Skype set up secret project to enable government snooping

SkypeBy IAN ALLEN | intelNews.org |
Skype, the world-famous company that provides Internet-based communications between registered users, set up a secret project five years ago to facilitate persistent requests by government agencies to listen in on users’ phone calls. The New York Times revealed the secret project, codenamed Project CHESS, on Wednesday, citing individuals with inside knowledge of the program, who asked to remain anonymous so as “to avoid trouble with the intelligence agencies”. For many years, it was believed that the US National Security Agency (NSA) and other intelligence agencies had found it impossible to intercept Skype’s instant messaging and voice traffic. This was because, like other voice-over-Internet protocol (VOIP) communications providers, Skype uses technology that converts audio signals to data, and transports them through most of the Internet infrastructure in binary, rather than audio, format. Furthermore, Skype uses very complex algorithms to encrypt its customers’ communications. The company had repeatedly pointed to the technical complexities of VOIP communications in arguing that it was often technically impossible to facilitate communications interception requests by government authorities. In 2009, rumors began to circulate in the cybersecurity community that Skype’s VOIP encryption system had been cracked. It now seems that, around that time, the company, which was then still owned by eBay, was already negotiating with the United States government in order to help intelligence agencies gain access to its users’ communications. Read more of this post

News you may have missed #739

The US Department of DefenseBy IAN ALLEN | intelNews.org |
►►US Supreme Court to consider case on secret wiretapping. The Supreme Court has agreed to consider blocking a constitutional challenge to the government’s secret wiretapping of international phone calls and emails. At issue is whether Americans who have regular dealings with overseas clients and co-workers can sue to challenge the sweep of this surveillance if they have a “reasonable fear” their calls will be monitored. The case, to be heard in the fall, will put a spotlight on a secret surveillance program that won congressional approval in the last year of President George W. Bush’s presidency.
►►Analysis: Why is CIA applauding DoD’s intel grab? Last month, Director of National Intelligence James Clapper and Secretary of Defense Leon Panetta announced the creation of a new US espionage agency: the Defense Clandestine Service, or DCS. The new agency is expected to expand the Pentagon’s espionage personnel by several hundred over the next few years, while reportedly leaving budgets largely unchanged. The news nonetheless surprised some observers in Washington because the move appeared, at least initially, to be a direct challenge to the Central Intelligence Agency, whose National Clandestine Service leads the country’s spy work overseas. Then came a second surprise: former CIA officers and other intelligence experts started applauding. The question is why.
►►FBI forms secretive online surveillance unit. On May 22, CNet’s Declan McCullagh revealed that the FBI had quietly formed a new Domestic Communications Assistance Center (DCAC), tasked with developing new electronic surveillance technologies, including intercepting Internet, wireless, and VoIP communications. According to McCullagh, DCAC’s goal is “to invent technology that will […] more readily eavesdrop on Internet and wireless communications”. Read more of this post

News you may have missed #710

Jonathan PollardBy IAN ALLEN | intelNews.org |
►►MI6 officer murder inquest to be held in secret. Britain’s Foreign Secretary William Hague has ordered that key evidence in the inquest into the death of MI6 officer Gareth Williams is to be heard in secret. Williams, who was found dead in a padlocked sports bag in the bath of his London apartment 20 months ago, was on secondment to MI6 from GCHQ, the British government’s signals intelligence agency, and had worked closely with the American security services.
►►GCHQ warns it is losing terrorists on the internet. Speaking of the GCHQ, the organization says that modern internet technology has left them unable to intercept calls which use new technology instead of traditional phone systems. Britain’s Daily Telegraph quotes “senior intelligence sources with detail knowledge of the problem”, who say that GCHQ technical experts have seen their access to telephone intercept information “eroded” by the use of the technologies such as Voice Over Internet Protocol, or VoIP, which route telephone calls over the world wide web.
►►Israel pressures Obama to release Jewish spy. Israel’s Prime Minister Benjamin Netanyahu has again called on the United States to release convicted spy Jonathan Pollard after the former US Navy intelligence analyst was hospitalized this week. Pollard, an American of Jewish descent, was sentenced to life in prison 25 years ago for leaking classified documents to Israel. Many Israelis believe the sentence was too harsh and officials often demand his release. But Democratic and Republican administrations in the US have repeatedly refused Israeli appeals to release the convicted spy.

