Showing posts with label civil liberties. Show all posts
Showing posts with label civil liberties. Show all posts
Lady Liberty
Wednesday, 1 May 2013
The Statue of Liberty is getting a facelift, though the changes aren’t only cosmetic. An upgraded "state of the art" security system will help keep Lady Liberty safe when it reopens soon. But what does the system entail, and could it involve a controversial new face-recognition technology that can detect visitors’ ethnicity from a distance? I tried to find out — and a New York surveillance company tried to stop me.
Face recognition was first implemented at the Statue of Liberty in 2002 as part of an attempt to spot suspected terrorists whose mug shots were stored on a federal database. At the time, the initiative was lambasted by the American Civil Liberties Union, which said it was so ineffective that “Osama Bin Laden himself” could easily dodge it.
But the technology has advanced since then: Late last year, trade magazine Police Product Insight reported that a trial of the latest face-recognition software was being planned at the Statue of Liberty for the end of 2012 to “help law enforcement and intelligence agencies spot suspicious activity.” New York surveillance camera contractor Total Recall Corp. was quoted as having told the magazine that it was set for trial at the famed tourist attraction software called FaceVACS, made by German firm Cognitec. FaceVACS, Cognitec boasts in marketing materials, can guess ethnicity based on a person’s skin color, flag suspects on watch lists, estimate the age of a person, detect gender, “track” faces in real time, and help identify suspects if they have tried to evade detection by putting on glasses, growing a beard, or changing their hairstyle. Some versions of face-recognition software used today remain ineffective, as investigators found in the aftermath of the Boston bombings. But Cognitec claims its latest technology has a far higher accuracy rating — and is certainly more advanced than the earlier versions of face-recognition software, like the kind used at the Statue of Liberty back in 2002. (It is not clear whether the face-recognition technology remained in use at the statue after 2002.)
Liberty Island took such a severe battering during Sandy that it has stayed closed to the public ever since — thwarting the prospect of a pilot of the new software. But the statue, which attracts more than 3 million visitors annually according to estimates, is finally due to open again on July 4. In March, Statue of Liberty superintendent Dave Luchsinger told me that plans were underway to install an upgraded surveillance system in time for the reopening. “We are moving forward with the proposal that Total Recall has come up with,” he said, adding that “[new] systems are going in, and I know they are state of the art.”
When it came to my questions about face recognition, though, things started to get murky. Was that particular project back on track? “We do work with Cognitec, but right now because of what happened with Sandy it put a lot of different pilots that we are doing on hold,” Peter Millius, Total Recall’s director of business development, said in a phone call. “It’s still months away, and the facial recognition right now is not going to be part of this phase.” Then, he put me on hold and came back a few minutes later with a different position — insisting that the face-recognition project had in fact been “vetoed” by the Park Police and adding that I was “not authorized” to write about it.
That was weird, but it soon got weirder. About an hour after I spoke with Total Recall, an email from Cognitec landed in my inbox. It was from the company’s marketing manager, Elke Oberg, who had just one day earlier told me in a phone interview that “yes, they are going to try out our technology there” in response to questions about a face-recognition pilot at the statue. Now, Oberg had sent a letter ordering me to “refrain from publishing any information about the use of face recognition at the Statue of Liberty.” It said that I had “false information,” that the project had been “cancelled,” and that if I wrote about it, there would be “legal action.” Total Recall then separately sent me an almost identical letter — warning me not to write “any information about Total Recall and the Statue of Liberty or the use of face recognition at the Statue of Liberty.” Both companies declined further requests for comment, and Millius at Total Recall even threatened to take legal action against me personally if I continued to “harass” him with additional questions. (You can read the full correspondence here.)
Linda Friar, a National Park Service spokeswoman, confirmed that the procurement process for security screening equipment is ongoing, but she refused to comment on whether the camera surveillance system inside the statue was being upgraded on the grounds that it was “sensitive information.” So will there be a trial of new face-recognition software — or did the Park Police “cancel” or “veto” this? It would probably be easier to squeeze blood from a stone than to obtain answers to those questions. “I’m not going to show my hand as far as what security technologies we have,” Greg Norman, Park Police captain at Liberty Island, said in a brief phone interview.
The great irony here, of course, is that this is a story about a statue that stands to represent freedom and democracy in the modern world. Yet at the heart of it are corporations issuing crude threats in an attempt to stifle legitimate journalism — and by extension dictate what citizens can and cannot know about the potential use of contentious surveillance tools used to monitor them as they visit that very statue. Whether Cognitec's ethnicity-detecting face recognition software will eventually be implemented at Lady Liberty remains to be seen. What is certain, however, is that the attempt to silence reporting on the mere prospect of it is part of an alarming wider trend to curtail discussion about new security technologies that are (re)shaping society.
