Showing posts with label Social Networking. Show all posts
Showing posts with label Social Networking. Show all posts

Saturday, June 27, 2009

Activists Use U.S. Tech to Poke Holes in Iran Firewall (Danger Room)

Activists Use U.S. Tech to Poke Holes in Iran Firewall (Updated)

73239afd-bbdc-4f45-bb52-4c5109d50511_mw800_mh600Tehran's demonstrators rose up by themselves. But the technology that helped them organize — and helped them connect with the rest of the planet — was funded in part by the U.S. government.

Early in the pro-democracy protests, everyone made a big deal out of the State Department's call to Twitter, asking the short-messaging firm to reschedule maintenance so the Iranian opposition movement could keep communicating. In retrospect, that might have been one of least meaningful moves an American agency made on the activists' behalf. More important, it now appears, are the millions of dollars invested over the years in technologies that could pry open the Iranian firewall — and avoid the Supreme Leader's web censors.

"Our goal was to promote freedom of speech for Iranians to communicate with each other and the outside world. We funded and supported innovative technologies to allow them to do this via the Internet, cell phones and other media," former State Department Iran democracy program coordinator David Denehy tells Eli Lake of the Washington Times.

Forget the driven-by-DC mock-populism and the all-too-clever schemes; this is how America should be promoting democracy abroad. Give activists the tools — and then let them decide how and when to use 'em.

The Broadcasting Board of Governors (BBG), which oversees the Voice of America and the Farsi-language Radio Farda, has a three-person anti-censorship team that focuses on China and Iran. "Iran has a growing audience of young activist Internet users and we have repurposed our tools to work in Farsi and make it available to Iranians," BBG's Ken Berman says. "We open up the channels so the Iranian blogosphere is more accessible to Iranians in Iran."

One of those projects: design the Firefox Web browser to embed the TOR network. That's the "onion router" anonymous surfing service, which throws off the Supreme Leader's online goons by "distributing your transactions over several places on the Internet, so no single point can link you to your destination," the project's site explains. "The idea is similar to using a twisty, hard-to-follow route in order to throw off somebody who is tailing you — and then periodically erasing your footprints. Instead of taking a direct route from source to destination, data packets on the Tor network take a random pathway through several relays that cover your tracks so no observer at any single point can tell where the data came from or where it's going."

"There are plenty of programs political dissidents can use to route their Internet traffic through third parties and escape censorship and avoid monitoring," one know-it-all blogger tells Lake. "But TOR is different because it is an encrypted network of node after node, each one unlocking encryption to the next node. And because of this, it is all but impossible for governments to track Web sites a TOR user is visiting. TOR is a great way to give Ahmadinejad's Web censors headaches."

That onion routing approach was originally developed by the Naval Research Lab and by Darpa, the Pentagon's leading science and technology arm.

UPDATE: Slate's Farhad Manjoo, on the other hand, thinks all this tech has actually made it easier for the regime to repress the activists. "On Wednesday, a reader alerted the Lede to an Iranian government Web site called Gerdab.ir, where authorities had posted pictures of protesters and were asking citizens for help in identifying the activists. That's right—the regime is now using crowd-sourcing, one of the most-hyped aspects of Web 2.0 organizing, against its opponents. If you think about it, that's no surprise. Who said that only the good guys get to use the power of the Web to their advantage?"

Saturday, June 20, 2009

DOD warns against the dark side of social networking (GCN)

DOD warns against the dark side of social networking

The pull of the online world is strong, but security must be maintained

By David F. Carr, Special to GCN
Jun 18, 2009

http://gcn.com/articles/2009/06/18/dod-on-dark-side-of-social-networking.aspx

In an earlier era, "loose lips sink ships" was the military's warning not to let even small details about military movements and operations slip in casual conversation. In contrast, social media Web sites today thrive on loose lips, making it even tougher to maintain operational security.

The problem is not so much people twittering away secrets as letting slip many smaller pieces of information that an adversary can piece together.

"There's a tendency to think that if information is not classified, it's OK to share," said Jack Kiesler, chief of cyber counter intelligence at the Defense Intelligence Agency, in a presentation last month in Orlando, Fla., at the DODIIS Worldwide Conference for intelligence information systems professionals.

Kiesler and colleague Nick Jensen, an operational security analyst at DIA, gave a presentation titled "How Adversaries Exploit Poor Operational Security."

Operational security refers to the process of denying information to potential adversaries about capabilities or intentions of individuals or organizations by identifying and protecting generally unclassified information on the planning and execution of sensitive activities.

An adversary trying to uncover secrets will start by chipping away at operational security indicators that point them toward a target, Kiesler said. A foreign agent seeking to steal stealth technology might start by trying to identify individuals who are working on the technology, figuring out whom they associate with, following their movements, looking for clues on new research areas and so on.

Much of that information might be available through a professional profile on LinkedIn, for example. Furthermore, participation in online discussion groups or blogs might help foreign intelligence services single out disgruntled military or intelligence agency employees who could be recruited or blackmailed, Kiesler said. Not only are younger employees immersed in the social media culture, but older ones often become participants without understanding their limited control over the information they post online, he added.

Although operational security is supposed to be a standard component of military operations, Kiesler seeks to pursue it in a more disciplined way, with proactive tests of an organization's operational security. Rather than embarrassing the organizations and individuals who flunk the test, the goal is to educate them, he said.

Jensen presented a fictional scenario that he said was based on those kinds of tests, in which a foreign agent named Jane starts by exploring the membership of a LinkedIn group called Intelligence Professionals.

In Jensen's scenario, LinkedIn provides a target DIA employee's basic résumé with a link to his blog. The blog, in turn, has links to other social media sites the person participates in, so the adversary can browse Flickr photos and Twitter messages, continuing to round out the picture. The DIA employee uses the same handle on many Web sites, allowing Jane to search for posts he has made elsewhere. On Slashdot, he mentions something about the Starbucks near his house.

That allows Jane to bump into her target at Starbucks, hack the wireless session he initiates from his iPhone and eventually capture information, including his online banking password. From there, she has many options to monitor his every move, drain his bank account or blackmail him.

Of course, the pull of the online world is not so easily countered. There really is an Intelligence Professionals group on LinkedIn, and Kiesler and Jensen found 163 LinkedIn members who listed DIA as their current employer, including at least one information security analyst based in Washington, D.C.

But Kiesler and Jensen said people can learn to be more circumspect and take precautions such as varying their online signatures rather than using the same user name on multiple Web sites.