News you may have missed #689: NSA edition

Michael HaydenBy IAN ALLEN| intelNews.org |
►►Ex-NSA Director calls Stuxnet a ‘good idea’. General Michael Hayden, once head of the NSA and CIA, who was no longer in office when the Stuxnet attack on Iran occurred, but who would have been around when the computer virus was created, denies knowing who was behind it. He calls Stuxnet “a good idea”. But he also admits “this was a big idea, too. The rest of the world is looking at this and saying, ‘clearly, someone has legitimated this kind of activity as acceptable'”.
►►NSA develops secure Android phones. The US National Security Agency has developed and published details of an encrypted VoIP communications system using commercial off-the-shelf components and an Android operating system. A hundred US government employees participated in a pilot of Motorola hardware running hardened VoIP called ‘Project FISHBOWL’, NSA Information Assurance Directorate technical director Margaret Salter told the RSA Conference in San Francisco on Wednesday. “The beauty of our strategy is that we looked at all of the components, and took stuff out of the operating system we didn’t need”, said Salter. “This makes the attack surface very small”.
►►Senior US Defense official says DHS should lead cybersecurity. In the midst of an ongoing turf battle over how big a role the National Security Agency should play in securing America’s critical infrastructure, Eric Rosenbach, deputy assistant secretary of Defense for Cyber Policy in the Department of Defense, said on Wednesday that the NSA should take a backseat to the Department of Homeland Security in this regard. “Obviously, there are amazing resources at NSA, a lot of magic that goes on there”, he said. “But it’s almost certainly not the right approach for the United States of America to have a foreign intelligence focus on domestic networks, doing something that throughout history has been a domestic function”.

News you may have missed #527

  • Has Microsoft broken Skype’s encryption? The US Congress has finally discovered Skype. But the timing may be bad, since there are rumors that Microsoft has found a way to break the encryption behind Skype communications, rendering all Skype calls potentially open to surveillance by governments. The company (Microsoft) has even filed a related patent application. Communications interception experts have been trying for some time to achieve this.
  • Ex-CIA agent loses legal battle over ‘unauthorized’ book. A former CIA deep-cover operative, who goes by the pseudonym ‘Ishmael Jones’, may have to financially compensate the Agency for publishing a book without the CIA’s approval, after a US judge ruled against him. Jones maintains that the CIA is bullying him because of his public criticism of its practices.
  • Family of accused Australian spy seeks support. The family of Australian-Jordanian citizen Eyad Abuarga, who has been charged with being a technical spy for Hamas, have called on the Australian government to do more to help him, with less than a month before he is due to face trial in Israel.

Police see ‘professional job’ in British spy’s death

Gareth Williams

Gareth Williams

By JOSEPH FITSANAKIS | intelNews.org |
As authorities investigate the recent death of British spy Dr. Gareth Williams, the country’s notorious tabloid media industry is having a field day disorienting interested observers. It is thus easy to miss important news breakthroughs in the cacophony of sensationalized headlines about Williams, whose body was discovered a week ago, stuffed in a sports duffle bag in the bath of his London apartment. One such breakthrough was yesterday’s report by Britain’s widely respected Channel 4, which said that law enforcement investigators described Williams’ death as “a neat job”, a term used to refer to professional killings. The Channel 4 report was preceded by strong official denials by police that Williams’ murder was sex-related, as had been previously reported. Some investigators now believe that Williams was killed by a foreign agent, who then deliberately “planted a trail of clues” pointing to a homosexual link to the death. Read more of this post

News you may have missed #0286 (Internet edition)

  • Email trojan targeted at US .gov, .mil accounts. A Trojan-containing email, which is spoofed so that it appears to have been sent by the US National Intelligence Council, appears to have been directed solely at US government and military email accounts.
  • Analysis: Smuggling secret information through VOIP. Voice over Internet Protocol (VOIP) systems use a series of protocols to essentially create an open, unmediated link between two computers. VOIP applications also provide a way to make sure the packets are ordered quickly and correctly. And that’s a goldmine for anyone trying to send hidden messages.
  • ACLU concerned about Google-NSA partnership. Google corporation has turned to the US National Security Agency for assistance in warding off cyberattacks. But the American Civil Liberties Union is among several organizations that view the partnership as “troubling”.

Bookmark and Share

News you may have missed #0128

  • US government appeals judge’s order in Cuban Five spy case. US government officials are contending a judge’s order because they say it would be detrimental to US national security. The order requires the US government to turn over any national security damage assessments in the Cuban Five case. Washington accuses the Five of spying on the US for Cuba. Three of the five are to be given new sentences on October 13 after an appeals court ruled that the initial sentences they received (ranging from 19 years to life) were too long.
  • Indian spies want access to missed calls. Indian security agencies have told the country’s Department of Telecommunications that they need access to missed calls because “anti-social elements” may be using the system to communicate without actually making a call. Last month, India’s Intelligence Bureau asked for all VOIP (internet-based) calls in the country to be blocked until it figures out a mechanism to track them. It also said it wants access to the content of all mobile phone calls in the country.
  • New book investigates Stasi’s scientific espionage. Documents from the vaults of HVA (Hauptverwaltung Aufklärung), the foreign department of the Stasi, the East German Ministry for State Security, which were purchased by the CIA from a German informant in 1992, were made available in 2005 to Kristie Macrakis professor of history at the Georgia Institute of Technology in Atlanta. Her book, Seduced by Secrets: Inside the Stasi’s Spy-Tech World, offers a rare look into the Stasi’s secret technical methods and sources. Macrakis’s analysis of the CIA material reportedly reveals that about 40% of all HVA sources planted in West German companies, research institutions and universities were stealing scientific and technical secrets.

