Bruce Schneier | |||||||||||||||
Schneier on SecurityA blog covering security and security technology. « GPS Spoofing | Main | The NSA Teams Up with the Chinese Government to Limit Internet Anonymity » September 17, 2008NSA Snooping on Cell Phone CallsFrom CNet: A recent article in the London Review of Books revealed that a number of private companies now sell off-the-shelf data-mining solutions to government spies interested in analyzing mobile-phone calling records and real-time location information. These companies include ThorpeGlen, VASTech, Kommlabs, and Aqsacom--all of which sell "passive probing" data-mining services to governments around the world. Posted on September 17, 2008 at 12:49 PM • 40 Comments To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. "which it has crunched in order to try and discover small anti-social groups that only call each other." Why don't they just advertise for computer nerds in the local jobs listings :-) OTOH, in what manner is it anti-social for a group of people to only call each other? Posted by: Nomen Publicus at September 17, 2008 1:29 PM So a couple of wrong numbers will break their data mine? Of course, if it's known they're doing that, it's easy enough to defeat. Posted by: Seth at September 17, 2008 1:35 PM "which it has crunched in order to try and discover small anti-social groups that only call each other." Why do cliques hate America? Posted by: Richard at September 17, 2008 1:35 PM Hah! Their data mining big brother system will never catch me! I don't have a cell phone at all! Posted by: ugh at September 17, 2008 1:35 PM Hmmmm....I guess I am safe then, since while I only talk to a very few people, those people are extrememly social and call many, many people. Posted by: edgore at September 17, 2008 2:00 PM @ugh: Since everyone else has a cell phone, or at least all normal people have cell phones, expect to be collected for questioning soon. Regards, your friendly government. Posted by: A Non at September 17, 2008 2:59 PM Ha! I registered my phone under an assumed name. Let them drag Harry Tuttle in for questioning! Posted by: Andre LePlume at September 17, 2008 3:05 PM "small anti-social groups that only call each other" They've discovered the family! Wow, this high-tech stuff is sure a boon. Posted by: kangaroo at September 17, 2008 3:06 PM "small anti-social groups that only call each other." A roundabout way of saying 'families'? Posted by: Roy at September 17, 2008 3:12 PM "The wiretapping laws, at least in this situation, simply don't apply." Apparently the 4th amendment doesn't, either. Posted by: Tangerine Blue at September 17, 2008 3:19 PM this data is more freely available than the article suggests. it's not just the NSA getting into snooping on cell records but commercial companies and other gov't agencies (e.g. transpo) have been doing this as well. Posted by: Davi Ottenheimer at September 17, 2008 3:27 PM I'm actually behind such solutions. So long as it doesn't involve the government strong arming any companies and they are harvesting their own data from the airwaves (like any Tom, Dick, or Harry could do) I don't see the problem (other than the fact it's against Federal (Wiretapping?) Law.) The real solution which should be implemented by the phone companies is to develop a solution that encrypts all this crap, then it won't matter who is sniffing what when from where! Posted by: Phillip at September 17, 2008 4:49 PM I like how they pretend to hide the personal information on the last slide. It's still there ;) Posted by: iqlusion at September 17, 2008 6:01 PM http://armsandthelaw.com/archives/2008/09/... ATF losing records of gun purchases. Posted by: nerdboy at September 17, 2008 6:13 PM With GPS spoofing apparently easy to do, I would guess that any groups that don't want to be monitored for location will use that path, and leave only honest or innocent cell phone users culpable for whatever the security agencies want to blame them for. By the way, in the U.S. one will find that teenagers comprise the largest population of such small anti-social groups. There goes that high school diploma. Why aren't they catching drug dealers and criminals with this? Because to do so would cause such groups to change their ways and then they couldn't be caught. Posted by: WhereBeYou at September 17, 2008 7:37 PM Several of you have misunderstood the definition of the "small, anti-social group". It's a small group of callers where _every_ caller in the group only ever calls other members of the group. This doesn't cover "families" (the teenager in the family calls their friends, who call _their_ family and friends, who call...). If you read up on it, it turns out that all but a few hundred callers (out of tens of millions) are a part of one big network of people that call each other. Which isn't at all surprising, is it? Posted by: kez at September 17, 2008 9:35 PM Fortunately I don't need a phone. If I ever need to call myself, I won't bother to. aren't there gpg type gizmo's that can use a cell acct? Posted by: 7 degrees of antisocial-ness? at September 17, 2008 10:33 PM whoever said they needed to could