More on the Indymedia shutdown

Law: t r u t h o u t quotes this press release from Rackspace:

In the present matter regarding Indymedia, Rackspace Managed Hosting, a U.S. based company with offices in London, is acting in compliance with a court order pursuant to a Mutual Legal Assistance Treaty (MLAT), which establishes procedures for countries to assist each other in investigations such as international terrorism, kidnapping and money laundering. Rackspace responded to a Commissioner’s subpoena, duly issued under Title 28, United States Code, Section 1782 in an investigation that did not arise in the United States. Rackspace is acting as a good corporate citizen and is cooperating with international law enforcement authorities. The court prohibits Rackspace from commenting further on this matter.

(my emphasis.) I wonder which of those 3 Indymedia is supposed to have been infringing? It’s pretty clear how Rackspace feel about this situation, I think.

It seems MLATs have been used before to shut down Indymedia sites in the US; this cryptome mirror of Montreal IMC pages documents one such case. Here’s a summary from a quoted email there:

Heres a quite interesting story on the power of mlats and what we will have to look forward to with the COE treaty :

A cop car was broken into in Quebec and a security doc relating to measures for the Free Trade Area of the Americas summit protests was stolen and posted in the net in Seattle. At the behest of the RCMP, a magistrate judge issued an order to grab the records from a Seattle web site called the ‘independent media center’ using the US/CAN mlat. They were then visited by the FBI/Secret Service. They then had a gag order on this for several days before it was released today.

Great precedent. I wonder if when my car gets broken into again, I can use the cybercrime treaty to find my stereo again…

And snippets from the IMC press release of the time:

On the evening of Saturday, April 21, a day which saw tens of thousands demonstrate against the FTAA in the streets of Quebec City, the Independent Media Center in Seattle was served with a sealed court order by two FBI agents and an agent of the US Secret Service. The terms of the sealed order prevented IMC volunteers from publicizing its contents; volunteers immediately began discussions with legal counsel to amend the order. This morning, April 27, Magistrate Judge Monica Benton issued an amended order, freeing us to discuss the situation without the threat of being held in contempt.

The original order, also issued by Judge Benton, directed the IMC to supply the FBI with ‘all user connection logs’ for April 20 and 21st from a web server occupying an IP address which the Secret Service believed belonged to the IMC. The order stated that this was part of an ‘ongoing criminal investigation’ into acts that could constitute violations of Canadian law, specifically theft and mischief. IMC legal counsel David Sobel, of the Electronic Privacy Information Center, comments: ‘As the U.S. Supreme Court has recognized, the First Amendment protects the right to communicate anonymously with the press and for political purposes. An order compelling the disclosure of information identifying an indiscriminately large number of users of a website devoted to political discourse raises very serious constitutional issues. To provide the same protection to the press and anonymous sources in the Internet world as with more traditional media, the Government must be severely limited in its ability to demand their Internet identity–their ‘Internet Protocol addresses.’ A federal statute already requires that such efforts against the press be approved by the Attorney General, and only where essential and after alternatives have been exhausted. There is no suggestion that these standards were met here.

The sealed court order also directed the IMC not to disclose ‘the existence of this Application or Order, or the existence of this investigation, unless or until ordered by this court.’ Such a prior restraint on a media organization goes to the heart of the First Amendment. Ironically, the Seattle Post-Intelligencer learned about the existence of the order from ‘federal sources,’ suggesting that the purpose of the gag order was simply to allow the government to spin the issue its way.

The order did not specify what acts were being investigated, and the Secret Service agent acknowledged that the IMC itself was not suspected of criminal activity. No violation of US law was alleged.

Of course, cryptome is still chugging away as it always has been; simple HTML and no server-side dynamic scripting, means easy offshore mirroring ;)

Tags: , , , , , , , , , ,

Comments

Indymedia server drives seized

Politics: Indymedia’s hard drives in Rackspace UK seized by FBI order, seemingly as a ‘courtesy’ to Swiss police. There’s several morals to be learned:

  • Rackspace UK are happy to roll over for the US feds;
  • it appears the action was taken using powers granted under the USA-Patriot Act;
  • hosting in Europe is not safe from bad US laws.

However, the UK site is back on the air, and reportedly they’re recovering nicely; ‘All this goes to prove that Indymedia is decentralised enough (but not perfectly) to survive an attack and that as a cooperative international network, we rock!’

Tags: , , , , , , , , , ,

Comments

Great Economist article on UNIX

Software: Economist: Unix’s founding fathers (via sourcefrog.net). A very good article on Thompson, Kernighan and Ritchie’s amazing achievement, with some new details I hadn’t heard before:

AT&T was required under the terms of a 1958 court order in an antitrust case to license its non-telephone-related technology to anyone who asked. And so Unix and C were distributed, mostly to universities, for only a nominal fee. When one considers the ineptness of AT&T’s later attempts to commercialise Unix — after the court order ceased to be applicable because of another antitrust case which broke up AT&T in 1984 – this restriction, an accidental boost to what would later become known as the open-source movement, becomes even more crucial.

So that’s how that happened. Just think — if it wasn’t for that court case, we’d probably all be hacking on VMS. ;)

Also at sourcefrog, mbp points out that the Sulston reverse-engineering story is ‘remarkably similar to that of Richard Stallman several years earlier, when the frustration of closed-source printer software helped motivate him to start the GNU project’.

Patents: yet another sourcefrog link, this time to a CNet story with a hilarious quote regarding software patents and the GIF/PNG debacle:

But Unisys credited its exertion of the LZW patent with the creation of the PNG format, and whatever improvements the newer technology brought to bear.

‘We haven’t evaluated the new recommendation for PNG, and it remains to be seen whether the new version will have an effect on the use of GIF images,’ said Unisys representative Kristine Grow. ‘If so, the patent situation will have achieved its purpose, which is to advance technological innovation. So we applaud that.’

Wow. Presumably by the same logic, they applaud al-Qaeda for improving airline security innovation, too…

Tags: , , , , , , , , ,

Comments

Don’t look for it, and you won’t find it

Health: USDA orders silence on mad cow in Texas: ‘The U.S. Department of Agriculture has issued an order instructing its inspectors in Texas, where federal mad cow disease testing policies recently were violated, not to talk about the cattle disorder with outside parties … The order … was issued in the wake of the April 27 case at Lone Star Beef in San Angelo, in which a cow displaying signs of a brain disorder was not tested for mad cow disease despite a federal policy to screen all such animals.’

Great idea — if you want to avoid finding mad cow cases, just don’t bother looking for them! The beef rendering plant in question supplies beef to MacDonalds, reportedly.

Press: LWN: A look at SpamAssassin 3.0 (article is subscriber-only until next week).

OSes: Kernelthread.com: Making an Operating System Faster. Great article on some OS-level optimisations Apple used in MacOS X — including a nifty boot-time read-ahead system which reportedly more than doubles the speed of OS X reboots. nice!

Wildlife: here’s another critter we encountered last weekend — a baby Western Diamondback rattlesnake, hiding in a crevice.

Tags: , , , , , , , , , ,

Comments

Pat Kenny tangles with Aileen

Ireland: So on Saturday last, Pat Kenny, the host of the Late Late Show (Ireland’s longest-running chat show) had Aileen O’Carroll on to talk about the Dublin Grassroots Network’s planned May Day march.

The Gardai have been doing their damnedest to block the march, gaining power to deploy armed police, and in turn, the PR big guns have been deployed in force to get scare stories printed, with the tabloid journos utilizing their considerable wiles in the process.

So, it’s culminated in an appearance on the Late Late for Aileen. By all accounts, it went very well.

Apparently, another great moment of reported hilarity was a lengthy discussion between Pat Kenny, the tabloid journalist, and a ’security expert’ as to whether there would be ‘agent provocateurs’ present. It seems all agreed there might just be. One wonders if they thought to look up the word beforehand:

Agents provocateurs are also used in the investigation of political crimes. Here, it has been claimed that the provocateurs deliberately seek to incite ineffective radical acts, in order to foster public disdain for the political group being investigated; and to worsen the punishments its members are liable for. Within the United States the COINTELPRO program of the Federal Bureau of Investigation had FBI agents posing as political radicals in order to disrupt the activities of political groups the U.S. government found unacceptably radical. The activities of agents provocateurs against political dissidents in Imperial Russia was one of the grievances that led to the Russian Revolution.

