable to a third party. In order to facilitate encryption that is readable by an intended recipient (Bob), but not by a malicious third party (Marko), a ‘key pair’ is often used. A key pair will typically include a primary key, as well as a secondary key that is generated from the primary, based on a mathematical formula. The relationship between the primary and secondary key is what allows a user (Alice) to encrypt a message in a manner that is very difficult for anyone other than the intended recipient (Bob) to decrypt.

There are a range of ways to encrypt communications. For the purposes of this article, we identify just two. First, there may be a persistent key pair. In such cases, the same keys are always used to encrypt and decrypt a communication so if an unauthorized party ever gets access to a decryption key they can retroactively decrypt all of the encrypted communications in their possession. In this case, if the third-party had been copying encrypted communications between a person’s Web browser (commonly referred to as a web client or user agent) and a SSL-enabled Web server for a year then all of those encrypted communications could be decrypted retroactively and read. Second, there could be a constantly (re)generating series of session keys. In these cases, the Web client and Web server create a new, temporary, set of encryption and decryption keys each time they communicate. Those session keys are then disposed of or deleted following the end of the communication. As a result, while a malicious third-party who gains access to Bob’s secret key might be able to decrypt future communications, the party cannot retroactively decrypt historically captured communications between the Web client and Web server. This is because, assuming that the process is properly configured, it can be functionally impossible for a third-party to (re)generate the same session keys.

Communication encryption tools combined with anonymity tools are important, as they“provide the privacy and security necessary for the exercise of the right to freedom of opinion and expression in the digital age. Such security may be essential for the exercise of other rights, including economic rights, privacy, due process, freedom of peaceful assembly and association, and the right to life and bodily integrity.” Encryption protects individuals and their communities alike by enabling them to learn and communicate without fear of unauthorized third-parties’ surveillance. As a result, encryption secures the communicative space within which individuals develop as persons. Moreover, given the use of Internet-based communications in all elements of daily life — banking transactions, the delivery of medical records, operation of critical infrastructures, routing of sensitive business information, etc  — encryption provides protections to the vast range of communications and transactions that individuals, groups, and organizations are constantly engaged in.

If the encryption keys that are used to decrypt messages are accessible to unauthorized third-parties then the contents of already-captured communications can subsequently be read by those third-parties. This is a non-trivial problem given that Western security as well as intelligence agencies are known to collect and archive large volumes of encrypted communications for decryption years or decades later (Aid 2009). Moreover, if the persistent key pair or the dynamically generated session keys are accessible to the third-party in real-time then they can also decrypt communications as they take place between the communicating parties. The result is that encrypted communications are no longer private from prying eyes. Such privacy might be violated by a government authority that was legally permitted to violate the communicants’ privacy, by a person inside a company who was inappropriately or illegally accessing communications, or by criminals wanting to know what the communicants are saying to one another. Requiring parties to disclose keys in their possession is deeply problematic because it undermines the whole purpose of encryption. Disclosing keys used for persistent encryption schemes not only allows for access to a specific set of encrypted communications, but exposes all past and future communications encrypted with those keys. A key retention obligation is even worse, as it wholly obviates dynamic keys, undermining the very purpose of the protocol itself.

As we discuss in the following sections, the federal government of Canada has actively attempted on a number of occasions to diminish the privacy and integrity of communications encryption protocols available to Canadians. Historically such efforts have been focused on undermining the privacy that mobile providers, such as Rogers and Bell, could provide to their customers. In the past several years, however, the government has quietly turned its attention to all TSPs which operate in Canada as well as to global encryption standards.

Encryption and Mobile Carriers in Canada

Canadian mobile telecommunications providers are required to agree to – and implement – the Solicitor General’s Enforcement Standards (SGES). Broadly, these standards establish the conditions that mobile providers must meet in order for government agencies to successfully receive information from the providers’ networks. There are a total of twenty-two standards that compose the SGES. For this article we focus on standard twelve; for a broader discussion of the SGES see our report, “The Governance of Telecommunications Surveillance: How Opaque and Unaccountable Practices and Policies Threaten Canadians.”

Standard twelve states, “[i]f network operators/service providers initiate encoding, compression or encryption of telecommunications traffic, law enforcement agencies require the network operators/service providers to provide intercepted communications en clair.” The annotation for this standard reads: “Law enforcement requires that any type of encryption algorithm that is initiated by the service provider must be provided to the law enforcement agency unencrypted. This would include proprietary compression algorithms that are employed in the network. This does not include end to end encryption that can be employed without the service provider’s knowledge.”

Mobile telecommunications providers have historically been compelled to decrypt or decode text messages, faxes, and voice communications which they encoded upon request by government authorities. This obligation is limited to certain types of encryption techniques – excluded are end-to-end encryption techniques, which may be implemented by the service provider but, once implemented, can be initiated by end users without the knowledge or active participation of that provider. Obviously technologies have changed since the mid-1990s and as a result the government proposed expanding the SGES’ scope of application in a spectrum auction consultation in 2012. After internal debates along with critiques from industry, who opposed expanding the SGES to non-traditional communications without authorizing legislation, the government ‘clarified’ that the updates to the SGES would apply only to communications that were historically carried over ‘circuits’ as opposed to packet-based communications (See: Parsons, 2015). This decision meant that, depending on the encryption mechanism being used, new technologies for generating and delivering SMS, MMS, fax, and voice communications would remain accessible to government authorities. This has seemingly led some telecommunications providers, such as Rogers Communications, to deliberately discuss how to weaken communications-related encryption protocols such as MIKEY-IBAKE. Moreover, discussions at the European Telecommunications Standards Institution have raised whether Canadian providers should ensure any cloud-based storage system they develop be designed with lawful interception functionality baked in (For more, see: The Governance of Telecommunications Surveillance: How Opaque and Unaccountable Practices and Policies Threaten Canadians.)

Legislating Access to Decryption Keys

The government of Canada has introduced legislation which would have required all telecommunications providers to decrypt communications they encrypted, where the providers retained decryption keys (commonly referred to as ‘lawful access’ legislation). Whereas the SGES applies to mobile providers, successive iterations of lawful access legislation that have been introduced by the federal government would apply to all telecommunications service providers. Thus, the legislation affects wireline and wireless telecommunications carriers, such as Rogers and Bell, as well as other providers, such as Google, Facebook, or Twitter.

Canada’s lawful access debate occurred over more than a decade. The salient portion of the legislative mandate for this article was reintroduced several times as Bill C-46, Bill C-51 and ultimately, in February 2012, as Bill C-30. Amongst a range of other provisions, these Bills imposed novel legal obligations that would make it easier for the state to intercept communications. Sub-sections 6(1) and (2) would have required telecommunications service providers to be capable of: intercepting communications, provide interceptions to authorized parties, offer information about the geographical sites of the communication, and comply with confidentiality or security conditions such as gag orders. Sub-section 6(5) would have required that, when multiple formats were available, telecommunications providers provide intercepted data in the format preferred by the government authorities. Each of these requirements paralleled requirements already established in the SGES.

Sub-sections 6(3) and 6(4) focused on encrypted communications; 6(3) read:

If an intercepted communication is encoded, compressed, encrypted or otherwise treated by a telecommunications service provider, the service provider must use the means in its control to provide the intercepted communication in the same form as it was before the communication was treated by the service provider.

Per this section, where a telecommunications provider is legally obligated to facilitate interception of communications, it would be required to decrypt those communications upon a demand from government if it retained the decryption key. Under 6(4) a provider would not be obligated, however, to “develop or acquire decryption techniques or decryption tools.”

Whereas the SGES imposed requirements principally on mobile providers, Bill C-30 would have applied decryption requirements on all telecommunications providers. The result is that there would have been an explicit legislative clause authorizing authorities to compel telecommunications providers to decrypt communications. The bill was not passed into law. It’s successor, Bill C-13, however includes language that arguably authorizes authorities to similarly request decryption keys.

Receiving Royal Assent on December 9, 2014, Bill C-13 includes preservation and production powers that were identical to those included in the proposed Bill C-30. Under 487.012(1) a “peace officer or public officer may make a demand to a person in Form 5.001 requiring them to preserve computer data that is in their possession or control when the demand is made.” In order to make the demand, the peace officer or public officer must have reasonable grounds to suspect that:

(a) an offence has been or will be committed under this or any other Act of Parliament or has been committed under a law of a foreign state;

(b) in the case of an offence committed under a law of a foreign state, an investigation is being conducted by a person or authority with responsibility in that state for the investigation of such offences; and

(c) the computer data is in the person’s possession or control and will assist in the investigation of the offence.

Conditions may be included as part of the demand; while these can include conditions about disclosing the reception of a demand, a broader (and left unstated in the legislation) set of conditions could be applied. Moreover, assuming that a cryptographic key is captured under the definition of “computer data” that is in a telecommunications provider’s “possession or control when the demand is made” the provider might be obliged to preserve, and subsequently disclose, the key.

In effect, whereas C-30 would have explicitly established decryption requirements of general application on telecommunications providers C-13 did so in a more obscure way. Fortunately, under C-13 a provider could challenge an order whereas under C-30 the same provider would have simply had an obligation to disclose keys. In that regard, the C-13 can be seen as an improvement over C-30 with respect to compelling the disclosure of decryption keys. However, the provisions in C-13 could be more intrusive on a case by case basis, depending on the types of conditions ultimately imposed by law enforcement or judges. So, for example, whereas C-30 did not require service providers to develop new decryption capacities, C-13 might, on a case by case basis.