This article first appeared at Slate.
Governments turn to hacking techniques for surveillance of citizens
Friday, 11 November 2011

In a luxury Washington, DC, hotel last month, governments from around the world gathered to discuss surveillance technology they would rather you did not know about. The annual Intelligence Support Systems (ISS) World Americas conference is a kind of mecca for representatives from intelligence agencies and law enforcement. But to the media or members of the public, it is strictly off limits.
Gone are the days when mere telephone wiretaps satisfied authorities’ intelligence needs. Behind the cloak of secrecy at the ISS World conference, tips are shared about the latest advanced “lawful interception” methods used to spy on citizens – computer hacking, covert bugging and GPS tracking. Smartphones, email, instant message services and free chat services such as Skype have revolutionised communication. This has been matched by the development of increasingly sophisticated surveillance technology.
Among the pioneers is Hampshire-based Gamma International, a core ISS World sponsor. In April, Gamma made headlines when Egyptian activists raided state security offices in Cairo and found documents revealing Gamma had in 2010 offered Hosni Mubarak's regime spy technology named FinFisher. The "IT intrusion" solutions offered by Gamma would have enabled authorities to infect targeted computers with a spyware virus so they could covertly monitor Skype conversations and other communications.
The use of such methods is more commonly associated with criminal hacking groups, who have used spyware and trojan horse viruses to infect computers and steal bank details or passwords. But as the internet has grown, intelligence agencies and law enforcement have adopted similar techniques.
“Traditionally communications flowed through phone companies, but consumers are increasingly using communications that operate outwith their jurisdiction. This changes the way interception is carried out … the current method of choice would seem to be spyware, or trojan horses,” says Chris Soghoian, a Washington-based surveillance and privacy expert. “There’s now a thriving outsourced surveillance industry and they are there to meet the needs and wants of countries from around the world, including those who are more – and less – respectful to human rights.”
In 2009, while a government employee, Soghoian attended ISS World. He made recordings of seminars and later published them online – which led him to be the subject of an investigation and, ultimately, cost him his Federal Trade Commission job. The level of secrecy around the sale of such technology by western companies, he believes, is cause for alarm.
“When there are five or six conferences held in closed locations every year, where telecommunications companies, surveillance companies and government ministers meet in secret to cut deals, buy equipment, and discuss the latest methods to intercept their citizens’ communications – that I think meets the level of concern,” he says. “They say that they are doing it with the best of intentions. And they say that they are doing it in a way that they have checks and balances and controls to make sure that these technologies are not being abused. But decades of history show that surveillance powers are abused – usually for political purposes.”
Another company that annually attends ISS World is Italian surveillance developer Hacking Team. A small, 35-employee software house based in Milan, Hacking Team's technology – which costs over £500,000 for a “medium-sized installation” – gives authorities the ability to break into computers or smartphones, allowing targeted systems to be remotely controlled. It can secretly enable the microphone on a targeted computer and even take clandestine snapshots using its webcam, sending the pictures and audio along with any other information – such as emails, passwords and word documents – back to the authorities for inspection. The smartphone version of the software has the ability to track a person’s movements via GPS as well as perform a function described as “remote audio spy”, effectively turning the phone into a bug without its user’s knowledge. The venture capital-backed company boasts that its technology can be used "country-wide" to monitor over 100,000 targets simultaneously, and cannot be detected by anti-virus software.
“Information such as address books or SMS messages or images or documents might never leave the device. Such data might never be sent to the network. The only way to get it is to hack the terminal device, take control of it and finally access to the relevant data,” says David Vincenzetti, founding partner of Hacking Team, who adds that the company has sold its software in 30 countries across five continents. "Our investors have set up a legal committee whose goal is to promptly and continuously advise us on the status of each country we are talking to. The committee takes into account UN resolutions, international treaties, Human Rights Watch and Amnesty International recommendations."
Three weeks ago Berlin-based hacker collective the Chaos Computer Club (CCC) exposed covert spy software used by German police forces similar to that offered by Hacking Team. The "Bundestrojaner [federal trojan]” software, which state officials confirmed had been used, gave law enforcement the power to gain complete control over an infected computer. The revelation prompted an outcry in Germany, as the use of such methods is strictly regulated under the country’s constitutional law. (A court ruling in 2008 established a “basic right to the confidentiality and integrity of information-technological systems”.)
“Lots of what intelligence agencies have been doing in the last few years is basically computer infiltration, getting data from computers and installing trojans on other people’s computers,” says Frank Rieger, a CCC spokesman. “It has become part of the game, and what we see now is a diffusion of intelligence methods into normal police work. We’re seeing the same mindset creeping in. They’re using the same surreptitious methods to gain knowledge without remembering that they are the police and they need to follow due process.”
In the UK there is legislation in place governing the use of all intrusive surveillance. Covert intelligence gathering by law enforcement or government agencies is currently regulated under the Regulation of Investigatory Powers Act (Ripa), which states that to intercept communications a warrant must be authorised by the Home Secretary and be deemed necessary and proportionate in the interests of national security, public safety or the economic well-being of the country. There were 1682 interception warrants approved by the Home Secretary in 2010, latest official figures show.
According to Jonathan Krause, an IT security expert who previously worked for Scotland Yard's hi-tech crime unit, bugging computers is becoming an increasingly important methodology for UK law enforcement. “There are trojans that will be customer written to get past usual security, firewalls, malware scanning and anti-virus devices, but these sorts of things will only be aimed at serious criminals,” he says.
Concerns remain, however, that despite export control regulations, western companies have been supplying high-tech surveillance software to countries where there is little – or no – legislation governing its use. In 2009, for instance, it was discovered that American developer SS8 had supplied the United Arab Emirates with smartphone spyware, after around 100,000 users were sent a bogus software update by telecommunications company Etisalat. The technology – if left undetected – would have enabled authorities to bypass Blackberry email encryption by mining communications from devices before they were sent.
Computer security researcher Jacob Appelbaum is well aware what it is like to be a target of covert surveillance. He is a core member of the Tor Project, which develops free internet anonymysing software used by activists and government dissidents across the Middle East and north Africa to evade government monitoring. A former spokesman for WikiLeaks, Appelbaum has had his own personal emails scrutinised by the US government as part of an ongoing grand jury investigation into the whisteblower organisation. On 13 October he was in attendance at ISS World where he was hoping to arrange a presentation about Tor – only to be ejected after one of the surveillance companies complained about his presence.
“There’s something to be said about how these guys are not interested in regulating themselves and they’re interested in keeping people in the dark about what they’re doing,” he says. “These people are not unlike mercenaries. The companies don’t care about anything, except what the law says. In this case, if the law’s ambiguous, they’ll do whatever the law doesn’t explicitly deny. It’s all about money for them, and they don’t care.
“This tactical exploitation stuff, where they’re breaking into people’s computers, bugging them… they make these arguments that it’s good, that it saves lives. But we have examples that show this is not true. I was just in Tunisia a couple of days ago and I met people who told me that posting on Facebook resulted in death squads showing up in your house."
The growth in the use of these methods across the world, Appelbaum believes, means governments now have a vested interest in keeping computer users' security open to vulnerabilities. "Intelligence [agencies] want to keep computers weak as it makes it easier to surveil you," he says, adding that an increase in demand for such technology among law enforcement agencies is of equal concern.
“I don’t actually think breaking into the computer of a terrorist is the world’s worst idea – it might in fact be the only option – but these guys [surveillance technology companies] are trying to sell to any police officer," he says. "I mean, what business does the Baltimore local police have doing tactical exploitation into people’s computers? They have no business doing that. They could just go to the house, serve a warrant, and take the computer. This is a kind of state terror that is simply unacceptable in my opinion.”
Jerry Lucas, the president of the company behind ISS World, TeleStrategies, does not deny surveillance developers that attend his conference supply to repressive regimes. In fact, he is adamant that the manufacturers of surveillance technology, like Gamma International, SS8 and Hacking Team, should be allowed to sell to whoever they want.
“The surveillance that we display in our conferences, and discuss how to use, is available to any country in the world,” he says. “Do some countries use this technology to suppress political statements? Yes, I would say that’s probably fair to say. But who are the vendors to say that the technology is being not being used for good as well as for what you would consider not so good.”
Would he be comfortable in the knowledge that regimes in Zimbabwe and North Korea were purchasing this technology from western companies? “That’s just not my job to determine who’s a bad country and who’s a good country. That’s not our business, we’re not politicians … we’re a for profit company. Our business is bringing governments together who want to buy this technology.”
TeleStrategies organises a number of conferences around the world, including in Europe, the Middle East and Asia Pacific. Every country has a need for the latest covert IT intrusion technology, according to Lucas, because modern criminal investigations cannot be conducted without it. He claims “99.9 per cent good comes from the industry” and accuses the media of not covering surveillance-related issues objectively.
“I mean, you can sell cars to Libyan rebels, and those cars and trucks are used as weapons. So should General Motors and Nissan wonder, ‘how is this truck going to be used?’ Why don’t you go after the auto makers?” he says. “It’s an open market. You cannot stop the flow of surveillance equipment.”
This article first appeared at: http://www.guardian.co.uk/technology/2011/nov/01/governments-hacking-techniques-surveillance