Tags: , , , , , , , , , ,

Comments

‘International blacklists’ absurdity

OK, this is very stupid.

----- Transcript of session follows -----
... while talking to mail.(elided).com.:
>>> RCPT To:
< << 591  The mail server you are SENDING FROM is listed on an
international blacklist. Send your questions to
blacklist-admin@(elided).net
554 5.0.0 Service unavailable

The mailserver in question is dogma.slashnull.org, 212.17.35.15. It’s never been on a blacklist. However, it does live outside the US — in Ireland, to be exact.

So it appears (from the wording) that someone is actually filtering their mail feed and blocking all mail from Ireland. Hello!? It’s worth noting, in passing, that I strongly doubt that blocking all mail from Ireland (a) reduces your spam load one iota or (b) accomplishes anything apart from pissing off Irish people. Ah well, not my problem…

SCO: In other news, Ben sends on this Pinky and The Brain rendition of the SCO-vs-the-world saga from Nicholas Petreley — worth a titter. Given that SCO are now sending invoices to Linux users, including charging 32 bucks for embedded developers — who almost definitely are not using Read-Copy-Update and that kind of absurdly-high-end code – it’s pretty accurate.

Malware: The latest Windows worm, coming to a system near you; make sure ports 135-139, 445 and 593 are blocked, if you really have to run Windows for some reason. The worm’s author includes this notable text string: billy gates why do you make this possible ? Stop making money and fix your software!!

Iraq: Amazing postmortem of the Iraq war. Summary: absolutely inept on the Iraqi side. ‘The only order I got was to dismantle my airplanes — the most idiotic order I ever received.’

Tags: , , , , , , , , ,

Comments

Unclear on the whole ‘Mardi Gras’ concept

Scotsman: tourism leaders in Northern Ireland have been urged to market the Protestant Orange Order’s Battle of the Boyne celebrations like … Mardi Gras in New Orleans, by a DUP councillor.

Tags: , , , , , , , , ,

Comments

Hotmail getting tough on spammers

Reg: Hotmail files anti-spam lawsuit. ‘Microsoft has targeted spammers with a lawsuit aimed at bulk mailers who harvest email addresses of Hotmail subscribers in order to bombard them with junk. … In the suit, Microsoft alleges that unnamed bulk mailers used tools to randomly generate email addresses prior to testing this list out to see which accounts were active. Essentially this is a form of dictionary attack, which Microsoft argues violates federal laws including the Computer Fraud and Abuse Act. Trespass is also involved in the attacks, the software giant argues.’ Go Hotmail!

Also noteworthy: Out-Law.com: The Spammers Are Watching You: ‘Eight out of ten spam e-mails contain covert tracking codes which allow the senders to record and log recipients’ e-mail addresses as soon as they open the message.’ well, duh, that’s why SpamAssassin has a WEB_BUGS rule. Unfortunately, eight out of ten legit HTML newsletter mails also contain web bugs, too. :(

Tags: , , , , , , , , ,

Comments

Who 0wnz your government?

Danny reports “the always excellent c’t magazine analyses the hypotheticals of the Dutch IP-surveillance scandal:

According to anonymous sources within the Dutch intelligence community, all tapping equipment of the Dutch intelligence services and half the tapping equipment of the national police force, is insecure and is leaking information to Israel. …”

Yikes. You’d think they’d have learnt from Ireland’s mistakes…. this article (update: moved to here) reports that massive back-door use by a third-party government occurred before in similar circumstances, during the Anglo-Irish negotiations of 1985.

For those of you who don’t know, these discussions were between the Republic of Ireland and the UK, and took place in London.

In order to allow the negotiating team to contact their government and civil service securely, a million-pound cryptographic system had been bought in order to secure the link between the Irish Embassy in London and the government in Dublin.

Unfortunately, this equipment was thoroughly compromised.

It turns out that the Swiss company from which the equipment was bought, namely Crypto AG, had cooperated with the NSA and the BND (the NSA’s German equivalent), to allow them to decipher the traffic trivially. (Judging from the snippet from another article below, sounds like this was done using a known-plaintext attack).