Compromising Global Encryption Standards

In addition to enabling domestic agencies to retroactively decrypt communications Canada’s foreign signals intelligence agency, the Communications Security Establishment (CSE), has been active in undermining key mechanisms that form the basis for encrypted communications. The CSE is Canada’s premier cryptographic organization. Documents provided by by former NSA contractor Edward Snowden to journalists reveal that CSE’s United States counterpart, the National Security Agency (NSA), successfully weakened an encryption standard called DUAL EC DRBG in 2006 that was then approved by the United States’ National Institute for Science and Technology (NIST).

As noted above, much of cryptography is dependent on mathematical manipulations of communications based on ‘keys’ or large random numbers. This feature of cryptography means that the ability to generate truly random numbers is integral to any successful encryption scheme. DUAL EC DRBG is a random number generator that could be used by a number of encryption schemes to create any necessary keys. A flawed number generator — particularly one with a known flaw — can render any encryption technique that relies on it insecure, because it becomes exponentially easier to ‘guess’ the ‘key’ and subsequently decrypt the message. In this particular instance, the NSA could exploit the flaw in the DUAL EC DRBG and, after NSA had successfully pushed its adoption as a national standard, the agency proceeded to advance it as an accepted international standard.

The NSA’s Canadian partner, CSE, ran the international committee at the International Organization for Standardization (ISO) that was responsible for evaluating and authorizing DUAL EC DRBG. Some “behind-the-scenes finessing” from the head of CSE and members of the NSA took place, which led to the NSA rewriting the drafted international standard. Meanwhile, the NSA ensured that its flawed version of DUAL EC DRBG was included as a Federal Information Processing Standard (FIPS), a set of standards approved by the US Government for use in non-military government computer systems. CSE similarly leveraged its role as steward of Canada’s government defensive capabilities to ensure that the flawed standard was included in a list of approved algorithms that must be used for any Canadian and US Government procurement. The consequence of this  NSA’s ‘finessing’ was to propagate and grant legitimacy to a method of data encryption known to be vulnerable.

As a result, DUAL EC DRBG has been incorporated into a range of products, including those from security company RSA, in operating systems such as Microsoft Windows,and in a version of OpenSSL (a tool commonly used to facilitate website encryption). The integration of the standard with operating systems was significant because, by changing the default method by which the operating system encrypted communications traffic, an intelligence agency could decrypt data now encrypted using DUAL EC DRBG. The secret of the standard’s weakness got out quickly: researchers discovered and disclosed the vulnerabilities in 2007. Nonetheless, the standards’ ISO and FIPS status was not revoked, and agencies such as CSE continued to retain it on their cybersecurity recommendation lists, allowing it to persist in spite of its known flaws.

While organizations like the NSA and CSE are expected to try and break cryptographic protocols, and while they have a history of deliberately providing ‘weak’ encryption to potential intelligence targets, the deliberate weakening of cryptographic standards themselves is dangerous. Such activity calls into question all of the cryptographic protocols that the NSA and CSE (and their allies) have had a hand in testing and approving. Moreover, such weaknesses call into question the legitimacy of established venues to create, test, and legitimize new cryptographic algorithms.

Canada’s Quiet War on Encryption?

In aggregate, the federal government of Canada has been actively trying to undermine the privacy and security afforded by encryption for at least two decades, with varying degrees of success. What began with quiet regulations that only industry insiders were aware of has transitioned to efforts to expand the kinds of communications covered by the Solicitor General’s Enforcement Standards (SGES) and, ultimately, to a legislative language that may compel the preservation and disclosure of decryption keys. At the same time, Canada’s signals intelligence agency has been caught deliberating weakening at least one cryptographic standard.

Canadians’ default ways of conducting mobile communications have been subject to decryption requirements since the 1990s. The SGES largely prevents Canadians from securely communicating using voice or SMS messages, unless they use a third-party Voice Over Internet Protocol (VoIP) or texting application. The result is that they ways that millions of Canadians speak with one another are made insecure by secret government regulation. Moreover, the government of Canada has established encryption key preservation and disclosure laws. Consequently, companies and persons who provide encrypted communications could be compelled to disclose decryption keys to government authorities. Such disclosures would effectively undermine the security that Canadians think they enjoy when communicating using SSL, TLS, or other encryption protocols.

In addition to ostensibly weakening communications for law enforcement purposes, the Canadian government vis-a-vis its signals intelligence agency intentionally advocated for, and propagated, a deficient security standard around the world. This standard rendered hundreds of millions of people’s communications less secure; in addition to the United States’ National Security Agency paying a security company, RSA, $10 million dollars to implement the standard, major operating system vendors such as Microsoft included DUAL EC in their products. The consequence was, and remains, that Canada has intentionally undermined the privacy and security of Canadians who use RSA and Microsoft products along with millions of other people around the world.

Despite the aforementioned activities, the Canadian government has not formally taken as strong a position as the American or British government concerning cryptography. To date, Canadian officials have not publicly called for ‘backdoors’, or deliberate cryptographic vulnerabilities that companies must include in their products in order to provide decrypted versions of communications to authorities upon request. But this public restraint may simply be reflective of the fact that the federal government’s quiet war on encryption has been surprisingly successful: the default mobile communications of most Canadians are accessible to government, decryption keys can be compelled from companies, and hundreds of millions of people have cryptographic suites installed on their computers that are exploitable by Canada’s signals intelligence agency.

How the federal government of Canada develops and implements national encryption policies can deeply influence Canadians’ abilities to compete in the digital economy. Bad policies undermine the sense of security that Canadians enjoy when they conduct daily activities online and when they make purchases online. Bad policies make it harder for non-Canadians to trust the security and privacy assurances given by Canadian businesses. And, perhaps even worse, bad policies mean that Canada’s advice will not be taken when it comes to developing, and advocating for, genuinely secure encryption protocols. In effect, bad policy hinders Canada’s stature in the world and Canadians’ capabilities to participate in the growing digital economy.

Encryption policies should be a non-partisan issue. All politicians, and all Canadians, should advocate for strong, reliable cryptographic protections so that Canadian businesses can thrive and Canadian citizens enjoy private communications. But instead of successive federal governments trying to enhance online security the governments have been actively trying to weaken online security. As a result, encryption policy debates need to receive far more attention from the public, policy makers, and politicians alike: this critical policy issue must debated in the light of the public eye instead of continuing to languish in the shadows of secretive government policy shops.

Text Sources

  • Matthew M. Aid. (2009). The Secret Sentry: The Untold History of the National Security Agency. New York: Bloomsbury Press.
  • Ian Goldberg. (2008). “Privacy-Enhancing Technologies for the Internet III: Ten Years Later.” Alessandro Acquits, Stefanos Gritzalis, Costas Lambrinoudakis, and Sabrina De Capitani di Vimercati (Eds). Digital Privacy: Theory, Technologies, and Practices. New York: Auerbach Publications.
  • Christopher Parsons. (2015). “Stuck on the Agenda: Drawing lessons from the stagnation of ‘lawful access’ legislation in Canada,” Michael Geist (ed.), Law, Privacy and Surveillance in Canada in the Post-Snowden Era (Ottawa University Press).

This post first appeared at the Telecom Transparency Project.

The post Canada’s Quiet History Of Weakening Communications Encryption appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/canadas-quiet-history-of-weakening-communications-encryption/feed/ 0
Every Rose Has Its Thorn: Censorship and Surveillance on Social Video Platforms in China https://citizenlab.org/2015/08/every-rose-has-its-thorn/ https://citizenlab.org/2015/08/every-rose-has-its-thorn/#comments Mon, 10 Aug 2015 12:29:12 +0000 https://citizenlab.org/?p=25925

In this paper presented at USENIX FOCI 2015 we use reverse engineering to provide a view into how keyword censorship operates on four popular social video platforms in China: YY, 9158, Sina Show, and GuaGua. We also find keyword surveillance capabilities on YY. Our findings show inconsistencies in the implementation of censorship and the keyword lists used to trigger censorship events between the platforms we analyzed. We reveal a range of targeted content including criticism of the government and collective action. These results provide evidence that there is no monolithic set of rules that govern how information controls are implemented in China.

The post Every Rose Has Its Thorn: Censorship and Surveillance on Social Video Platforms in China appeared first on The Citizen Lab.

]]>
Media Coverage: Bloomberg, Toronto Star.

You may have never heard of YY, 9158, Sina Show, or GuaGua, but in China these are four of the most popular social video platforms (SVPs). Collectively these applications have over 1 billion registered users.

Social video platforms offer real-time video streaming and social networking features that enable users to broadcast content and interact with groups over video, voice, and text. One of the most popular uses is broadcasting karaoke performances. SVPs are primarily monetized through the sale of virtual goods (such as virtual roses) that users give to performers during broadcasts. While musical performances account for the majority of revenues, SVPs are expanding to gaming, education, financial analysis, and online dating applications.

Like other social media companies operating in China, SVPs face a complex array of regulations and are liable for content posted to their platforms. Companies are expected to invest in staff and technology for ensuring compliance with government regulations. Failure to comply with regulations can lead to fines or revocation of operating licenses.

Today, we shine a light into how content filtering and monitoring operate on these platforms with the release of our paper “Every Rose Has Its Thorn: Censorship and Surveillance on Social Video Platforms in China”, at the 2015 USENIX Free and Open Communications on the Internet (FOCI) workshop.

Through reverse engineering we find keyword censorship in all four platforms and keyword surveillance capabilities on YY. Each platform implements these controls on the client side (i.e., on the application itself rather than on a remote server), which allows us to extract the full keyword lists from the software binaries.  In total, we reveal a dataset of 17,547 unique keywords used to trigger censorship.  We translate and contextualize each keyword and group them into content categories.  This is the largest dataset of sensitive keywords currently available to researchers and builds on previous research we conducted on chat applications in China that produced a dataset of 4,256 unique censorship and surveillance keywords. Our dataset is available on our GitHub page.

