Saturday, February 24, 2018

Need Help? - Crisis Hotlines

 
 
There are 3 easy steps
 
1. Fill out a brief Self-Check Quiz, which takes about 10 minutes.
2. A VA Chat Responder will review it and leave a personal response for you on this secure website, usually within 10-15 minutes. If the volume is especially high, it may take up to 30 minutes. The Responder's note will offer options for follow-up if it's felt that could be helpful.
3. You decide what's next. You may enter the online Veterans Chat and continue talking with a Responder without identifying yourself. You may want to get a referral to see someone in person. Or, you can decide to do nothing further at this time. It's all up to you. No follow-up services will be provided unless you request them.
 
Protecting your privacy

You will not be asked to provide your name or any other information that identifies you.
You will be automatically assigned a unique identifying number called a "Reference Code" which will appear on the upper right-hand corner of your screen. Your Reference Code will also be provided on a page that you will see immediately after you submit the Self-Check Quiz. You will need to make a note of your Reference Code, because you'll need it to get the Responder's note to your Quiz.

Do you need help? Are you thinking about suicide, a victim of domestic violence, struggling with an addiction? National Hotlines will connect you to someone who will listen, and help connect you with resources you need in your local area. The first step in getting help is to simply pick up the phone and ask. You are not alone!

Suicide Prevention Lifeline - 1-800-273-TALK (8255)
The National Suicide Prevention Lifeline is a national network of local crisis centers that provides free and confidential emotional support to people in suicidal crisis or emotional distress 24 hours a day, 7 days a week.


National Domestic Violence Hotline - 1-800-799-SAFE (7233)
National Domestic Violence Hotline has been the vital link to safety for women, men, children and families affected by domestic violence. With the help of our dedicated advocates and staff, we respond to calls 24/7, 365 days a year.


National Sexual Assault Hotline 1-800-656-HOPE (4673)
The National Sexual Assault Hotline is available 24/7. You'll be connected to a trained staff member from a local sexual assault service provider in your area.


National Hotline for Crime Victims - 1-855-4-VICTIM (1-855-484-2846)
The Victim Connect Resource Center is a referral helpline where crime victims can learn about their rights and options confidentially and compassionately.


National Drug Helpline - 1-877-709-2389
The National Drug Helpline offers free, 24/7 drug and alcohol help to those struggling with addiction. Call the national hotline today to receive information regarding treatment and recovery.


Mental Health & Substance Abuse National Helpline - 1-800-662-HELP (4357)
SAMHSA’s National Helpline is a free, confidential, 24/7, 365-day-a-year treatment referral and information service for individuals and families facing mental and/or substance use disorders.

Warning Signs

Suicide

 

Domestic Violence

 

Workplace Violence

 
 
Signs Of A Dangerous Person

Difficulty getting along with others: Inappropriate conduct and outbursts - yelling at co-workers (profanities or threats), and passive aggressive conduct ("I'm not talking to you.").

Clinical paranoia:  They may not yet be diagnosed, but they think others are out to get them. "Every time I hear a noise I have to check to be sure someone is not there to hurt me or my family. - If someone showed up with a high-power rifle we would be sitting ducks."

Litigious nature: Filing false police reports and grievances is their way of virtually controlling others. Everything is blown out of proportion.

Victim attitudes: They never take responsibility for their behaviors, faults, mistakes or actions. They always blame others; it’s always someone else’s fault.

Controlling behaviors: Keeping secret / hidden files about co-workers or others they believe are "out to get them". Deliberately disrupting the work of others - deleting files being used by another employee.

Vindictive references: They say things like, "He will get his someday," or "What comes around goes around," or "One of these days I’ll have my say."
 

Who Watches the Watchmen?


Who Watches the Watchmen?
The Conflict Between National Security and Freedom of the Press
by: Gary Ross, National Intelligence University, Washington, DC, July 2011

Those who surrender true liberty to a false security defend nothing worth preserving, while those who abandon real security to an illusory liberty protect nothing worth safeguarding.

"Since the founding of this nation, the U.S. press has been committed to promoting democracy through an informed citizenry. From the "lone pamphleteers" of 1776 to major metropolitan newspaper editors of 2011, each has recognized the significance of disseminating essential information to the public. This includes publishing information concerning government actions conducted on behalf of its citizens as well as exposing corrupt or illegal activity committed by its elected representatives. This free flow of information allows individuals to remain engaged with their government."

An interesting book, available as a free download from the National Intelligence University.