have obtained billing data in the past, even w/o being a govt employee (social engineering) - Posted by: neill at September 18, 2008 1:24 AM Hmm. I live in a foreign country with my girlfriend. We don't know many people here, so my cellphone for instance almost always calls her cellphone.... Now I'm anti-social apparently! R Posted by: R at September 18, 2008 2:33 AM Yet another 'false positive system' to throw into the mix. The implied idea this could pinpoint terrorist cells would be laughable if it were not for the fact that the US (and probably the UK) is willing to 'engage suspects' anywhere. Posted by: Bill at September 18, 2008 4:09 AM People in the US seem to think you need GPS to locate a cell phone, which isn't true. You can judge someone's physical location to a great degree of accuracy simply by the cell phone towers they use. Look at Google Maps mobile for example. Posted by: Cybergibbons at September 18, 2008 4:09 AM The last slide has been removed! What was on it? Posted by: NP at September 18, 2008 4:42 AM They don't teach civics in school anymore, because its all theory, and the reality is government corrupts, absolute government corrrups absolutely, Posted by: rip at September 18, 2008 7:50 AM i am not "anti-social", i just only call my friends. the flip side would be that telemarketers are the only group never to make it "the list"? that just seems wrong. Posted by: edm at September 18, 2008 7:59 AM from the last slide: Thank youFurther information and discussion:Vincent Barry – VP Global SalesVincent.barry@thorpeglen.comMobile - +65-97558905On September 9, the Berkman Center received a request from Mr. Dave Woods, CEO of ThorpeGlen to remove the .pdf sales presentation that Christopher Soghoian was mirroring on his Berkman account.Mr Woods cited privacy concerns, as the name, email address and mobile phone # of his VP of Sales were listed on the last slide.We have removed this slide as per his request, although we note that the original slides are still available on ThorpeGlen’s website ?as well as Google’s cache?, and still list the “private” contact information of Vincent Barry, their VP of Global Sales Posted by: Not Hidden at September 18, 2008 8:00 AM Domestic terrorists may have to go back to pay phones. Posted by: Jason at September 18, 2008 10:36 AM @Jason: That's assuming they can find a payphone. As someone happily without a cell phone, I've been watching as the level of maintenance on pay phones has decreased and a lot of phones that used to be available aren't there anymore. Posted by: Bryan Feir at September 18, 2008 11:04 AM kez: do you understand sarcasm? I am sure those "small anti-social groups" in other parts of the world have already modified their behavior so they won't be identified as such anymore. Posted by: WhereBeYou at September 18, 2008 11:08 AM It might be a good idea for terrorists to also work in some sales related job that requires many calls to many people from a cell phone (such as a Real Estate agent). Posted by: JJ at September 18, 2008 11:38 AM I wonder if the humble carrier pigeon is going to make a "come back" ;-) Posted by: Peter Maxwell at September 18, 2008 1:34 PM @rip Since being different is a crime, shouldn't they teach a class called "how to be average,normal" That's what public school is. It teaches kids how not to stand out. The ones that stand out get pounded down, either by other students or by faculty/staff. Posted by: if I had a hammer at September 18, 2008 4:38 PM Evidently a terrorist cell can evade detection by making a few crank calls and ordering a pizza. Posted by: Jim Bullcrapper at September 19, 2008 12:25 AM @Jason: Terrorists can continue to use Skype, as does Vincent Barry. Posted by: Ray at September 19, 2008 8:34 AM ThorpeGlen appear to have taken down the pdf demo to which Bruce had linked. But, seriously, did anyone really doubt that the NSA or several other SigInt organisations already had this capability? Posted by: Bob Meade at September 22, 2008 9:09 PM Since 9-11 the U.S. government has been gathering various data about US citizens (phone calls etc). Now when they own mortgages and other debt, they will be able to map any data from these to the data that has been collected so far. Read more in the comments here: Posted by: Guest at September 24, 2008 4:48 AM Doesn't this just give you an urge to make a set of .wav files that contain combinations of all the 'sensitive' words (but in innocuous use) you can think of, post them on several webpages, start a viral email and then have everyone phone each other and play the file? Posted by: bob at September 24, 2008 7:43 AM This is when pay-as-you-go phones come in handy. No annoying contract and no gps/personal information to track! Posted by: J at September 30, 2008 2:25 PM well what is new? NSA and FBI and CIA spying this and NSA spying that is all old news. Cant we have articles on what the acronym agencies DO NOT spy on?? We know that U.S is pretty much a full dictatorship... Posted by: and_so_forth at September 30, 2008 3:15 PM Post a comment
Powered by Movable Type. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments