Privacy

FBI Searched the Data of Millions of Americans Without Warrants (bloomberg.com) 35

An anonymous reader quotes a report from Bloomberg: The FBI searched emails, texts and other electronic communications of as many as 3.4 million U.S. residents without a warrant over a year, the nation's top spy chief said in a report. The "queries" were made between December 2020 and November 2021 by Federal Bureau of Investigation personnel as they looked for signs of threats and terrorists within electronic data legally collected under the Foreign Intelligence Surveillance Act, according to an annual transparency report issued Friday by the Office of the Director of National Intelligence. The surge came as the FBI made a push to stop hacking attacks.

The authority the FBI used in this case was under Section 702 of FISA, which is set to expire at the end of next year unless it's renewed by Congress. The report doesn't say the activity was illegal or even wrong. But the revelation could renew congressional and public debates over the power U.S. agencies have to collect and review intelligence information, especially data concerning individuals. In comparison, fewer than 1.3 million queries involving Americans' data were conducted between December 2019 and November 2020, according to the 38-page report. The report sought to provide a justification for the increase in queries during the last year.

"In the first half of the year, there were a number of large batch queries related to attempts to compromise U.S. critical infrastructure by foreign cyber actors," according to the report. "These queries, which included approximately 1.9 million query terms related to potential victims -- including U.S. persons -- accounted for the vast majority of the increase in U.S. person queries conducted by FBI over the prior year." The exact number of U.S. residents who potentially had their information reviewed isn't known because there's no precise way to measure the data, according to the report.
"Today's report sheds light on the extent of these unconstitutional 'backdoor searches,' and underscores the urgency of the problem," said senior staff attorney with the ACLU. "It's past time for Congress to step in to protect Americans' Fourth Amendment rights."
United States

US, Over 55 Other Countries Commit To Democratic Internet Governance (cnn.com) 72

An anonymous reader quotes a report from CNN: More than 55 countries and the United States announced their commitment Thursday to defending a free and open internet, agreeing to uphold digital human rights in response to rising authoritarianism in cyberspace. The agreement (PDF), known as the Declaration for the Future of the Internet, aims to forestall an emerging "splinternet" characterized by the growing repression of internet users in closed regimes such as Russia and China -- and the divergence of those countries from the internet's founding principles of universal access and unfettered information flow. Concerns about the internet's long-term trajectory have been amplified by the war in Ukraine, according to senior Biden administration officials, as Russia has moved to block western social media services and penalized the sharing of accurate information about the conflict.

Many of the commitments outlined in the agreement reflect existing US policy initiatives, and the administration officials described the declaration as a way to organize and harmonize those efforts internationally. Under the agreement, countries have pledged not to abuse internet technologies for illegal surveillance; block content or websites in violation of so-called net neutrality principles; or use digital tools to undermine trust in elections. They agreed to support multilateral efforts against cybercrime, an issue that's grown in significance as businesses and governments alike have reeled in the face of devastating ransomware attacks. They committed to using only "trustworthy" network equipment, a nod to the spying risks the US and its allies have said are associated with Chinese vendors such as Huawei. And they joined together in reaffirming support for the decentralized, consensus-driven approach that for decades has underpinned decisions about how the internet should work.

Microsoft

Microsoft Testing Integrated VPN 'Secure Network' in Edge (neowin.net) 35

Microsoft Edge could soon receive an integrated VPN service called the "Microsoft Edge Secure Network." The VPN (Virtual Private Network) service would work very similar to commercial VPN services, but it could be deeply integrated within the Microsoft Edge browser. From a report: The VPN service will be powered by Cloudflare. The company assures it permanently deletes the diagnostic and support data collected, every 25 hours.
Google