The NSA routinely monitored and deciphered the Irish diplomatic messages. All it took then was for the UK’s NSA equivalent, GCHQ, to pull some strings, and the UK government had a distinct advantage in the negotiations from then on.

Another source for details on Crypto AG’s breakage is Der Spiegel, issue 36/96, pages 206-207. Here’s some snippets:

The secret man (sic) have obviously a great interest to direct the trading of encryption devices into ordered tracks. … A former employee of Crypto AG reported that he had to coordinate his developments with “people from Bad Godesberg”. This was the residence of the “central office for encryption affairs” of the BND, and the service instructed Crypto AG what algorithms to use to create the codes.

Members of the American secret service National Security Agency (NSA) also visited the Crypto AG often. The memorandum of the secret workshop of the Crypto AG in August 1975 on the occasion of the demonstration of a new prototype of an encryption device mentions as a participant the cryptographer of the NSA, Nora Mackebee. …

Depending on the projected usage area the manipulation on the cryptographic devices were more or less subtle, said Polzer. Some buyers only got simplified code technology according to the motto “for these customers that is sufficient, they don’t not need such a good stuff.”

In more delicate cases the specialists reached deeper into the cryptographic trick box: The machines prepared in this way enriched the encrypted text with “auxiliary informations” that allowed all who knew this addition to reconstruct the original key. The result was the same: What looked like inpenetrateable secret code to the users of the Crypto-machines, who acted in good faith, was readable with not more than a finger exercise for the informed listener.

Full text here.

So what’s the bottom line? Use GPG! ;)

From: Julian Assange (spam-protected)

To: (spam-protected) (spam-protected)
Date: Mon, 14 Oct 1996 13:24:31 +1000 (EST)

Approved: (spam-protected)

Subject: BoS: Crypto AG = Crypto NSA/BNG ?

Thanks to Anonymous for this English translation of the German original.


secret services undermine cryptographic devices


Archive of “DER SPIEGEL” issue 36/96 pages 206-207


“Who is the authorized fourth”

Secret services undermine the protection of cryptographic devices.

Switzerland is a discreet place. Uncounted millions of illegal money find an asylum in the discreet banks of the republic. Here another business can prosper, which does not need any publicity: the production of cryptographic devices.

A top address for tools of secrecy was for several decades the company Crypto AG in Zug. It was founded in 1952 by the legendary Swedish cryptographer Boris Hagelin. Hundreds of thousands of his “Hagelin-machines”, pendants of the German “Enigma” devices, were used in World War II on the side of the Allies.

A prospectus of the company states: “In the meantime, the Crypto AG has built up long standing cooperative relations with customers in 130 countries.” Crypto AG delivers enciphering devices applicable to voice as well as data networks.

But behind this solid facade the most impudent secret service feint of the century has been staged: German and American services are under suspicion of manipulation of the cryptographic devices of Crypto AG in a way that makes the codes crackable within a very short time, and this allegedly happened until the end of the eighties.

Customers of Crypto AG are many honorable institutions, like the Vatican, as well as countries like Iraq, Iran, Libya, that are at the top of the priority list of U.S. services. At the beginning of the nineties the discreet company was suspected to play an unfair game. What was the source of the “direct precise and undeniable proofs” U.S. president Reagan referred to when he ordered the bombardment of Libya, the country he called the wire puller of the attack against the disco La Belle? Obviously the U.S services were able to read encrypted radio transmissions between Tripoli and its embassy in East Berlin.

Hans Buehler, a sales engineer of Crypto AG, got between the fronts of the secret service war. On March 18, 1992, the unsuspecting tradesman was arrested in Teheran. During the nine and a half months of solitary confinement in a military prison he had to answer over and over again, to whom he leaked the codes of Teheran and the keys of Libya.

In the end Crypto AG paid generously the requested bail of about one million German marks (DM), but dismissed the released Buehler a few weeks later. The reason: Buehlers publicity, “especially during and after his return” was harmful for the company. But Buehler started to ask inconvenient questions and got surprising answers.

Already the ownership of the Crypto AG was diffuse. A “foundation”, established by Hagelin, provides according to the company “the best preconditions for the independence of the company”.