Key Findings

Inconsistencies in the content and implementation in keyword lists across companies and platforms

We compare our dataset to previously extracted keyword data from chat applications used in China and find very limited keyword list overlap within SVPs and between other platforms. This result substantiates previous findings that suggest companies are only given general directives from authorities and have a degree of flexibility in the implementation.

Range of targeted content including criticism of the government and collective action

While there is limited direct overlap in unique keywords, across lists we see trends in the topics that are targeted including criticism of the government, and collective action. These findings serve as a counterpoint to previous work  from King et al. who posit that content related to collective action is heavily censored on Chinese social media while content critical of the government is often allowed to persist.

Diversity of tactics in implementing censorship undoubtedly lead to a diversity in what content is ultimately restricted. We thus offer a cautious note about applying any comprehensive theory about an ecosystem as varied and fast changing as the Chinese Internet.

The post Every Rose Has Its Thorn: Censorship and Surveillance on Social Video Platforms in China appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/every-rose-has-its-thorn/feed/ 0
Information Controls Research at FOCI 2015 https://citizenlab.org/2015/08/foci2015/ https://citizenlab.org/2015/08/foci2015/#comments Mon, 10 Aug 2015 05:13:49 +0000 https://citizenlab.org/?p=25922

At the  2015 USENIX Free and Open Communications on the Internet (FOCI) workshop, held in Washington DC on August 10, Citizen Lab and collaborators present three papers.

The papers include: investigation of censorship and surveillance on China’s most popular social video platforms, an updated analysis of China’s Great Canon, and examination of securing cookie-based identifiers from passive surveillance.

The post Information Controls Research at FOCI 2015 appeared first on The Citizen Lab.

]]>
At the 2015 USENIX Free and Open Communications on the Internet (FOCI) workshop, held in Washington DC on August 10, Citizen Lab researchers and collaborators present three papers.

The papers include: investigation of censorship and surveillance on China’s most popular social video platforms, an updated analysis of China’s Great Cannon, and examination of securing cookie-based identifiers from passive surveillance.

Every Rose Has Its Thorn: Censorship and Surveillance on Social Video Platforms in China
Jeffrey Knockel (University of New Mexico and Citizen Lab), Masashi Crete-Nishihata (Citizen Lab), Jason Q. Ng (Citizen Lab), Adam Senft (Citizen Lab),  and Jedidiah R. Crandall (University of New Mexico)

Social media companies operating in China face a complex array of regulations and are liable for content posted to their platforms. Through reverse engineering we provide a view into how keyword censorship operates on four popular social video platforms in China: YY, 9158, Sina Show, and GuaGua. We also find keyword surveillance capabilities on YY. Our findings show inconsistencies in the implementation of censorship and the keyword lists used to trigger censorship events between the platforms we analyzed. We reveal a range of targeted content including criticism of the government and collective action. These results develop a deeper understanding of Chinese social media via comparative analysis across platforms, and provide evidence that there is no monolithic set of rules that govern how information controls are implemented in China.

An Analysis of China’s “Great Cannon”
Bill Marczak (UC Berkeley and Citizen Lab), Nicholas Weaver (ICSI,UC Berkeley), Jakub Dalek (Citizen Lab), Roya Ensafi (Princeton University), David Fifield (UC Berkeley), Sarah McKune (Citizen Lab), Arn Rey, John Scott-Railton (Citizen Lab) and Ron Deibert (Citizen Lab).

On March 16th, 2015, the Chinese censorship apparatus employed a new tool, the “Great Cannon”, to engineer a denial-of-service attack on GreatFire.org, an organization dedicated to resisting China’s censorship. This paper presents a technical analysis of the attack and what it reveals about the Great Cannon’s working, underscoring that in essence it constitutes a selective nation-state Man-in-the-Middle attack tool. Although sharing some code similarities and network locations with the Great Firewall, the Great Cannon is a distinct tool, designed to compromise foreign visitors to Chinese sites. We identify the Great Cannon’s operational behavior, localize it in the network topology, verify its distinctive side-channel, and attribute the system as likely operated by the Chinese government. We also discuss the substantial policy implications raised by its use, including the potential imposition on any user whose browser might visit (even inadvertently) a Chinese website.

Half Baked: The Opportunity to Secure Cookie-based Identifiers from Passive Surveillance
Andrew Hilts (Citizen Lab and Open Effect) and Christopher Parsons (Citizen Lab)

This paper examines the security of the embedded ad trackers that transmit unique identifiers. This work is important because network snoops can collect internet traffic in bulk, linking together unencrypted cookies to build out detailed profiles of user’s interests, and “patterns of life”, which can then be used to target specific individuals for intelligence operations. The paper identifies simple ways that websites can take steps today to better protect the privacy of their readership.

The post Information Controls Research at FOCI 2015 appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/foci2015/feed/ 0
What we know about the South Korea NIS’s use of Hacking Team’s RCS https://citizenlab.org/2015/08/what-we-know-about-the-south-korea-niss-use-of-hacking-teams-rcs/ https://citizenlab.org/2015/08/what-we-know-about-the-south-korea-niss-use-of-hacking-teams-rcs/#comments Mon, 10 Aug 2015 00:00:58 +0000 https://citizenlab.org/?p=25878

This research note outlines what we know about the use of Hacking Team’s Remote Control System (RCS) by South Korea’s National Intelligence Service (NIS). The note synthesizes information found in publicly leaked materials, as well as our own research.

The post What we know about the South Korea NIS’s use of Hacking Team’s RCS appeared first on The Citizen Lab.

]]>
Authors: Bill Marczak, Sarah McKune

Summary

This research note outlines what we know about the use of Hacking Team’s Remote Control System (RCS) by South Korea’s National Intelligence Service (NIS).  The note synthesizes information found in publicly leaked materials, as well as our own research.

The data available in the leaked Hacking Team files provides circumstantial evidence pointing to an interest in compromising individuals with ties to South Korea (i.e., Korean language speakers who use software or apps popular in South Korea, or South Korean editions of Samsung phones).

The leaked data alone cannot identify specific individuals targeted by NIS, nor prove misuse of the technology; further investigation and research is necessary to make those determinations.  Moreover, the presence of intrusion software does not necessarily equate to its misuse, as such software may be utilized by intelligence or law enforcement agencies in a manner that conforms with rule of law and democratic principles. We are releasing this report in order to assist with further investigation and research into South Korea’s use of Hacking Team.

 

요약

본 연구노트는 한국 국정원의 해킹팀 RCS (Remote Control System) 사용에 관해 저희가 알고 있는 것을 개략적으로 기술한 것입니다. 노트에는 공개적으로 유출된 자료와 저희의 연구를 통해 발견된 정보가 함께 포함되어 있습니다.

중요한 것은, 유출된 해킹팀 파일에서 발견된 자료에는 국정원이 한국과 관련 있는 개인 (민간인) 들을 사찰하는 데 관심이 있었다는 정황적 증거들(사례 : 한국에서 대중적인 소프트웨어나 앱을 사용하는 한국어 사용자 또는 삼성의 내수용(한국 에디션) 스마트폰)이 포함되어 있다는 점입니다.

유출된 자료만으로는 국정원이 대상으로 삼은 특정인의 신원을 알 수 없으며, 해당 기술이 악용되었는지도 증명할 수 없습니다. 이를 확인하기 위해서는 추가적인 조사와 연구가 필요합니다. 또한 침입소프트웨어/해킹프로그램이 존재한다고 하여 악용되었을 것이라고 단정하기 어렵습니다. 정보기관이나 법집행기관이 이러한 프로그램을 적법한 절차와 민주적 원칙에 따라 사용할 수도 있기 때문입니다. 저희는 한국에서의 해킹팀 사용에 대한 추가적인 조사와 연구를 돕고자 본 보고서를 공개합니다.

 

Background

The National Intelligence Service (NIS) is Korea’s main intelligence agency. It was founded in 1961 as the Korea Central Intelligence Agency (KCIA).1  The name and functions of the agency have evolved considerably over time.  Named the NIS in 1999, it has a three-part mandate: domestic security, national security, and counterintelligence operations against North Korea.2  Despite widely-reported reform efforts, the agency continues to face criticism for reported and perceived abuses of its power and mandate.3

Recent Scrutiny of NIS

The NIS has been scrutinized for misuse of its powers in a number of cases, which have been revisited in media coverage of the Hacking Team leaks.