Google May Now Remove Search Results That Dox You (theverge.com) 18

Google says it's expanding the types of personal information that it'll remove from search results to cover things like your physical address, phone number, and passwords. From a report:: Before now, the feature mostly covered info that would let someone steal your identity or money -- now, you can ask Google to stop showing certain URLs that point to info that could lead someone to your house or give them access to your accounts. According to a blog post, Google's giving people the new options because "the internet is always evolving" and its search engine giving out your phone number or home address can be both jarring and dangerous. Here's a list of what kinds of info Google may remove, with the new additions in bold (h/t to the Wayback Machine for making the old list accessible): Confidential government identification (ID) numbers like U.S. Social Security Number, Argentine Single Tax Identification Number, etc, bank account numbers, credit card numbers, images of handwritten signatures, images of ID docs, highly personal, restricted, and official records, like medical records (used to read "confidential personal medical records"), personal contact info (physical addresses, phone numbers, and email addresses), and confidential login credentials.
Businesses

Crypto Firms Seek Clearer US Rules on Their Interest-Bearing Products (reuters.com) 12

Cryptocurrency companies said they remain unsure of U.S. regulations governing products that allow customers to earn interest on holdings instead of trading them, months after such an interest-bearing product drew a $100 million fine from a federal regulator and state governments. From a report: In February, New Jersey crypto company BlockFi agreed to pay $100 million in a landmark settlement with the U.S. Securities and Exchange Commission and state authorities who said its interest-bearing product qualifies as a security and should have been registered. Still, many digital asset companies providing such products said this month the rules remain unclear to them and they are uncertain when they should register such offerings, which are growing more popular and which many firms launched within the last year. Most firms have tried to structure the interest-bearing products to avoid the need to register them with the SEC, a process that takes time and entails ongoing disclosure and reporting obligations. That effort might set them up for a clash with the agency as it increases scrutiny of the crypto industry. BlockFi plans to offer an alternative yield product, which it said it would register first. The company and the SEC said the deal should provide a roadmap for other companies.
Apple

Apple Launches Do-It-Yourself Repairs For iPhone 13, iPhone 12 and iPhone SE, But There's a Catch (cnet.com) 58

Apple on Wednesday followed through on its plans to begin publicly releasing repair manuals for some of its products, in addition to selling parts and tools online. The goal, the company said, is to allow iPhone owners an alternative way to repair their devices. From a report: The tech giant's new program, called Self Service Repair, is starting out for US customers with Apple's iPhone 13 line of smartphones, the iPhone 12 and new iPhone SE. Apple said it designed the program to offer adventurous and capable people access to the same parts, tools and instructions it gives to its own certified technicians and partner repair shops, hopefully making it easier for people to repair devices instead of resorting to buying a new one. "We believe we have a responsibility to customers and the environment to offer convenient access to safe, reliable, and secure repairs to help customers get the most out of their devices," the company wrote in a document published Wednesday that outlines its plans. "As the doors open on this new venue, we're underwhelmed, and settling back into our usual skepticism," iFixit posted on Wednesday. The firm adds: The biggest problem? Apple is doubling down on their parts pairing strategy, enabling only very limited, serial number-authorized repairs. You cannot purchase key parts without a serial number or IMEI. If you use an aftermarket part, there's an "unable to verify" warning waiting for you. This strategy hamstrings third-party repair with feature loss and scare tactics and could dramatically limit options for recyclers and refurbishers, short-circuiting the circular economy. As of today, you can buy an official Apple iPhone 12 screen and install it yourself, on your own device, with no fuss. Until now, DIY repairs relied on keeping the Face ID speaker and sensor assembly intact, then very carefully moving it to your new screen, and finally ignoring some gentle warnings. If your assembly was damaged or defective, you were out of luck. The new program will solve that problem -- assuming you've bought an official Apple part.
Android

Android's App Store Privacy Section Starts Rolling Out Today (arstechnica.com) 14

An anonymous reader quotes a report from Ars Technica: Following in the footsteps of iOS 14, Google is rolling out an app privacy section to the Play Store on Tuesday. When you look up an app on the Play Store, alongside sections like "About this app" and "ratings and reviews," there will be a new section called "Data privacy & security," where developers can explain what data they collect. Note that while the section will be appearing for users starting today, it might not be filled out by developers. Google's deadline for developers to provide privacy information is July 20. Even then, all of this privacy information is provided by the developer and is essentially working on the honor system.

Here's how Google describes the process to developers: "You alone are responsible for making complete and accurate declarations in your app's store listing on Google Play. Google Play reviews apps across all policy requirements; however, we cannot make determinations on behalf of the developers of how they handle user data. Only you possess all the information required to complete the Data safety form. When Google becomes aware of a discrepancy between your app behavior and your declaration, we may take appropriate action, including enforcement action."

Once the section is up and running, developers will be expected to list what data they're collecting, why they're collecting it, and who they're sharing it with. The support page features a big list of data types for elements like "location," "personal info," "financial info," "web history," "contacts," and various file types. Developers are expected to list their data security practices, including explaining if data is encrypted in transit and if users can ask for data to be deleted. There's also a spot for "Google Play's Families Policy" compliance, which is mostly just a bunch of US COPPA and EU GDPR requirements. Google says developers can also indicate if their app has "been independently validated against a global security standard."

China

Concerns Raised Over Chinese Surveillance Camera Firm (apnews.com) 24

An independent monitor of Britain's use of surveillance cameras has asked for the government to clarify its positions on buying equipment from a Chinese technology company accused of involvement in human rights abuses. From a report: Fraser Sampson, the biometrics and surveillance camera commissioner, said he raised concerns with senior Cabinet officials after Hikvision failed to answer questions about the extent of its role in China's treatment of Uyghurs and other Muslim minorities in western Xinjiang province. "There are serious unanswered questions about Hikvision's involvement in appalling human rights abuses in China," Sampson said in a statement Tuesday. "The company seems unwilling or unable to provide assurances about the ethics of some of its operations and about security concerns associated with its equipment."

Sampson said the company's cameras and facial recognition technology have been implicated in "systematic human rights abuses" against Uyghurs. He said widespread persecution of the minority group in Xinjiang "is known to rely heavily on surveillance technology, including facial recognition software designed to detect racial characteristics." The Telegraph newspaper reported earlier this month that the U.K. health department banned Hikvision, which is part-owned by the Chinese government, from competing for new business after a procurement report found "ethical concerns" about the company.

The Courts

Payment Startup Bolt Sued by Its Most Prominent Customer (bloomberg.com) 9

Bolt, the payments startup known for its founder's inflammatory Twitter threads claiming Silicon Valley is run by "mob bosses," is being sued by its most prominent customer. From a report: The complaint by Authentic Brands Group alleges that Bolt not only failed to deliver promised technology but that during Bolt's integration with Forever 21, the clothier lost out on more than $150 million in online sales. The complaint also states that Bolt raised funding at increasingly high valuations by "consistently overstating" the nature of its integration with ABG's brands to suggest it had more customers than it did and to convince investors to bankroll additional growth for the startup. Because Bolt's business relies on having a large network of consumers, the allegations create major new uncertainty for the controversial payments startup, which investors most recently valued at $11 billion. In a filing, Bolt responded to the complaint saying that ABG's claims are without merit, and are "a transparent attempt" to renegotiate the terms of the companies' agreements.
Government

Open-Source Intelligence: How Bellingcat Uses Data Gathered by Authoritarian Governments (cnn.com) 52

CNN profiles Bellingcat, a Netherlands-based investigative group specializing in "open-source intelligence". And investigator Christo Grozev tells CNN that authoritarian governments make their work easier, because "they love to gather data, comprehensive data, on ... what they consider to be their subjects, and therefore there's a lot of centralized data."

"And second, there's a lot of petty corruption ... within the law enforcement system, and this data market thrives on that." Billions have been spent on creating sophisticated encrypted communications for the military in Russia. But most of that money has been stolen in corrupt kickbacks, and the result is they didn't have that functioning system... It is shocking how incompetent they are. But it was to be expected, because it's a reflection of 23 years of corrupt government.
Interestingly there's apparently less corruption in China — though more whistleblowers. But Bellingcat's first investigation involved the 2014 downing of a Boeing 777 over eastern Ukraine that killed 283 passengers. (The Dutch Safety Board later concluded it was downed by a surface-to-air missile launched from pro-Russian separatist-controlled territory in Ukraine.) "At that time, a lot of public data was available on Russian soldiers, Russian spies, and so on and so forth — because they still hadn't caught up with the times, so they kept a lot of digital traces, social media, posting selfies in front of weapons that shoot down airliners. That's where we kind of perfected the art of reconstructing a crime based on digital breadcrumbs..."

"By 2016, it was no longer possible to find soldiers leaving status selfies on the internet because a new law had been passed in Russia, for example, banning the use of mobile phones by secret services and by soldiers. So we had to develop a new way to get data on government crime. We found our way into this gray market of data in Russia, which is comprised of many, many gigabytes of leaked databases, car registration databases, passport databases. Most of these are available for free, completely freely downloadable from torrent sites or from forums and the internet." And for some of them, they're more current. You actually can buy the data through a broker, so we decided that in cases when we have a strong enough hypothesis that a government has committed the crime, we should probably drop our ethical boundaries from using such data — as long as it is verifiable, as long as it is not coming from one source only but corroborated by at least two or three other sources of data. That's how we develop it. And the first big use case for this approach was the ... poisoning of Sergei and Yulia Skripal in 2018 (in the United Kingdom), when we used this combination of open source and data bought from the gray market in Russia to piece together who exactly the two poisoners were. And that worked tremendously....

It has been what I best describe as a multilevel computer game.... [W]hen we first learned that we can get private data, passport files and residence files on Russian spies who go around killing people, they closed the files on those people. So every spy suddenly had a missing passport file in the central password database. But that opened up a completely new way for us to identify spies, because we were just able to compare older versions of the database to newer versions. So that allowed us to find a bad group of spies that we didn't even know existed before.

The Russian government did realize that that's maybe a bad idea to hide them from us, so they reopened those files but just started poisoning data. They started changing the photographs of some of these people to similar looking, like lookalikes of the people, so that they confused us or embarrass us if we publish a finding but it's for the wrong guy. And then we'll learn how to beat that.

When asked about having dropped some ethical boundaries about data use, Grozev replies "everything changes. Therefore, the rules of journalism should change with the changing times." "And it's not common that journalism was investigating governments conducting government-sanctioned crimes, but now it's happening." With a country's ruler proclaiming perpetual supreme power, "This is not a model that traditional journalism can investigate properly. It's not even a model that traditional law enforcement can investigate properly." I'll give an example. When the British police asked, by international agreement, for cooperation from the Russian government to provide evidence on who exactly these guys were who were hanging around the Skripals' house in 2018, they got completely fraudulent, fake data from the Russian government....

So the only way to counter that as a journalist is to get the data that the Russian government is refusing to hand over. And if this is the only way to get it, and if you can be sure that you can prove that this is valid data and authentic data — I think it is incumbent on journalists to find the truth. And especially when law enforcement refuses to find the truth because of honoring the sovereign system of respecting other governments.

It was Bellingcat that identified the spies who's poisoned Russian opposition leader Alexey Navalny. CNN suggests that for more details on their investigation, and "to understand Vladimir Putin's stranglehold on power in Russia, watch the new film Navalny which premieres Sunday at 9 p.m. ET on CNN."

The movie's tagline? "Poison always leaves a trail."
Government

How US Billionaires Can Avoid Paying Income Taxes (propublica.org) 229

On April 15th Americans filed their taxes with the Internal Revenue Service (or IRS). But on the same day ProPublica was reporting a difference between "the rich and the rest of us" — that their wealth just isn't easily defined: For one, wages make up only a small part of their earnings. And they have broad latitude in how they account for their businesses and investments. Their incomes aren't defined by a tax form. Instead, they represent the triumph of careful planning by skilled professionals who strive to deliver the most-advantageous-yet-still-plausible answers to their clients. For them, a tax return is an opening bid to the IRS. It's a kind of theory....

We counted at least 16 other billionaires (along with hundreds of other ultrawealthy people, including hedge fund managers and former CEOs) among the stimulus check recipients. This is just how our system works. It's why, in 2011, Jeff Bezos, then worth $18 billion, qualified for $4,000 in refundable child tax credits. (Bezos didn't respond to our questions.) A recent study by the Brookings Institution set out with a simple aim: to compare what owners of privately held businesses say they earn with the income that appears on the owners' tax returns. The findings were stark: "More than half of economic income generated by closely held businesses does not appear on tax returns and that ratio has declined significantly over the past 25 years."

That doesn't mean business owners are illegally hiding income from the IRS, though it's certainly a possible contributor. There are plenty of ways to make income vanish legally. Tax perks like depreciation allow owners to create tax losses even as they expand their businesses... "Losses" from one business can also be used to wipe out income from another. Sometimes spilling red ink can be lots of fun: For billionaires, owning sports teams and thoroughbred racehorses are exciting loss-makers. Congress larded the tax code with these sorts of provisions on the logic that what's good for businesses is good for the economy. Often, the evidence for this broader effect is thin or nonexistent, but you can be sure all this is great for business owners. The Brookings study found that households worth $10 million or more benefited the most from being able to make income disappear....

In the tax system we have, billionaires who'd really rather not pay income taxes can usually find a way not to. They can bank their accumulating gains tax-free and deploy tax losses to wipe out whatever taxable income they might have. They can even look forward to a few thousand dollars here and there from the government to help them raise their kids or get through a national emergency.

This system also means it's much harder to catch underreported income on the tax returns of the wealthy, the article points out. And with so many legal deductions, it's also hard to prove the low incomes really exceed what the law allows. Even then, the wealthy can still hire an army of the best tax lawyers to make their case in court.

And now thousands of auditors have left the agency — and have not been replaced. The end result? "Audits of the wealthy have plummeted.

"Business owners have still more reason to be bold...."
Privacy

Spyware and Pegasus: How Democracies Spy on Their Citizens (newyorker.com) 55

Writing for the New Yorker, Ronan Farrow reports on Pegasus, "a spyware technology designed by NSO Group, an Israeli firm, which can extract the contents of a phone, giving access to its texts and photographs, or activate its camera and microphone to provide real-time surveillance — exposing, say, confidential meetings." Pegasus is useful for law enforcement seeking criminals, or for authoritarians looking to quash dissent.... In Catalonia, more than sixty phones — owned by Catalan politicians, lawyers, and activists in Spain and across Europe — have been targeted using Pegasus. This is the largest forensically documented cluster of such attacks and infections on record. Among the victims are three members of the European Parliament... Catalan politicians believe that the likely perpetrators of the hacking campaign are Spanish officials, and the Citizen Lab's analysis suggests that the Spanish government has used Pegasus....

In recent years, investigations by the Citizen Lab and Amnesty International have revealed the presence of Pegasus on the phones of politicians, activists, and dissidents under repressive regimes. An analysis by Forensic Architecture, a research group at the University of London, has linked Pegasus to three hundred acts of physical violence. It has been used to target members of Rwanda's opposition party and journalists exposing corruption in El Salvador. In Mexico, it appeared on the phones of several people close to the reporter Javier Valdez Cárdenas, who was murdered after investigating drug cartels. Around the time that Prince Mohammed bin Salman of Saudi Arabia approved the murder of the journalist Jamal Khashoggi, a longtime critic, Pegasus was allegedly used to monitor phones belonging to Khashoggi's associates, possibly facilitating the killing, in 2018. (Bin Salman has denied involvement, and NSO said, in a statement, "Our technology was not associated in any way with the heinous murder.") Further reporting through a collaboration of news outlets known as the Pegasus Project has reinforced the links between NSO Group and anti-democratic states.

But there is evidence that Pegasus is being used in at least forty-five countries, and it and similar tools have been purchased by law-enforcement agencies in the United States and across Europe. Cristin Flynn Goodwin, a Microsoft executive who has led the company's efforts to fight spyware, told me, "The big, dirty secret is that governments are buying this stuff — not just authoritarian governments but all types of governments...." "Almost all governments in Europe are using our tools," Shalev Hulio, NSO Group's C.E.O., told me. A former senior Israeli intelligence official added, "NSO has a monopoly in Europe." German, Polish, and Hungarian authorities have admitted to using Pegasus. Belgian law enforcement uses it, too, though it won't admit it.