Bookmark and Share

News you may have missed #0108

  • Fatah dismisses spy chief in West Bank. Palestinian President Mahmoud Abbas has dismissed Palestinian General Intelligence Chief Mohammad Abu Assam. The dismissal appears to be part of a broader plan to unify the Palestinian Preventive Security Service and the General Intelligence Service, who have been fighting a notorious turf war for several years.
  • Indian Intelligence Bureau wants to block all VOIP Services. India’s Intelligence Bureau has instructed the country’s communications ministry to block all VOIP (internet-based) calls in the country until it figures out a mechanism to track them. It has also said it wants access to the content of all mobile phone calls in the country. Indian security agencies have been struggling with this issue since the 2008 Mumbai attacks, after it emerged that the attackers used VOIP software to communicate with the their handlers.
  • Is Afghan President’s brother a US informant? There is speculation that Ahmed Wali Karzai, notorious drug lord and younger brother of Afghan President Hamid Karzai, is in fact an informant for US intelligence agencies. It true, this would explain why he has been allowed by US agencies to operate freely in the country.

Bookmark and Share

News you may have missed #0088

Bookmark and Share

Has Skype’s VOIP encryption been broken?

NSA HQ

NSA HQ

By IAN ALLEN | intelNews.org |
I have explained before that the US National Security Agency (NSA) and other intelligence agencies have found it impossible to intercept Skype’s instant messaging and voice traffic. Like other voice-over-Internet protocol (VOIP) communications providers, Skype uses technology that converts audio signals to data, and transports them through most of the Internet infrastructure in binary, rather than audio, format. Furthermore, Skype uses very complex algorithms to encrypt its customers’ communications. Skype has repeatedly pointed to the technical complexities of VOIP communications, arguing that it is often technically impossible to facilitate communications interception requests by government authorities. There are rumors among communications interception specialists that the NSA is offering billions to anyone who can come up with a reliable eavesdropping model for Skype. Remarkably, on August 25, a Swiss software developer released what he claims is the source code of a program for tapping into encrypted Skype communications. I don’t know whether the source code (essentially a trojan) is effective. He claims it is. If this is confirmed, then several people in Fort George F. Meade, Maryland, will be really close paying attention.

Bookmark and Share

Comment: EU wants to intercept encrypted VOIP communications

By IAN ALLEN| intelNews.org |
Italian authorities are taking the initiative in a European Union (EU)-wide effort to terminate the tacit immunity of voice-over-Internet-protocol (VOIP) communications from authorized interception. Italy’s delegation to Eurojust, an EU coordination body tasked with combating transnational organized crime, issued a statement last weekend, promising to spearhead a project to “overcome the technical and judicial obstacles to the interception of internet telephony systems”. The statement contains several references to Skype, a Luxembourg-based VOIP provider that has so far reportedly refused to share its communications encryption system with government authorities. Because of this, the latter have accused Skype of providing organized crime syndicates with the ability to communicate without fear of their messages being intercepted.

Read more of this post

Unprotected Wi-Fi now seen as security threat in India

By IAN ALLEN | intelNews.org |
IntelNews has been reporting on the interesting technical intelligence details of the November 2008 attacks in the Indian city of Mumbai. On January 7, we explained that the organizers of the attacks used a virtual number, 1-201-253-1824, set up by a California-based VOIP (voice-over-Internet protocol) telecommunications provider, to communicate with the assailants on the ground in real-time. Now the Mumbai Police have said they will start monitoring the city’s neighborhoods for unprotected Wi-Fi networks, and instructing their owners to secure them on the spot. This is because militant groups have apparently been logging on to unprotected wireless networks to sent emails claiming responsibility for several attacks in the country. Last November it emerged that the email claiming responsibility for the Mumbai attacks was sent by an individual with “technical expertise and their knowledge of sophisticated [anonymizing] software”.

Further technical details emerge on Mumbai attacks

Mumbai attacker

Mumbai attacker

By IAN ALLEN | intelNews.org |
On December 9, we reported that the Pakistani militant group, Lashkar-e-Taiba, used voice-over-Internet-protocol (VOIP) software to communicate with the perpetrators of the 2008 Mumbai attacks on the ground and direct the operation on a real-time basis. We further noted that VOIP signals pose severe barriers to communications interception, as well as to the ability of law enforcement and intelligence agencies to locate the source of target calls. The Mumbai attacks were a typical example of this. Thus, even though Indian intelligence services know that the handlers of the Mumbai attackers were located in Pakistan, their VOIP communications data pointed to companies in New Jersey and Austria. Further details have now emerged of a virtual number, 1-201-253-1824, which the handlers of the Mumbai attackers actually generated via a California-based VOIP provider. Read more of this post