There ought to be more emphasis that these documents are circa 07/08. HTTPS websites were an oddity back then.
Indeed! 2008 is 5+ years ago. 5 years in tech is a couple of eternities.
US and UK spy agencies scoop up private data from 'leaky' phone apps
31–40 of 98 posts
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#32Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#33Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#34One slide from a May 2010 NSA presentation on getting data from smartphones – breathlessly titled "Golden Nugget!" – sets out the agency's "perfect scenario": "Target uploading photo to a social media site taken with a mobile device. What can we get?" To me, this is quite telling. The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking…
It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#35Curious, how many app devs are doing security/permissions audits? On Android java side we have a tool called: sable/soot Which I am recently learning to use..
> Soot is a Java optimization framework
Seems to be a Java static analysis tool and not related to Android permissions (although maybe related to security).
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#36Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…
That was in 2008. Imagine what else they've been able to jimmy in 6 years! I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes.
Considering Apple did that on your behalf I would be surprised if this was not the case.
http://bits.blogs.nytimes.com/2011/04/20/3g-apple-ios-device...
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#37So they're spying on the children playing Angry Birds in the name of preventing terrorism. I bet the data they're gathering has saved a lot of lives. This is just one more strike into the already well-beaten dead horse of an argument that the NSA is spying in the name of preventing terrorism. I will spell it out: the goal of the NSA surveillance is omniscience in the name of preserving the power of the state. They ha…
What about leaking bookmarks from Al-Quran app?
As violent and primitive as the Islamic fundamentalists are, the vast, vast, vast majority of the world's 1.6 billion Muslims are not fundamentalists, nor are they terrorists, nor do they aid terrorists.
The phrases that people bookmark in a religious app book are a very far cry from demonstrable intent to commit violence, anyway. If you spied on everyone's bookmarks in religious text apps, I'm fairly certain that if you pitched it properly you could depict my own gentle mother as a genocidal crusader.
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#38The only solution is to move to a phone OS that is 100%, completely, open. I.e. Not even apps developers are allowed to ship blobs - its All-Source-Code, All-The-Time. I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#39Ridiculous,seems like they are taking data and storing it and waiting to get subpoenas to look into and analyze the data later. Welcome to the new world order where your every movement is known.
Don't be alarmed citizen. They only 'know' about your movements if they actually look at them. Until then, they don't 'know' anything as long as it sits in their archives untouched.
Re: US and UK spy agencies scoop up private data from 'leaky' phone apps
#40Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…
Maps and other apps on the iPhone weren't using HTTPS in 08 (underpowered device, need to squeeze every last drop from battery). They do now however. It's not just a spy agency issue, anyone could have sniffed the unencrypted traffic.
Really now? Is that the official reasoning for not using HTTPS?