Calling the spyware industry "largely unregulated and increasingly controversial," the article notes how it's now impacting major western democracies. "The Citizen Lab's researchers concluded that, on July 26 and 27, 2020, Pegasus was used to infect a device connected to the network at 10 Downing Street, the office of Boris Johnson, the Prime Minister of the United Kingdom.... The United States has been both a consumer and a victim of this techÂnology. Although the National Security Agency and the C.I.A. have their own surveillance technology, other government offices, including in the military and in the Department of Justice, have bought spyware from private companies, according to people involved in those transactions."

But are the company's fortunes faltering? The company has been valued at more than a billion dollars. But now it is contending with debt, battling an array of corporate backers, and, according to industry observers, faltering in its long-standing efforts to sell its products to U.S. law enforcement, in part through an American branch, Westbridge Technologies. It also faces numerous lawsuits in many countries, brought by Meta (formerly Facebook), by Apple, and by individuals who have been hacked by NSO....

In November, the [U.S.] Commerce Department added NSO Group, along with several other spyware makers, to a list of entities blocked from purchasing technology from American companies without a license. I was with Hulio in New York the next day. NSO could no longer legally buy Windows operating systems, iPhones, Amazon cloud servers — the kinds of products it uses to run its business and build its spyware.

Government

US Invests $6 Billion to Save 'Financially Distressed' Nuclear Reactors (apnews.com) 188

The U.S. government "is launching a $6 billion effort to rescue nuclear power plants at risk of closing," reports the Associated Press, "citing the need to continue nuclear energy as a carbon-free source of power that helps to combat climate change." A certification and bidding process opened Tuesday for a civil nuclear credit program that is intended to bail out financially distressed owners or operators of nuclear power reactors, the U.S. Department of Energy told The Associated Press exclusively, shortly before the official announcement. It's the largest federal investment in saving financially distressed nuclear reactors... "U.S. nuclear power plants contribute more than half of our carbon-free electricity, and President Biden is committed to keeping these plants active to reach our clean energy goals," Energy Secretary Jennifer Granholm said in a statement. "We're using every tool available to get this country powered by clean energy by 2035, and that includes prioritizing our existing nuclear fleet to allow for continued emissions-free electricity generation and economic stability for the communities leading this important work...."

A dozen U.S. commercial nuclear power reactors have closed in the past decade before their licenses expired, largely due to competition from cheaper natural gas, massive operating losses due to low electricity prices and escalating costs, or the cost of major repairs. This has led to a rise in emissions in those regions, poorer air quality and the loss of thousands of high-paying jobs, dealing an economic blow to local communities, according to the Department of Energy. A quarter or more of the fleet is at risk, the Department of Energy added. The owners of seven currently operating reactors have already announced plans to retire them through 2025.... Twenty more reactors faced closure in the last decade before states stepped in to save them, according to the Nuclear Energy Institute , the industry's trade association.... Low electricity prices are the main cause of this trend, though federal and state policies to boost wind and solar have contributed as well, the NEI added.

There are 55 commercial nuclear power plants with 93 nuclear reactors in 28 U.S. states. Nuclear power already provides about 20% of electricity in the U.S., or about half the nation's carbon-free energy. If reactors do close before their licenses expire, fossil fuel plants will likely fill the void and emissions will increase, which would be a substantial setback, said Andrew Griffith, acting assistant secretary for nuclear energy at DOE. While natural gas may be cheaper, nuclear power hasn't been given credit for its carbon-free contribution to the grid and that has caused nuclear plants to struggle financially, Griffith added....

David Schlissel, at the Ohio-based Institute for Energy Economics and Financial Analysis, said he wishes the federal government, before it allocated the $6 billion, had analyzed whether that money might have been better spent on ramping up renewables, battery storage and energy efficiency projects, which can be done quickly and cheaply to displace fossil fuels.