But a big part of the shares are owned by German owners in changing constellations. Eugen Freiberger, who is the head of the managing board in 1982 and resides in Munich, owns all but 6 of the 6,000 shares of Crypto AG. Josef Bauer, who was elected into managing board in 1970, now states that he, as an authorized tax agent of the Muenchner Treuhandgesellschaft KPMG [Munich trust company], worked due to a “mandate of the Siemens AG”. When the Crypto AG could no longer escape the news headlines, an insider said, the German shareholders parted with the high-explosive share.

Some of the changing managers of Crypto AG did work for Siemens before. Rumors, saying that the German secret service BND was hiding behind this engagement, were strongly denied by Crypto AG.

But on the other hand it appeared like the German service had an suspiciously great interest in the prosperity of the Swiss company. In October 1970 a secret meeting of the BND discussed, “how the Swiss company Graettner could be guided nearer to the Crypto AG or could even be incorporated with the Crypto AG.” Additionally the service considered, how “the Swedish company Ericsson could be influenced through Siemens to terminate its own cryptographic business.”

The secret man have obviously a great interest to direct the trading of encryption devices into ordered tracks. Ernst Polzer*, a former employee of Crypto AG, reported that he had to coordinate his developments with “people from Bad Godesberg”. This was the residence of the “central office for encryption affairs” of the BND, and the service instructed Crypto AG what algorithms to use to create the codes. (* name changed by the editor)

Members of the American secret service National Security Agency (NSA) also visited the Crypto AG often. The memorandum of the secret workshop of the Crypto AG in August 1975 on the occasion of the demonstration of a new prototype of an encryption device mentions as a participant the cryptographer of the NSA, Nora Mackebee.

Bob Newman, an engineer of the chip producer Motorola, which cooperated with Crypto AG in the seventies to develop a new generation of electronic encryption machines, knows Mackebee. She was introduced to him as a “counselor”.

“The people knew Zug very good and gave travel tips to the Motorola people for the visit at Crypto AG”, Newman reported. Polzer also remembers the American “watcher”, who strongly demanded the use of certain encryption methods.

Depending on the projected usage area the manipulation on the cryptographic devices were more or less subtle, said Polzer. Some buyers only got simplified code technology according to the motto “for these customers that is sufficient, they don’t not need such a good stuff.”

In more delicate cases the specialists reached deeper into the cryptographic trick box: The machines prepared in this way enriched the encrypted text with “auxiliary informations” that allowed all who knew this addition to reconstruct the original key. The result was the same: What looked like inpenetrateable secret code to the users of the
Crypto-machines, who acted in good faith, was readable with not more than a finger exercise for the informed listener.

The Crypto AG called such reports “old hearsay” and “pure invention”. But the process, that was started by the company against the former employee Buehler, on the grounds that he had said that there might be some truth in the suspicions of the Iranian investigators, surprisingly ended in November of last year.

After the trial, that could have brought embarrassing details to the light, the company agreed to an settlement outside the court. Since that time Buehler is very silent with regard to this case. “He made his fortune financially,” presumed an insider of the scene.

“In the industry everybody knows how such affairs will be dealed with,” said Polzer, a former colleague of Buehler. “Of course such devices protect against interception by unauthorized third parties, as stated in the prospectus. But the interesting question is: Who is the authorized fourth?”

– “Of all tyrannies a tyranny sincerely exercised for the good of its victims may be the most oppressive. It may be better to live under robber barons than under omnipotent moral busybodies, The robber baron’s cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for own good will torment us without end, for they do so with the approval of their own conscience.” - C.S. Lewis, _God in the Dock_ +———————+——————–+———————————-+ |Julian Assange RSO | PO Box 2031 BARKER | Secret Analytic Guy Union | (spam-protected) | VIC 3122 AUSTRALIA | finger for PGP key hash ID = | (spam-protected) | FAX +61-3-98199066 | 0619737CCC143F6DEA73E27378933690 | +———————+——————–+———————————-+

Tags: , , , , , , , , ,

Comments

(Untitled)

A Las Vegas sleaze-merchant reckons that a “shadowy cabal of criminals, corrupt insiders and professional hackers” selectively re-routes phone calls in order to “steal” customers.

Tags: , ,

Comments