In February 2015, a former NIS director was sentenced to three years in prison for ordering NIS agents to attempt to influence the 2012 presidential elections by posting negative comments about President Park Geun-hye’s rivals.4  Some of the 1.2 million comments that prosecutors say NIS agents posted accused President Park’s rivals of being pro-North Korean sympathizers.5  NIS denied interfering in the election, claiming that the agency’s online activities were solely directed at North Korea.6  Recently, the Supreme Court ordered a retrial in the case, as some evidence used to convict the former director was ruled inadmissible.7
Additionally, in 2005, a former deputy chief of NIS was arrested for illegal wiretapping.  The prosecutor in the case stated that the deputy chief may have attempted to destroy evidence in the case before his arrest.8

Previous Citizen Lab Report

In February 2014, Citizen Lab released a report entitled “Mapping Hacking Team’s ‘Untraceable’ Spyware,” which identified 21 suspected government users of Hacking Team’s RCS spyware, including South Korea.9  The report triggered limited media coverage in South Korea at the time.10

Current Scandal

On July 6, 2015, it became clear that Hacking Team had suffered a substantial compromise of its internal systems.11  Shortly thereafter, much of Hacking Team’s code, data, and communications were leaked into the public domain.  The material not only confirmed that South Korea was a customer of Hacking Team, but exposed substantial commercial interactions between Hacking Team and the “5163 Army Division,” whose mailing address matches that of the NIS,12 and is reported to be a codename of the NIS.13

Shortly after this revelation, an employee of the NIS reportedly committed suicide.  A note claimed he had deleted information regarding the NIS’s use of Hacking Team RCS,14 triggering nationwide interest in who the NIS was targeting.15  Lawmakers said that, in a closed-door meeting, the NIS admitted to purchasing Hacking Team spyware.16  A lawmaker in the Intelligence Committee of the National Assembly of the Republic of Korea disclosed that the NIS testified to the Committee that it had used Hacking Team spyware more than 200 times for counterespionage, and to track the North Korean arms trade.17

 

The NIS Purchases Hacking Team

According to the leaked files, a South Korean company called Nanatech introduced itself to Hacking Team in August 2010, claiming that it provided “support” in relation to “telecommunication equipments to domestic companies.”18  Nanatech was purportedly attempting to acquire solutions to monitor Skype on behalf of its customer,19 and noted that the customer was also interested in “monitoring the voice conversation on the mobile phone.”20  Nanatech stated that Hacking Team competitor Gamma Group, developer of FinFisher, was also dealing with its customer through another reseller.21

Notably, it appears that Nanatech never informed Hacking Team that its customer was NIS. In November 2010, Nanatech responded to Hacking Team queries pressing for more information on its customer22 with “About end-user: Our client is the research team of Army (named KINSTEL). I think you don’t have to worry about it,” which appeared to satisfy Hacking Team.23 Renewed exchanges in June 2011 also indicated the “army” as end user.24 In proceeding with the purchase, Nanatech specifically identified its customer to Hacking Team in November 2011 as the “5163 Army Division.”25 The mailing address that Nanatech provided for the Division matches that of the NIS,26 and “5163 Army Division” is reported to be a codename of the NIS.27 This obfuscation of customer identity raises significant questions regarding corporate due diligence and overall transparency in identifying end users of the spyware. Indeed, end user verification is often required by export licensing regimes.

In subsequent emails28 and in its customer list,29 Hacking Team also variously referred to the customer as “South Korea Army,” “SKA,” or “The Army South Korea.”

Nanatech organized a visit for two representatives from the customer, Sunny Han and Se-Hun Lee, and one person from Nanatech,30 to Hacking Team’s offices in Milan on 21-22 November 2011.31 Nanatech mentioned that they had managed to outmaneuver the competition, and arranged for the customer to meet with Hacking Team before any meeting with competitors Gamma International and Trovicor.32 After the meeting in Milan, Nanatech expressed that the customer wanted to rush to purchase Hacking Team’s RCS, claiming that they needed to spend their budget by 20 December 2011.33

After some back and forth, Nanatech’s customer accepted offer #NA111214Q1.34 (See Figure 1 below.) The offer included the ability to monitor a total of 10 targets simultaneously on Windows, Symbian, Blackberry, iPhone, and Android platforms. It also included the Remote Mobile Infection/Installation (RMI) feature, and one year of zero-day exploits and maintenance. RMI apparently involves sending WAP push messages (SI and SL) through a GSM modem to mobile devices.35 Depending on phone settings, such messages can automatically open a browser window or attempt to install an application, and can appear to be from the user’s mobile phone operator. The total cost was €390,000.

image09Figure 1: Nanatech Offer #NA111214Q1.36

A letter of credit (#M03QY112GS0014) was issued for this offer,37 with delivery to be made to the “5163 site.” (See Figure 2 below.)

loc

Figure 2: Excerpts from Letter of Credit issued for Offer #NA111214Q1.38

Delivery was completed and accepted by the “5163 Army Division.”39 (See Figure 3 below.) The license agreement for Hacking Team’s RCS spyware was signed by Sunny Han.40 (See Figure 4 below.)

image08

Figure 3: Certificate of Acceptance in relation to Letter of Credit #M03QY112GS0014 from the “5163 Army Division.”41

eula

Figure 4: Excerpts from License Agreement between Hacking Team and the “5163 Army Division.”42

The Korean customer purchased 10 additional target licenses in August 2012, for €57,600, allowing them to monitor a total of 20 targets simultaneously.43

On 6 December 2012, the Korean customer expressed interested in purchasing an additional 30 target licenses, which would have allowed it to monitor 50 targets at once.44 The purchase was apparently never completed, and it appears that no further target license purchases were initiated.

 

Targets in South Korea?

The data available in the leaked Hacking Team files provides circumstantial evidence pointing to an interest in compromising individuals with ties to South Korea (i.e., Korean language speakers who use software or apps popular in South Korea, or South Korean editions of Samsung phones). However, the leaked data does not identify the targets, or conclusively show whether these targets were inside or outside Korea.

Interest in Targeting South Korean-Edition Phones

The customer communicated with Hacking Team via the email accounts devilangel1004@gmail.com45 (“devilangel”) and smiolean@gmail.com.46  Devilangel filed several support tickets47,48,49,50 in August and September 2012 asking for support for call recording on “SHW-M series” (South Korean edition) Samsung phones, as well as, in one case, on “Galaxy S3 Chinese models.” Nanatech also contacted Hacking Team to ask for voice recording support for South Korean edition Galaxy 3 phones.51 In January 2013, Nanatech sent a South Korean edition Galaxy S3 to Hacking Team52 to help them support call recording.53 An August 2013 e-mail requests that Hacking Team test their Android exploit against South Korean edition phones.54

Interest in Targeting South Korean Software (KakaoTalk and AhnLab Anti-Virus)

Devilangel requested that Hacking Team test their solution against the latest version of South Korean company AhnLab’s antivirus program,5 as well as popular Chinese anti-virus programs, mentioning that they have “some targets in China.”56

According to a trip report filed by a Hacking Team employee who visited the Korean customer on 24 March 2014, the customer “asked about the progress of Kakao Talk which they mentioned is very commonly used in their country.”57 One of the “key takeaways” of the report was that “Kakao Talk is something which SKA is emphasising.”  The customer also requested support for voice and message recording on the PC versions of KakaoTalk and LINE (a chat application similar to KakaoTalk developed by LINE Corporation, a Japan-based company).58

KakaoTalk is a chat program developed and owned by the South Korea-based company Daum-Kakao. A May 2015 article notes that KakaoTalk is the most popular chat application used in South Korea and has 35 million users in the country, representing 70% of South Korea’s population of 50 million.59

KakaoTalk has previously been the target of government pressure. In 2014, President Park Geun-hye announced a crackdown on the spread of rumors online following criticism of how her administration handled the capsize of a South Korean ferry. As part of this crackdown, a South Korean student and an opposition politician involved in discussions and protests around the ferry incident were notified that law enforcement officials were given access to data from their KakaoTalk accounts.60

Interest in Deploying Spyware via OTA Updates and Wireless Networks

Nanatech also twice inquired about “over the air61 and Wi-Fi infections, mentioning they wanted to “remotely and forcibly ‘push’” the spyware “in a stealth manner onto the target’s device without his knowledge or cooperation.”62 The Korean customer expressed interest in Hacking Team’s TNI (Tactical Network Injector),63 a laptop that “provides everything needed in order to crack a WiFi network, join it, identify the interested target and deploy the RCS Agent.”64  The TNI can also create rogue WiFi networks, and can even work with wired networks given special infrastructure access. The Korean customer tested the TNI from April65 until July 2014, but ultimately decided not to purchase the TNI, citing issues including lack of reliable support for mobile phones.66

Use of Korean Bait Content

We identified several instances of the Korean customer using Korean language or Korea-themed bait content:

  • We observed a drive-by-download attack in 2014 that used a bait content file called “free korean movies.” (see: Attribution of “Drive-by-Download” Samples below)
  • In the leaked files, we found bait content including a file containing the names and phone numbers of Seoul University alumni in Southern California,67 and a file containing information pertaining to the sinking of the ROKS Cheonan,68,69 (and a Computer Science presentation about Machine Learning).70,71
  • One bait content link72,73,74 contained a picture showing the schedule for the 2015 Geumcheon Harmony Cherry Blossom Festival in Seoul, while another one contained a link to a blog about reviews of rice cake dishes at Korean restaurants.75,76,77,78
  • One bait content link contained a link to a Google app on the Google Play Store called “Google Korean Input.”79,80

 

Attribution of “Drive-by-Download” Samples

The leaked Hacking Team e-mails allowed us the opportunity to attribute several samples of Hacking Team RCS spyware that we previously observed:

SHA256: cbde6a113a54b8dcf122d9d879b7c21c8b03a89d792f49210bbe41e8466d121a
URL: http://free.dramakorea.asia/s/free_korean_movies.exe

The command and control (C&C) server used in the sample is hulahope.mooo.com, which matches the C&C for numerous Android samples submitted by devilangel to Hacking Team for preparation of exploits. This sample was submitted to VirusTotal on 21 July 2014, and was submitted eight additional times to VirusTotal in the following month, including twice from Korea.81  This sample appears to have been served through a drive-by-download strategy, involving a file “x.js:”

SHA256: 8793d6eda87163b04a3db9251ff89b7c8a66500a4ed475c7026b5fc9a4c8abe9

On its own, the script causes an Internet Explorer user to see a popup asking them to authorize an ActiveX control. If the control is authorized, then the spyware is downloaded and executed.

We also found the following sample:

SHA256: 21e8d495bca60edc3b64ac970f9a9fa896d0eadc6491452ea937d64849b1f4a0
URL: http://shrook.mooo.com/cn/notify.exe

The sample was submitted to VirusTotal once on September 12, 2014,82 and was apparently served by the same drive-by-download javascript method. The C&C server is also hulahope.mooo.com.

 

Analysis of Bait Content

According to the leaked documents, Hacking Team provides an exploit service to customers that requires that the customers transmit them basic information, including a bait document or link, and their monitoring agent.83 Depending on the type of request, Hacking Team then modifies the bait document to include an exploit to install the agent, or creates a URL that, when clicked, exploits the target’s web browser to install the agent. The exploits and agents are hosted on servers belonging to Hacking Team. Hacking Team sends the bait documents back to the customer, who can then send the booby-trapped bait document to targets to infect them.84  The leaked Hacking Team documents contain numerous customer requests to create exploit documents or links, often with bait content attached. In some cases, these bait documents or links speak to the interests, or identity, of potential targets.

Devilangel expressed concern about having to furnish Hacking Team with bait content used to infect victims, as the information “can be related with my target.”85 Hacking Team responded that they do not “retain any information about the files the customers send us” (note, however, we were able to identify many files sent by devilangel for infection) and suggested that devilangel choose a document “containing not so sensitive data.”86 Given devilangel’s concerns and Hacking Team’s advice, bait documents may have been chosen to minimize the link between the bait content and the target.

Devilangel’s exploit requests also sometimes included a statement as to whether the exploit would be used for “testing” or “real targets.” Below, we provide an overview of some common themes associated with the bait content and bait links submitted by devilangel to Hacking Team. We exclude any marked “testing:”

  • We describe Korean-themed bait content above (see: Use of Korean Bait Content).
  • Some of the bait content includes generic holiday greetings.  For example, “Happy New Year” messages, or Christmas greetings

image04

Figure 5: A “Happy New Year!” bait document submitted by devilangel to create an exploit document.87

image02

Figure 6: A “Christmas Blessing” e-card submitted by devilangel to create an exploit link.88

  • A number of pieces of bait content included medical themes, including a PowerPoint presentation about a Belfast cancer conference, and links about MERS89 and Avian Flu.90

image01

Figure 7: A bait document about the 2015 National Cancer Intelligence Network (NCIN) Cancer Outcomes Conference submitted by devilangel to create an exploit document.91

  • Some bait content included tips for protecting online privacy, including one PowerPoint presentation called “Save you Privacy” and a Word document called “How to Access and Clear Your iPhone’s Web Browsing History.”

image10

Figure 8: A bait document containing information about iPhone browsing history submitted by devilangel to create an exploit document.92

  • Some bait links involved Asian pornography, including a website featuring “only Chinese porn,”93 a page on a pornography website featuring a search for the term “chinese,”94 and a website called “Asian Porn Tube.”95,96

 

Exploit server Logs

The leaked Hacking Team data contains files “Exploit_Delivery_Network_android.tar.gz,” and “Exploit_Delivery_Network_windows.tar.gz,” which appear to contain detailed information about each exploit link or document generated by Hacking Team upon customer request (for May and June 2015), as well as details of which IP addresses clicked on each link (or opened each document), whether the exploitation was successful or not, which website directed each visitor to the exploit (if applicable), as well as the language and model of the phone (in some cases of Android exploits). The log information is in “var/www/files/[ID]/log.jsonl,” where “[ID]” is the six character alphanumeric ID assigned to the exploit by Hacking Team.

We present details on all clicks on Android exploit links below (we did not identify any Windows exploits requested by Hacking Team during this period). Hacking Team’s Android exploit involved a link sent to the target’s phone. If the target opened the link in the built-in Android web browser app, then the exploit may have installed Hacking Team’s RCS on their phone. Importantly, the list below excludes individuals who did not click on the link (as Hacking Team cannot record logs in this case):

ID Time97 IP Country Phone Locale Referer URL Hit?98
BBltjx99 6/29/2015 13:01:49 212.5.158.22 BG NX403A en-US No
BBltjx 6/29/2015 13:02:16 212.5.158.70 BG NX403A en-US No
bO47cc100 6/22/2015 11:24:22 93.84.2.181 BY SM-A500F No
BR2u9z101 6/22/2015 10:50:03 109.188.125.17 RU SM-G800H No
8CS48M102 6/18/2015 10:32:23 92.230.140.206 DE GT-I9103 ko-KR No
v9K0GQ103 6/18/2015 10:45:13 213.87.129.241 RU GT-I8190 ru-RU Yes
jAWxkt104 6/26/2015 01:33:51 220.181.132.217 CN G700-U00 zh-CN http://video.sexyhub.co/x/?rd=SjLzM2 No
zuggfM105 6/17/2015 11:23:43 49.230.231.158 TH SM-G900F No
zuggfM 6/17/2015 11:28:25 49.230.225.3 TH SM-N910C No
zuggfM 6/17/2015 15:37:27 139.193.176.58 ID S5E en-US No
zEsa9i106 6/17/2015 10:55:09 111.80.143.117 TW SM-G900I No
vYLpBl107 6/18/2015 03:34:39 175.168.46.204 CN SAMSUNG-SM-N9008V_TD zh-CN No
8n3gio108 6/12/2015 12:01:41 114.124.0.237 ID GT-S7270 No
7ZSBlX109 6/4/2015 06:32:58 223.62.169.2 KR SHV-E250S ko-KR http://dns.cdc-asia.org/docs/7ZSBlX/fwd Yes
9hN2Zn110 6/1/2015 9:07:03 41.210.154.105 UG GT-I9100 ko-KR No
9hN2Zn 6/1/2015 9:14:43 41.210.154.13 UG SM-N900 No
uPz4mj111 6/17/2015 10:46:17 223.62.212.18 KR GT-N7100 en-PH http://link.sexyhub.co/docs/uPz4mj/fwd Yes

South Korean Targets?

The data shows that there were two successful Android exploitations of phones with Korean IP addresses: one SK Telecom edition Galaxy Note 2 with SK Telecom IP address and Korean-Korea locale, one international Galaxy Note 2 with SK Telecom IP address and English-Phillippines locale. There was only one other successful exploit in May and June 2015: a Galaxy S3 Mini with a Russian IP address and Russian-Russia locale.

One individual with a Ugandan IP address, and one individual with a German IP address, clicked on the link with their locale set to “Korean-Korea.”

 

Command and Control and Exploit Infrastructure

Using referrer URLs in the exploit server logs, as well as domain names and IP addresses found in the Korean customer’s malware samples, we were able to characterize their Hacking Team infrastructure.

We start from the domain name dns.cdc-asia.org, used in a referrer URL seen in the exploit logs. We assume that the Korean customer controlled dns.cdc-asia.org, because this URL referred to the exploit requested from Hacking Team, and was not sent to them by Hacking Team. We further assume that the customer controlled the domain name cdc-asia.org, as the registration date of the domain (June 3, 2015) matches the date that devilangel requested the exploit112 that was clicked on with referring domain dns.cdc-asia.org.

We found the following registrant information for cdc-asia.org:

Registrant Name:krystal Freeman
Registrant Organization:Co
Registrant Street: 136 Driftwood Road
Registrant City:CA
Registrant State/Province:CA
Registrant Postal Code:95129
Registrant Country:US
Registrant Phone:+1.14083799445
Registrant Email:insomnia214@outlook.com
Name Server:NS4.ITITCH.COM
Name Server:NS3.ITITCH.COM
Name Server:NS2.ITITCH.COM
Name Server:NS1.ITITCH.COM

The name server suggests that the domain was registered with ititch.com, a service for purchasing domain names and web hosting using Bitcoin.

We found two other domains registered with the same registrant email:

mytelkomsel.co
telegram-apps.org

We plugged these domains, as well as cdc-asia.org, into PassiveTotal113 in order to identify other domains using the same IP address. PassiveTotal is an infrastructure analysis tool designed for security research. We found that cdc-asia.org resolved to 180.235.132.45, and two other websites resolved to this same address: droidlatestnews.com, and enjoyyourandroid.com.

image06

Figure 9: Excerpt of PassiveTotal results for 180.235.132.45.

The initial registrant information for both domains was as follows:

Registrant Name: Leonard Freeman
Registrant Organization: N/A
Registrant Street: 1203 Grove Street   
Registrant City: Bethpage
Registrant State/Province: New York
Registrant Postal Code: 11714
Registrant Country: US
Registrant Phone: +1.4194763271
Registrant Email: mappingmechanism@hotmail.com
Name Server: domains4bitcoins.earth.orderbox-dns.com
Name Server: domains4bitcoins.mars.orderbox-dns.com
Name Server: domains4bitcoins.mercury.orderbox-dns.com
Name Server: domains4bitcoins.venus.orderbox-dns.com

The name server suggests that the domain was registered with domains4bitcoins.com, a service for purchasing domain names and web hosting using Bitcoin.