The Courts

Zoom Agrees To 'Historic' $85 Million Payout For Graphic Zoombombing Claims (theguardian.com) 50

The Covid-19 pandemic brought on a surge of "zoom-bombing" as hackers and pranksters crashed into virtual meetings with abusive messages and imagery. Now, Zoom has agreed to a "historic" payout of $85m as part of a class-action settlement brought by its users, including church groups who said they were left traumatized by the disruptions. From a report: As part of the settlement agreement, Zoom Video Communications, the company behind the teleconference application that grew popular during the pandemic, will pay the $85m to users in cash compensation and also implement reforms to its business practices. On Thursday, federal judge Laurel Beeler of California granted final approval to the agreement which was first filed in July. The agreement was granted preliminary approval in October. The settlement stems from 14 class-action complaints filed against the San Jose-based company by users between March and May of 2020, in which they argued that the company violated their privacy and security.
Privacy

American Phone-Tracking Firm Demo'd Surveillance Powers By Spying On CIA and NSA (arstechnica.com) 50

Anomaly Six, a secretive government contractor, claims to monitor the movements of billions of phones around the world and unmask spies with the press of a button. Reader BeerFartMoron shares a report: In the months leading up to Russia's invasion of Ukraine, two obscure American startups met to discuss a potential surveillance partnership that would merge the ability to track the movements of billions of people via their phones with a constant stream of data purchased directly from Twitter. According to Brendon Clark of Anomaly Six -- or "A6" -- the combination of its cellphone location-tracking technology with the social media surveillance provided by Zignal Labs would permit the U.S. government to effortlessly spy on Russian forces as they amassed along the Ukrainian border, or similarly track Chinese nuclear submarines. To prove that the technology worked, Clark pointed A6's powers inward, spying on the National Security Agency and CIA, using their own cellphones against them.

Virginia-based Anomaly Six was founded in 2018 by two ex-military intelligence officers and maintains a public presence that is scant to the point of mysterious, its website disclosing nothing about what the firm actually does. But there's a good chance that A6 knows an immense amount about you. The company is one of many that purchases vast reams of location data, tracking hundreds of millions of people around the world by exploiting a poorly understood fact: Countless common smartphone apps are constantly harvesting your location and relaying it to advertisers, typically without your knowledge or informed consent, relying on disclosures buried in the legalese of the sprawling terms of service that the companies involved count on you never reading.

Facebook

Facebook's Fibre Optics in Nigerian State Put Africa Pivot in Focus (theguardian.com) 13

As Facebook/Meta faces rising pressure in west, it is investing in digital infrastructure elsewhere. From a report: When government officials in the southern Nigerian state of Edo set about radically improving poor internet access for its population of 4 million, they didn't have to look far for help. MainOne, a company responsible for laying a vast network of fibre-optic cables across west Africa, was an obvious partner. Another, perhaps less obvious one, was Facebook. A joint agreement was signed to install fibre-optic cables running across the state's capital, Benin City. Since 2019, 400km (250 miles) of cables have been laid in Edo, about a quarter via the partnership between the two companies and the government. "Obviously, Facebook isn't really a digital infrastructure company, but they invested in these cables," said Emmanuel Magnus Eweka, who worked as a senior government official for the Edo government until last September. In recent years, as Facebook has come under rising legislative pressure in the west, the company has increased its focus on Africa, particularly in countries where the regulatory and legislative environment tends to be much looser.

The combination of weak and expensive internet coverage for most of Nigeria's fast-growing population of more than 200 million people has meant that companies hoping to tap into a potential goldmine of new users -- and their data -- have sought to invest in the business of helping those potential users get online in the first place. "To make internet data more affordable, Facebook needs to build infrastructures that are almost free," Eweka said. "In fact, I'd say Facebook actually loses in terms of making money out of those cables. But then they gain it back on the user data that they will generate, and obviously that has huge potential in a country like Nigeria."

Businesses

Former EBay Security Director To Plead Guilty To Cyberstalking (bloomberg.com) 16

Former eBay security director Jim Baugh will plead guilty to running a bizarre 2019 cyberstalking campaign against a couple who ran a website critical of the company, Bloomberg reported Tuesday, citing a person familiar with the matter. From a report: Baugh had been scheduled to face trial in late May. In a court filing on Tuesday, his defense attorney, William Fick, asked a federal judge in Boston to allow Baugh to change his plea via videoconference. Five other former eBay employees have already admitted to roles in a cross-country campaign designed to intimidate Ina and David Steiner of Natick, Mass. Several were expected to testify against Baugh. Another eBay employee, former global resiliency director David Harville is scheduled to face trial in May. Ina Steiner's reporting about eBay on the couple's site eCommerce Bytes upset the company's then-Chief Executive Officer Devin Wenig, whose compensation package she revealed. "Take her down," Wenig texted his then-communications chief Steve Wymer, according to prosecutors.
Piracy