There are certainly things that governments must do in secret to accomplish the functions of government - no one expects to see classified national defense information published on the front page of the New York Times.

At the same time, government secrecy can also be used to cover up illegal activity. When a government agency seeks to hide its actions from public view, by sealing court records, denying FOIA requests, and keeping secret / hidden files, one must ask just what type of official misconduct and wrong-doing they are trying to cover up!

Friday, February 23, 2018

Washington State Lawmakers Exempt Themselves from Public Records Law


When a government agency seeks to hide its actions from public view, by sealing court records, denying FOIA requests, and keeping secret / hidden files, one must ask just what type of official misconduct and wrong-doing they are trying to cover up!

OLYMPIA, Wash. (AP) - Washington state lawmakers have overwhelmingly approved legislation that will circumvent a recent court ruling that found they were fully subject to the state’s public disclosure laws. The measure retroactively removes the legislative branch from the state’s voter-approved Public Records Act so that lawmakers are able to attempt to shield records sought by a coalition of media groups, led by The Associated Press, who prevailed in court last month. The Legislature is appealing the Jan. 19 ruling of Thurston County Superior Court Judge Chris Lanese, who ruled state representatives and senators and their offices are fully subject to the same broad public disclosure requirements that cover other local and state elected officials and employees at state agencies.


The Evil Maid Attack


An evil maid attack is a security exploit that targets a computing device that has been shut down and left unattended.  An evil maid attack is characterized by the attacker's ability to physically access the target multiple times without the owner's knowledge.

Besides giving this type of attack a very catchy name, Polish security researcher Joanna Rutkowska successfully demonstrated in 2009 that even full disk encryption (FDE) cannot be counted on to protect a laptop when an attacker has physically access the device. Since then, the name "evil maid" has caught on with security professionals and the label has been used in a general fashion to describe scenarios in which the attacker doesn't simply steal the device -- or access it once to clone the hard drive -- but instead, returns multiple times to wreak havoc.

Basically, the attack works like this:

Step 1: Attacker gains access to your shut-down computer and boots it from a separate volume. The attacker writes a hacked bootloader onto your system, then shuts it down.

Step 2: You boot your computer using the attacker's hacked bootloader, entering your encryption key. Once the disk is unlocked, the hacked bootloader does its mischief. It might install malware to capture your encryption key and send it over the Internet somewhere, or store it in some location on the disk to be retrieved later.

You can see why it's called the "evil maid" attack; a likely scenario is that you leave your encrypted computer in your hotel room when you go out to dinner, and the maid sneaks in and installs the hacked bootloader. The same maid could even sneak back the next night and erase any traces of her actions.

Defeating the Evil Maid

No security product on the market today can protect you if the underlying computer has been compromised by malware with root level administrative privileges. If someone has physical access to your computer, we assume that that person has complete access to everything on your computer.
Putting your data on a thumb drive and taking it with you doesn't work; when you return you're plugging your thumb into a corrupted machine.

That being said, there are some common sense defenses against the "Evil Maid":

The defenses include two-factor authentication: a token you don't leave in your hotel room for the maid to find and use. The maid could still corrupt the machine, but it's more work.

Setting a BIOS password to prevent your laptop from being booted with external media. Remember though that a BIOS password can be removed by clearing dip switches, jumpers, jumping BIOS, or replacing BIOS - and other techniques. Some people super-glue the screws that hold their laptop together. This prevents the case from being easily opened.

Have a secure locking case in which to store your laptop while it is unattended, such as PacSafe, or a Pelican Laptop Case.

The simplest measure may be to always keep your device with you instead of leaving it in a hotel room or other unattended location.


Joanna Rutkowska's Anti Evil Maid article (Sept 7, 2011) provides a more technical look at defense against the Evil Maid.

People who encrypt their hard drives, or partitions on their hard drives, have to realize that the encryption gives them less protection than they probably believe. It protects against someone confiscating or stealing their computer and then trying to get at the data. It does not protect against an attacker who has access to your computer over a period of time during which you use it, too.

Thursday, February 22, 2018

Anarchists, Activists, and Saboteurs


Are you worried about government agents keeping secret files about you? Are you concerned that government agents are violating the civil rights of thousands of Americans by conducting an intensive, invasive, and illegal intelligence-gathering operation against people who oppose current government policy? Do you believe that government employees would submit false reports to local law enforcement about you, reports to be used in harassment campaigns that includes preemptive arrests and physical attacks on peaceful demonstrations; reports aimed at neutralizing the activities of individuals and political organizations through a pattern of false arrests and detentions, attacks on homes and friendships, and attempting to impede people from peacefully assembling and demonstrating against the government, anywhere and at any time? Do you believe they are Spying on Democracy?

Most of us probably do not concern ourselves with such things. But there is a part of our society that sees these things as a very real threat. These individuals oppose what they see as the illegal actions of big government and the crimes of big business. This opposition may be through political activity, civil disobedience, or even violent direct action. An April 28, 2017 article, "So You Want to Protest: A Beginner's Guide" in the Seattle Weekly pointed out that "asking nicely for change doesn't always work. To be effective, protesters must sometimes force a crisis-that is, interrupt some vital piece of social machinery like a highway or place of business, so that leaders are unable to ignore their demands. The squeaky wheel gets the grease, as the saying goes."

The culture that opposes Big Brother and Big Business can be very well-organized, and these groups publish manuals and guides on security culture, resistance, and direct action. Some of these manuals and guides are available at the following links. This is only a small sample what can be found on-line, and this doesn’t take into account what else may be available on the "dark web". But reading what's here will give you some understanding of the culture and provide you leads to other resources.



An Activist's Guide to Information Security

Animal Liberation Front: Guide to Direct Action

Black Cat Sabotage Manual

CrimethInc


Ecodefense: A Field Guide to Monkeywrenching

Family Guardian

Frontline Defenders

If An Agent Knocks


Rage University

Rats! Your guide to protecting yourself against snitches, informers, informants, agents provocateurs, narcs, finks, and similar vermin. - Claire Wolfe

Resistance Manual

Revolutionary Resources

Rise Up


Ruckus Society

Sprout Distro

Tactical Technology Collective

Warrior Publications

If you are responsible for the security of a business likely to be targeted by these groups, or maybe you live in a city that sees regular civil disturbances, it would be of value to understand the mindset and the tactics of this part of our society and our communities. Are you a police officer, or a government agent? There is a sub-culture of society that opposes you simply because of your chosen profession. Understanding the tactics that these individuals may employ against you will contribute to your personal safety.

           

It is however essential that we recognize that Americans have constitutionally protected rights to assemble, speak, and petition the government. Potential criminality exhibited by certain members of a group does not negate the constitutional rights of the group itself or its law-abiding participants to exercise their individual liberties under the First Amendment to the U.S. Constitution.

Wednesday, February 21, 2018

Microsoft Office Encryption


MS Office allows you to protect documents (Word), spreadsheets (Excel), databases (Access), and presentations (PowerPoint) with a password. When MS Office products are protected, they are encrypted and a password is required to open and read them. The default encryption values for MS Office 2013 are AES (Advanced Encryption Standard), 128-bit key length, SHA1, and CBC (cipher block chaining).  This provides reasonably good security for the content of your products, but you must ensure that you are using a strong password. (The 40-bit key RC4 protection used in earlier versions of MS Office, 97-2003, can typically be bypassed with password hacking software.)

To add a password to an MS Office product, click on the ‘File Tab’, choose the ‘Info’ Menu, and then click on the ‘Protect Document’ (‘Protect Workbook’, etc.) Button, and choose "Encrypt with Password" from the drop-down menu. Add a password to the open dialog box, confirm the password, and now your MS Office product will require a password the next time it is opened.

While MS Office Encryption provides good security for personal use, you should be aware of a potential security vulnerability if you use MS Office on a network. This vulnerability is a Microsoft tool called DocRecrypt.

Network administrators can use Group Policy to push registry changes that associate a certificate with password-protected documents. This certificate information is embedded in the file header. Later, if the password is forgotten or lost, use the DocRecrypt command line tool and the private key to unlock the file and, optionally, assign a new password.

Now, DocRecrypt won't recover the password for an encrypted document before this policy was established on the network, but once it is installed any MS Office encrypted documents you create thereafter will be able to be decrypted using the DocRecrypt tool.

One way to defeat the DocRecrypt tool is to create an encrypted document outside of the network and e-mail it to yourself. DocRecrypt shouldn't be able to add a decryption header to an already encrypted document.

While there are certainly better encryption tools than MS Office, the password-to-open / encryption function available in MS Office adds an additional layer of security to your documents, spreadsheets, databases, and presentations that is certainly far better than having no security at all. Would I use MS Office encryption to protect my most sensitive documents? No, probably not. At least not as my only form of encryption. Do I use MS Office encryption as an additional layer of security? Yes! It will keep most individuals and many local level agencies from accessing your data - when used with a strong password.