Note that the registrant name, “Leonard Freeman,” uses the same surname, “Freeman,” as the registrant for the previous three domains “Krystal Freeman.” The registrant email address for both domains was updated after July 8, 2015 (after the Hacking Team leak) to the following:

Registrant Name: Alexis
Registrant Organization: N/A
Registrant Street: 4403   
Registrant City: Los Angeles
Registrant State/Province: California
Registrant Postal Code: 90017
Registrant Country: US
Registrant Phone: +1.9174849999
Registrant Email: prmgrabzi@hotmail.com

We plugged droidlatestnews.com and enjoyyourandroid.com into PassiveTotal, and found that these resolved to 95.215.46.224. We found several other domains that resolved to this IP address:

bijiaexhibition.com
samsung-update.net
getnewandroid.com
secure.anyurl.org
update.indoorapps.com

We also checked registrant email addresses and phone numbers to find additional domains:

facebook-update.info
samsung-update.net
play-mob.org

It is noteworthy that play-mob.org was registered on 8 April 2015, a day after devilangel requested Android exploits redirecting to “play.mob.org”.114 We provide a list of suspected domain names linked to the Korean customer below, including the domain names above, as well as domain names from RCS samples submitted by devilangel to Hacking Team, and RCS samples detected by Hacking Team on VirusTotal and attributed to the same customer:

cdc-asia.org
mytelkomsel.co
telegram-apps.org
bijiaexhibition.com
samsung-update.net
getnewandroid.com
facebook-update.info
samsung-update.net
play-mob.org
boardingpasstohome.com115
mywealthpop.com116
secure.anyurl.org
update.indoorapps.com
video.sexyhub.co
link.sexyhub.co
shrook.mooo.com
free.dramakorea.asia
nkpro.lalanews.net117
androidgplay.us.to118
hulahope.mooo.com
publiczone.now.im119
reflect.dalnet.ca120
pantheon.tobban.com121

The domain names above were associated with the following e-mail addresses:

checkonetwothree@hotmail.com
mappingmechanism@hotmail.com
watermelonholicq@eclipso.email
insomnia214@outlook.com
prmgrabzi@hotmail.com

We also identified the following IP addresses associated with the Korean customer’s infrastructure:

131.72.137.10
198.105.125.107
198.105.125.108
131.72.137.11
198.105.122.117
185.7.35.79
131.72.137.104
131.72.137.101
95.215.46.224
180.235.132.45
103.13.228.240
185.10.57.150
46.19.143.244
37.46.114.43
5.199.166.180

It also appeared that the Korean customer’s exploits were served from the following IP addresses, which may belong to Hacking Team, and thus have also been used to serve exploits for other Hacking Team customers:

46.38.63.194
188.166.5.201
46.38.63.112
46.251.239.150
212.117.180.108

In our 2014 report, “Mapping Hacking Team’s ‘Untraceable’ Spyware,” we identified the following IP addresses associated with the South Korean customer:

211.51.14.129
101.99.83.12
5.255.87.146
198.144.178.104
198.144.178.118
204.188.221.198
185.7.35.79
185.7.35.80
64.32.12.75
124.217.245.64
185.29.8.202

 

Conclusion and Further Investigation

We have outlined circumstantial evidence indicating that NIS was interested in targets with links to South Korea, and in two cases infected devices belonging to “real targets” inside South Korea.

The leaked data alone cannot identify specific targets. Thus, we presented some technical data regarding the NIS’s Hacking Team RCS command and control infrastructure, which may be useful in further investigation.

We briefly outline some promising avenues for further investigation:

  • First, obtaining DNS logs over the past year associated with the domains publiczone.now.im and hulahope.mooo.com would be very helpful, as this would reveal IP addresses of infected devices.
  • Second, organizations or institutions that run Intrusion Detection Systems should check their logs for hits on the IP addresses and domain names provided herein.
  • Third, groups focused on testing should scan the e-mail accounts of potential targets, as well as their SMS message logs, WAP push message logs, and logs of any other mobile messaging apps, for any e-mails or messages containing the domain names we identified (or any links, such as Tinyurl links, that unshorten to these domains), and any attachments matching Hacking Team’s exploits or spyware.
  • Finally, if NIS initiated their Bitcoin domain name purchases from a single address, it may be possible to trace NIS’s Bitcoin address by searching the Blockchain using the registration times associated with the domains. Tracing NIS’s Bitcoin address could illuminate further elements associated with their C&C architecture.

 

Footnotes

1 http://eng.nis.go.kr/svc/history.do?method=content&cmid=11915
2 http://www.economist.com/blogs/banyan/2014/03/south-korean-intelligence
3 http://www.economist.com/blogs/banyan/2014/03/south-korean-intelligence
4 http://www.bbc.com/news/world-asia-31284704
5 http://www.nytimes.com/2013/11/22/world/asia/prosecutors-detail-bid-to-sway-south-korean-election.html
6 http://www.nytimes.com/2013/05/01/world/asia/prosecutors-raid-south-korean-spy-agency.html
7 http://www.reuters.com/article/2015/07/16/southkorea-spychief-retrial-idINKCN0PQ0LJ20150716
8 http://web.international.ucla.edu/asia/article/31102
9 https://citizenlab.org/2014/02/mapping-hacking-teams-untraceable-spyware/
10 http://www.ohmynews.com/NWS_Web/view/at_pg.aspx?CNTN_CD=A0001970476
11 http://www.wired.com/2015/07/hacking-team-breach-shows-global-spying-firm-run-amok/
12 See “서울 서초우체국 사서함 200호” on http://www.nis.go.kr/svc/community.do?method=content&cmid=11477, which matches “Seocho P.O Box 200, Seocho-dong, Seocho-gu, Seoul, Korea” on https://wikileaks.org/hackingteam/emails/emailid/441251.
13 http://english.hani.co.kr/arti/english_edition/e_national/700356.html
14 http://english.yonhapnews.co.kr/national/2015/07/19/43/0302000000AEN20150719001152315F.html
15 http://www.nytimes.com/2015/07/20/world/asia/in-suicide-note-south-korea-hacking-expert-denies-domestic-spying.html?_r=0
16 http://bigstory.ap.org/article/acd838d482254df9b7e401607bfce9a0/south-korean-spy-agency-explored-technology-hack-chat-app
17 http://english.yonhapnews.co.kr/news/2015/08/04/0200000000AEN20150804000900315.html
18 https://wikileaks.org/hackingteam/emails/emailid/441228
19 https://wikileaks.org/hackingteam/emails/emailid/441228
20 https://wikileaks.org/hackingteam/emails/emailid/440571
21 https://wikileaks.org/hackingteam/emails/emailid/441056
22 https://wikileaks.org/hackingteam/emails/emailid/440827
23 https://wikileaks.org/hackingteam/emails/emailid/441309
24 https://wikileaks.org/hackingteam/emails/emailid/440989
25 https://wikileaks.org/hackingteam/emails/emailid/441105
26 See “서울 서초우체국 사서함 200호” on http://www.nis.go.kr/svc/community.do?method=content&cmid=11477, which matches “Seocho P.O Box 200, Seocho-dong, Seocho-gu, Seoul, Korea” on https://wikileaks.org/hackingteam/emails/emailid/441251.
13 http://english.hani.co.kr/arti/english_edition/e_national/700356.html
27 http://english.hani.co.kr/arti/english_edition/e_national/700356.html
28 See, e.g., https://wikileaks.org/hackingteam/emails/emailid/16742; https://wikileaks.org/hackingteam/emails/emailid/608816; https://wikileaks.org/hackingteam/emails/emailid/585101; https://wikileaks.org/hackingteam/emails/emailid/42977
29 https://ht.transparencytoolkit.org/Amministrazione/01%20-%20CLIENTI/6%20-%20Offensiva/Client%20List_Renewal%20date.xlsx
30 https://wikileaks.org/hackingteam/emails/emailid/441306
31 https://wikileaks.org/hackingteam/emails/emailid/441293
32 https://wikileaks.org/hackingteam/emails/emailid/440837
33 https://wikileaks.org/hackingteam/emails/emailid/441269
34 https://wikileaks.org/hackingteam/emails/emailid/440822
35 https://wikileaks.org/hackingteam/emails/emailid/437543
36 Source: “Price_1214-1[1].pdf” extracted from “Price_1214-1[1].zip” in e-mail: https://wikileaks.org/hackingteam/emails/emailid/440822. The attachment is unavailable on WikiLeaks. The password to extract the .zip file is “ejopenit” (without quotes).
37 https://wikileaks.org/hackingteam/emails/emailid/441001
38 Source: “LC.pdf” extracted from “LC.zip” in e-mail: https://wikileaks.org/hackingteam/emails/emailid/441001. The attachment is unavailable on WikiLeaks. The password to extract the .zip file is “ejopenit” (without quotes).
39 https://wikileaks.org/hackingteam/emails/emailid/441207
40 https://wikileaks.org/hackingteam/emails/emailid/441001
41 Source: “certificate of acceptance.pdf” extracted from “certificate of acceptance.zip” in e-mail https://wikileaks.org/hackingteam/emails/emailid/441207. The attachment is unavailable on WikiLeaks. The password to extract the .zip file is “ejopenit” (without quotes).
42 Source: “software license agreement.pdf” extracted from “software license agreement.zip” in e-mail https://wikileaks.org/hackingteam/emails/emailid/441001. The attachment is unavailable on WikiLeaks. The password to extract the .zip file is “ejopenit” (without quotes).
43 https://wikileaks.org/hackingteam/emails/emailid/440599
44 https://wikileaks.org/hackingteam/emails/emailid/441209
45 https://wikileaks.org/hackingteam/emails/emailid/808281
46 See “My googletalk id for communication is smiolean” in https://wikileaks.org/hackingteam/emails/emailid/715100.
47 https://wikileaks.org/hackingteam/emails/emailid/790170
48 https://wikileaks.org/hackingteam/emails/emailid/797052
49 https://wikileaks.org/hackingteam/emails/emailid/781892
50 https://wikileaks.org/hackingteam/emails/emailid/782084
51 https://wikileaks.org/hackingteam/emails/emailid/441239
52 https://wikileaks.org/hackingteam/emails/emailid/440900
53 https://wikileaks.org/hackingteam/emails/emailid/673756
54 https://wikileaks.org/hackingteam/emails/emailid/353110
55 https://wikileaks.org/hackingteam/emails/emailid/702485
56 https://wikileaks.org/hackingteam/emails/emailid/73106
57 https://wikileaks.org/hackingteam/emails/emailid/16742
58 https://wikileaks.org/hackingteam/emails/emailid/75661
59 http://www.forbes.com/sites/kathleenchaykowski/2015/05/28/creator-of-messaging-app-kakaotalk-acquires-social-network-path/
60 http://bigstory.ap.org/article/97c92b056482488abd990db9a4acb388/s-korea-rumor-crackdown-jolts-social-media-users
61 https://wikileaks.org/hackingteam/emails/emailid/441040
62 https://wikileaks.org/hackingteam/emails/emailid/440923
63 https://wikileaks.org/hackingteam/emails/emailid/17076
64 Source: “TNI Datasheet.docx” in e-mail https://wikileaks.org/hackingteam/emails/emailid/511703.
65 https://wikileaks.org/hackingteam/emails/emailid/728653
66 https://wikileaks.org/hackingteam/emails/emailid/18952
67 https://wikileaks.org/hackingteam/emails/emailid/361888
68 https://wikileaks.org/hackingteam/emails/emailid/354147
69 https://wikileaks.org/hackingteam/emails/emailid/482969
70 https://wikileaks.org/hackingteam/emails/emailid/665890
71 https://wikileaks.org/hackingteam/emails/emailid/786233
72 https://wikileaks.org/hackingteam/emails/emailid/31789
73 https://wikileaks.org/hackingteam/emails/emailid/33868
74 https://wikileaks.org/hackingteam/emails/emailid/44184
75 https://wikileaks.org/hackingteam/emails/emailid/27950
76 https://wikileaks.org/hackingteam/emails/emailid/33398
77 https://wikileaks.org/hackingteam/emails/emailid/38800
78 https://wikileaks.org/hackingteam/emails/emailid/43363
79 https://wikileaks.org/hackingteam/emails/emailid/27419
80 https://wikileaks.org/hackingteam/emails/emailid/40565
81 https://www.virustotal.com/en/file/cbde6a113a54b8dcf122d9d879b7c21c8b03a89d792f49210bbe41e8466d121a/analysis/
82 https://www.virustotal.com/en/file/21e8d495bca60edc3b64ac970f9a9fa896d0eadc6491452ea937d64849b1f4a0/analysis/
83 https://wikileaks.org/hackingteam/emails/emailid/686579
84 https://wikileaks.org/hackingteam/emails/emailid/674354
85 https://wikileaks.org/hackingteam/emails/emailid/673712
86 https://wikileaks.org/hackingteam/emails/emailid/676667
87 https://wikileaks.org/hackingteam/emails/emailid/315891
88 https://wikileaks.org/hackingteam/emails/emailid/630854
89 https://wikileaks.org/hackingteam/emails/emailid/1526
90 https://wikileaks.org/hackingteam/emails/emailid/22456
91 https://wikileaks.org/hackingteam/emails/emailid/27582
92 https://wikileaks.org/hackingteam/emails/emailid/27029
93 https://wikileaks.org/hackingteam/emails/emailid/1031218
94 https://wikileaks.org/hackingteam/emails/emailid/25540
95 https://wikileaks.org/hackingteam/emails/emailid/1079340
96 https://wikileaks.org/hackingteam/emails/emailid/1079405
97 This reflects the time of the initial click (i.e., the time in the log of the request for “/fwd”).
98 This reflects whether there is a log entry for the “.apk” file for the IP, indicating that the Hacking Team RCS was installed.
99 https://wikileaks.org/hackingteam/emails/emailid/1079122
100 https://wikileaks.org/hackingteam/emails/emailid/1078587
101 https://wikileaks.org/hackingteam/emails/emailid/1078587
102 https://wikileaks.org/hackingteam/emails/emailid/1078956
103 https://wikileaks.org/hackingteam/emails/emailid/1078956
104 https://wikileaks.org/hackingteam/emails/emailid/1079019
105 https://wikileaks.org/hackingteam/emails/emailid/1079095
106 https://wikileaks.org/hackingteam/emails/emailid/1079095
107 https://wikileaks.org/hackingteam/emails/emailid/1079521
108 https://wikileaks.org/hackingteam/emails/emailid/789
109 https://wikileaks.org/hackingteam/emails/emailid/1450
110 https://wikileaks.org/hackingteam/emails/emailid/779
111 https://wikileaks.org/hackingteam/emails/emailid/1079521
112 https://wikileaks.org/hackingteam/emails/emailid/1526
113 https://www.passivetotal.org/
114 https://wikileaks.org/hackingteam/emails/emailid/25016
115 https://wikileaks.org/hackingteam/emails/emailid/628450
116 https://wikileaks.org/hackingteam/emails/emailid/628450
117 https://wikileaks.org/hackingteam/emails/emailid/371942
118 Shares IP address 119.59.123.78 with free.dramakorea.asia and shrook.mooo.com, according to PassiveTotal.
119 C&C server for newer RCS samples, e.g., https://wikileaks.org/hackingteam/emails/emailid/1078904.
120 https://wikileaks.org/hackingteam/emails/emailid/473090
121 https://wikileaks.org/hackingteam/emails/emailid/1001778