DuckDuckGo Insists It Didn't 'Purge' Piracy Sites From Search Results (theverge.com) 33

An anonymous reader shares a report: Users of privacy-focused search engine DuckDuckGo have been unable to site search the domains of some well-known pirated media sites recently, as reported by TorrentFreak on Friday. This follows a News Punch article last month calling out DuckDuckGo for "purging" independent media sources from search results, and naming them "Google Lite." DuckDuckGo's CEO Gabriel Weinberg called the News Punch piece "completely made up" in a Twitter thread over the weekend to respond to the public and address both issues.

To observers, it seemed as if DuckDuckGo had de-indexed searches for copyright-flouting media download sites like The Pirate Bay and Fmovies, and even a site search for the open-source tool youtube-dl came up empty. TorrentFreak later updated its report citing a company spokesperson blaming the issue on Bing search data, which DuckDuckGo relies upon. Weinberg insisted the company is not purging any results and said that site search results are not appearing due to the site operator error "Anyone can verify this by searching for an outlet and see it come up in results," Weinberg tweeted.

United Kingdom

No 10 Suspected of Being Target of NSO Spyware Attack, Boris Johnson 'Told' (theguardian.com) 23

Boris Johnson has been told his Downing Street office has been targeted with "multiple" suspected infections using Pegasus, the sophisticated hacking software that can turn a phone into a remote listening device, it was claimed on Monday. The Guardian reports: A report released by Citizen Lab at the University of Toronto said the United Arab Emirates was suspected of orchestrating spyware attacks on No 10 in 2020 and 2021. Pegasus is the hacking software -- or spyware -- developed, marketed and licensed to governments around the world by the Israeli firm NSO Group. It has the capability to infect phones running either iOS or Android operating systems. Citizen Lab added there had also been suspected attacks on the Foreign Office over the same two years that were also associated with Pegasus operators linked to the UAE -- as well as India, Cyprus and Jordan.

The researchers, considered among the world's leading experts in detecting digital attacks, announced they had taken the rare step of notifying Whitehall of the attack as it "believes that our actions can reduce harm." However, they were not able to identify the specific individuals within No 10 and the Foreign Office who are suspected of having been hacked. "The suspected infections relating to the FCO were associated with Pegasus operators that we link to the UAE, India, Cyprus and Jordan. The suspected infection at the UK prime minister's office was associated with a Pegasus operator we link to the UAE."

Government

Another Pentagon Official Exits, Saying US Is at Risk of Losing Tech Edge (bloomberg.com) 46

A senior official responsible for driving technological innovation at the U.S. Department of Defense has resigned, saying the Pentagon needs "structural change" and should behave more like SpaceX, Elon Musk's satellite company that has shaken up rocket launches. From a report: "We're falling behind the commercial base in key areas, so we've got to catch up," Preston Dunlap, the first person in the U.S. Department of Defense to fulfill the role of chief architect officer, told Bloomberg News in an interview. As a result the U.S. risked losing its technological edge against potential adversaries, he said.

Dunlap, who handed in his resignation on Monday after three years in the post at the U.S. Space Force and U.S. Air Force, was responsible for pushing more technology into a $70 billion budget for research, development and acquisition. He plans to start a space software company focused on the nexus with satellites, data and artificial intelligence. The Pentagon was behind the domestic commercial sector in data, distributed computer processing, software, AI and cybersecurity, he said. "By the time the Government manages to produce something, it's too often obsolete," he said in a nine-page resignation statement he billed as a "playbook" to help guide the Pentagon, which he later made public on LinkedIn. "Much more must be done if DoD is going to regrow its thinning technological edge. Ironically as I'm writing this, I received notification that the phone lines are down at the Pentagon IT help desk. Phone lines are down? It's 2022, folks," he wrote.

Slashdot Top Deals