The post What we know about the South Korea NIS’s use of Hacking Team’s RCS appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/what-we-know-about-the-south-korea-niss-use-of-hacking-teams-rcs/feed/ 0
Cyber Stewards selected as Quantified Society grant winners https://citizenlab.org/2015/08/cyber-stewards-selected-as-quantified-society-grant-winners/ https://citizenlab.org/2015/08/cyber-stewards-selected-as-quantified-society-grant-winners/#comments Fri, 07 Aug 2015 16:11:31 +0000 https://citizenlab.org/?p=25865

The Media Democracy Fund, in conjunction with the Ford Foundation and Open Society Foundations, selected Cyber Stewards Network partners Asociación por los Derechos Civiles (ADC) and Derechos Digitales as recipients of the Quantified Society Grants.

The post Cyber Stewards selected as Quantified Society grant winners appeared first on The Citizen Lab.

]]>
Cyber Stewards Network partners Asociación por los Derechos Civiles (ADC) in Argentina and Derechos Digitales in Chile are among the recipients of the Quantified Society Grants, which distribute $270,000 to organizations in 10 countries around the world.

The international Quantified Society called for submissions from researchers, academics, journalists, human rights defenders, civil society organizations, and professionals. The selected proposals are intended to increase understanding of Big Data collection, and associated developments in human rights, innovation, and regulation.

ADC will use the funds to research the implementation of a multifunctional card system by the Buenos Aires city government, which aims to use big data in order to become a “smart city,” while Derechos Digitales will study the practice of mass collection of personal information and the ways in which it is used for labor discrimination in Chile by profiling potential employees.

Read more on the Quantified Society grants on the Media Democracy Fund page.

The post Cyber Stewards selected as Quantified Society grant winners appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/cyber-stewards-selected-as-quantified-society-grant-winners/feed/ 0
Pakistan to ban BlackBerry encrypted messaging https://citizenlab.org/2015/08/pakistan-to-ban-blackberry-encrypted-messaging/ https://citizenlab.org/2015/08/pakistan-to-ban-blackberry-encrypted-messaging/#comments Fri, 07 Aug 2015 15:30:57 +0000 https://citizenlab.org/?p=25862

The Pakistan Telecommunication Authority (PTA), a government agency responsible for the establishment and operation of telecommunications in the country, ordered the shutdown of BlackBerry's encrypted communication services.

The post Pakistan to ban BlackBerry encrypted messaging appeared first on The Citizen Lab.

]]>
The Pakistan Telecommunication Authority (PTA), a government agency responsible for the establishment and operation of telecommunications in the country, ordered the shutdown of BlackBerry’s encrypted communication services for businesses.

Citizen Lab Cyber Stewards Network partner Bytes for All, Pakistan received an internal document from a PTA whistleblower, in which three cellular service providers have been “requested’ to shut down BlackBerry encryption services. The notice asks them to provide 90 days notice to customers, in order that the service be allowed to close by November 30, 2015. The document is signed by Amjad Mustafa Malik, director of Wireless Licensing at the PTA. Telecommunication companies such as Mobilink, Ufone, and Telenor are asked to submit a compliance report within 10 days, given “serious concerns by the Security Agency.”

The government is especially keen to shutdown the Blackberry Enterprise Server (BES), which is used by companies to secure employee communications, and allow system administrators to create their own keys for encryption. This means that there is no backdoor for anyone, including the Pakistani security agency, who may want to decrypt communications. The inability for access via backdoor may explain the PTA’s motivations in banning the service outright.

Citizen Lab Postdoctoral Fellow Christopher Parsons weighed in on the issue, telling the Globe and Mail that “this move suggests BlackBerry wasn’t willing to capitulate to those requests for access.” In an interview with VICE Motherboard, Parsons made the broader observation that “this demonstrates, at a policy level, that a very large government is willing to ban communications if they can’t gain access to it.” He added, “Maybe it’s just Pakistan, and nobody else will do it, but it’s certainly a strong change to, ‘If we can’t backdoor it, then we will ban it.'”

Read the PTA document, or read further information on Bytes for All’s website.

 

The post Pakistan to ban BlackBerry encrypted messaging appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/pakistan-to-ban-blackberry-encrypted-messaging/feed/ 0
Hacking Team leak highlights Citizen Lab research https://citizenlab.org/2015/08/hacking-team-leak-highlights-citizen-lab-research/ https://citizenlab.org/2015/08/hacking-team-leak-highlights-citizen-lab-research/#comments Thu, 06 Aug 2015 20:50:22 +0000 https://citizenlab.org/?p=25781

Hacking Team, a Milan-based developer of “offensive security” technology that markets its products to governments and law enforcement agencies around the world, was significantly compromised when hackers leaked nearly 400 GB of its internal data, including emails, client files, and financial documents. The leak was announced via Hacking Team’s own compromised Twitter account, and the content made publicly available. Among other things, the leaked documents confirmed our findings that the company sells its software to several governments with repressive human rights records, such as Ethiopia, Sudan, Rwanda, Saudi Arabia, Kazakhstan, and more.

The post Hacking Team leak highlights Citizen Lab research appeared first on The Citizen Lab.

]]>
Media coverage: Fast Company, NPR, VICE Motherboard, CSO Online, Washington Post, The InterceptThreatpost, The Korea Times, The Associated Press, The Hamilton Spectator, The Toronto Star.

Hacking Team, a Milan-based developer of “offensive security” technology that markets its products to governments and law enforcement agencies around the world, was significantly compromised when hackers leaked nearly 400 GB of its internal data, including emails, client files, and financial documents. The leak was announced via Hacking Team’s own compromised Twitter account, and the content made publicly available. Among other things, the leaked documents confirmed our findings that the company sells its software to several governments with repressive human rights records, such as Ethiopia, Sudan, Saudi Arabia, Kazakhstan, and more.

Previous Citizen Lab Work

In 2012, the Citizen Lab started researching Hacking Team as a component of several overlapping interests, including technical research and documentation of targeted digital attacks on NGOs and human rights activists, and investigation of the global dissemination of commercial surveillance, filtering, and spyware products. Our first report on Hacking Team, “Backdoors are Forever: Hacking Team and the Targeting of Dissent?,” was published in 2012, when we discovered that a Moroccan civil society group’s computers and those of a prominent United Arab Emirates (UAE) human rights activist were compromised. We were able to positively identify the malicious software on those computers as a Hacking Team product sold to the Moroccan and UAE government secret services, respectively.

In 2014 we continued to publish reports on Hacking Team. The first report, “Hacking Team and the Targeting of Ethiopian Journalists,” showed that Ethiopia’s intelligence services were using Hacking Team’s products to hack and monitor Ethiopian-American journalists based in the United States and Belgium. That report led to front page coverage [PDF] in the Washington Post, and triggered extensive reporting on Hacking Team’s practices. Then, using network measurement techniques, we were able to positively identify the end-points and thus government clients of Hacking Team’s infrastructure in 21 countries, which we reported in “Mapping Hacking Team’s “Untraceable” Spyware”, including many that are notorious abusers of human rights. The final report, “Hacking Team’s US Nexus,” pointed out that Hacking Team products made extensive use of US-based servers to covertly exfiltrate hacked data, and pointed out the policy implications of hacked data transiting the United States. We followed up these reports with an open letter to Hacking Team asking for clarification about their due diligence in light of our findings. We did not receive a response.

Later in 2014, we followed up with two more reports. A report published in June, entitled “Police Story: Hacking Team’s Government Surveillance Malware,” highlighted that Hacking Team’s software appeared to be utilized against Shia minorities in Saudi Arabia through a backdoored copy of a legitimate Android news app, while a report published in August, “Schrodinger’s Cat Video and the Death of Clear-Text,” demonstrated how particular Hacking Team techniques could be used to remotely infect computers. Citizen Lab researchers Bill Marczak, Morgan Marquis-Boire, and John Scott-Railton, along with Professor Vern Paxson of Berkeley, also collaborated on a peer-reviewed academic publication, “When Governments Hack Opponents: A Look at Actors and Technology” [PDF], that laid out what we then knew about commercial malware, including a discussion of Hacking Team.

In 2015, despite the scrutiny and attention to potential abuses stemming from our reporting on the targeting of Ethiopian journalists, we uncovered strong evidence that the Ethiopian government was still receiving support from Hacking Team, as we reported in “Hacking Team Reloaded? US-Based Ethiopian Journalists Again Targeted with Spyware.” Furthermore, after a pause immediately following our 2014 report, attackers were again found to be targeting US-based journalists with Hacking Team spyware. We then wrote a second open letter to Hacking Team, requesting clarification about their customer policies and due diligence. We again did not receive a response.

The Leaks

The leaked emails validate key elements of our research. All of the countries we identified in previous research have been confirmed as Hacking Team clients, as are several other countries of major concern from a human rights perspective. Although Hacking Team publicly questioned the validity of our research, the company’s internal emails detail cases where Hacking Team engineers at times confirm our research. They show the company aggressively courting authoritarian and repressive regimes. In the case of Ethiopia, Hacking Team was aware that their product was used against journalists, yet continued to provide services to the client. Other leaked emails suggest the company attempted to obfuscate the truth to mislead journalists.

Citizen Lab Research Fellow Bill Marczak, who contributed to a series of Citizen Lab reports on Hacking Team, told the Washington Post that the company’s leaked internal reactions in the wake of these reports show that “their primary concern seems to have been not getting caught again.” Research Fellow Claudio Guarnieri, who also worked on Hacking Team reports by the Citizen Lab, told Threatpost that the company is just one of many that markets similar surveillance products. “Hacking Team is just one player in a big market. I suspect others will continue just fine, and probably Hacking Team itself will resurface in a while,” said Guarnieri. In an interview, Director Ron Deibert told the Toronto Star that it was interesting to see that Citizen Lab’s reports had an impact on Hacking Team, though he said that the leaked files were “very discouraging.” “Hacking Team is a symptom of a larger disease,” he added, referring to the sale of spyware to repressive regimes worldwide.

Read more of the Citizen Lab’s reports and posts relating to Hacking Team spyware.

The post Hacking Team leak highlights Citizen Lab research appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/hacking-team-leak-highlights-citizen-lab-research/feed/ 0
Authoritarianism Goes Global: Cyberspace Under Siege https://citizenlab.org/2015/08/ron-deibert-authors-journal-article-titled-authoritarianism-goes-global-cyberspace-under-siege/ https://citizenlab.org/2015/08/ron-deibert-authors-journal-article-titled-authoritarianism-goes-global-cyberspace-under-siege/#comments Thu, 06 Aug 2015 15:49:53 +0000 https://citizenlab.org/?p=25835

Citizen Lab Director Ron Deibert authored an article in the June 2015 edition of the Journal of Democracy, titled "Authoritarianism Goes Global: Cyberspace Under Siege."

The post Authoritarianism Goes Global: Cyberspace Under Siege appeared first on The Citizen Lab.

]]>
Citizen Lab Director Ron Deibert authored an article titled “Authoritarianism Goes Global: Cyberspace Under Siege,” published in the July 2015 edition of the Journal of Democracy. In the article, Deibert argues that authoritarianism in cyberspace has evolved over three generations of information controls. He goes on to account for the range of methods frequently used by these regimes to control the Internet, including technical measures, laws, targeted malware attacks, and campaigns to coopt social media.

Read the full journal article or read the analysis by Resurgent Dictatorship.

In a related event, Ron Deibert spoke at the International Forum for Democratic Studies at the National Endowment for Democracy (NED), joining a panel discussion on “The Global Campaign Against Democratic Norms.”

The post Authoritarianism Goes Global: Cyberspace Under Siege appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/08/ron-deibert-authors-journal-article-titled-authoritarianism-goes-global-cyberspace-under-siege/feed/ 0
Ron Deibert at the National Endowment for Democracy https://citizenlab.org/2015/07/ron-deibert-speaks-at-the-national-endowment-for-democracy/ https://citizenlab.org/2015/07/ron-deibert-speaks-at-the-national-endowment-for-democracy/#comments Mon, 27 Jul 2015 14:42:08 +0000 https://citizenlab.org/?p=25802

Citizen Lab Director Ron Deibert spoke at the International Forum for Democratic Studies at the National Endowment for Democracy (NED), joining a panel discussion on "The Global Campaign Against Democratic Norms."

The post Ron Deibert at the National Endowment for Democracy appeared first on The Citizen Lab.

]]>
Citizen Lab Director Ron Deibert spoke at the International Forum for Democratic Studies at the National Endowment for Democracy (NED), joining a panel discussion on “The Global Campaign Against Democratic Norms.”

The event, which took place in Washington DC, also featured Alexander Cooley, Director of the Harriman Institute at Columbia University, Steven Heydemann, Former Vice President of Applied Research on Conflict and Senior Advisor at the U.S Institute of Peace, and Christopher Sabatini, Adjunct Professor of International Affairs at Columbia University.

Panelists discussed the emergence of a number of new antidemocratic norms, justified as regional security or state sovereignty. Broader trends also suggest that authoritarian regimes are seeking to reshape Internet governance standards. For example, Russia and China’s domestic political norms are extending beyond their own borders via organizations such as the Shanghai Cooperation Organization, the Commonwealth of Independent States, and the Eurasian Economic Union. Similarly,in the Middle East, the Gulf Cooperation Council has sought to crack down on dissent by coordinating member efforts. The panelists discussed the implications of this campaign for Eurasia, North Africa, Latin America, the Middle East, and global cyberspace.

Read full conference details and watch a video stream of the panel.

 

The post Ron Deibert at the National Endowment for Democracy appeared first on The Citizen Lab.

]]>
https://citizenlab.org/2015/07/ron-deibert-speaks-at-the-national-endowment-for-democracy/feed/ 0